Summary
The Chief Security Officer leads efforts to protect sensitive information and systems for Michigan's Office of the Auditor General, ensuring everything from data security to employee training follows laws and best practices.
This role involves advising the top tech leader, creating security plans, and managing a team to handle threats and compliance.
It's ideal for an experienced IT security professional with strong leadership skills and knowledge of government operations who thrives in complex, high-stakes environments.
Key Requirements
- Bachelor's degree, preferably in computer information systems or a related field
- Four years of professional experience, including two years at an experienced level (P11) or one year at an advanced level (12)
- Extensive knowledge of state and federal laws, legislative processes, and government relationships impacting department operations
- Thorough understanding of administrative management principles, including planning, staffing, budgeting, and program administration
- Strong supervisory skills, including training techniques, employee evaluation, and labor relations
- Ability to develop and enforce security and privacy policies, procedures, and standards
- Preferred experience in information security/privacy, identifying IT vulnerabilities, and coordinating with agencies on data protection
Full Job Description
To carry out its constitutionally established mission, the OAG relies on extensive confidential, sensitive, and critical information and systems. Protecting this information and these systems from unauthorized access, loss, or theft is essential to fulfilling that mission. To ensure compliance with mandated requirements, statutory obligations, and industry best practices for security and privacy, the OAG Chief Security Officer (CSO) is responsible for advising and assisting the Chief Information Officer (CIO) with:
• Development, implementation, and management of the OAG security and privacy program, including protection of critical data and information.
• Establishment of the OAG’s security strategy, architecture, and related oversight.
• Creation and enforcement of security/privacy policies, procedures, standards, data classifications, evaluations, roles, and employee awareness efforts.
• Planning and coordinating all security and privacy functions and assignments.
• Direction, review, and evaluation of all OAG security and privacy activities.
• Supervision and evaluation of the work performance of staff assigned to the CSO.
• Management of security for critical OAG and agency data, as well as all OAG security technologies and services, including defenses and access controls for employees, contractors, and visitors.
• Coordination with other agencies on security discussions for the receipt, classification, protection, and destruction of agency data provided to the OAG.
Requirements
EDUCATION:
Possession of a bachelor's degree. Preferred major in computer information systems or related field.
EXPERIENCE:
Four years of professional experience, including two years equivalent to the experienced (P11) level or one year equivalent to the advanced (12) level.
Additional Information
• Extensive knowledge of state and federal laws and legislative processes related to the work.
• Extensive knowledge of federal, state, and local relationships that impact the operations of a department.
• Extensive knowledge of current literature in the field.
• Extensive knowledge of training and supervisory techniques.
• Extensive knowledge of employee policies and procedures.
• Thorough knowledge of state government organization and functions.
• Thorough knowledge of the principles and techniques of administrative management including organization, planning, staffing, training, budgeting, and reporting.
• Thorough knowledge of methods of planning, developing, and administering programs.
• Thorough knowledge of fiscal planning and management.
• Thorough knowledge of staffing requirements as to type, number, and training necessary for the accomplishment of program goals.
• Thorough knowledge of labor relations and equal employment opportunity policies and procedures.
• Thorough knowledge of public relations techniques.
• Ability to instruct, direct, and evaluate employees.
• Ability to plan, direct, and coordinate program and administrative activities of a complex, interrelated, and interdependent nature, where unknowns and numerous contingency factors are involved.
• Ability to analyze and appraise facts and precedents in making administrative decisions.
• Ability to formulate policies and procedures based on information of a conceptual nature from varied and complex sources.
• Ability to establish and maintain effective relationships with government officials, private industry officials, professional personnel, and others.
• Ability to communicate effectively.
• Preferred knowledge of professional guidance related to information security/privacy.
• Preferred experience in identifying IT system vulnerabilities and appropriate solutions.
• Preferred experience in developing, maintaining, and monitoring access control system policies and procedures.
• Preferred experience in the investigation of potential security violations.
• Preferred experience in risk assessment.
• Preferred ability to exercise independent judgment and work well under pressure.
• Preferred proficiency in Powershell programming/reporting.
CERTIFICATES, LICENSES, REGISTRATIONS:
CISA (Certified Information Systems Auditor), CISM (Certified Information Systems Manager), or CISSP (Certified Information Systems Security Professional) desirable.