What are the responsibilities and job description for the Security Compliance Manager position at Sall Fire?
Job Description
Job Description
Job Summary : The Security Compliance Manager is responsible for the effective planning, management, and governance of the County’s regulatory compliance programs. The compliance frameworks include NIST 800-53, CJIS, PCI-DSS, HIPAA, vendor management, IT policy administration, and all internal governance reviews. This role is also responsible for coordinating all inquiries from the Internal and External Audit teams regarding Technology services, initiatives, projects, platforms, and products. Ensures that all processes related to the IT security program and compliance initiatives are successfully prioritized, executed, and delivered with regular status reporting.
Duties and Responsibilities :
- Facilitates annual, quarterly, monthly, weekly, and periodic reviews of IT controls, recording findings and corrective actions in the GRC repository tool. Recommends improvements to enhance the County’s security compliance posture. Provides bi-weekly summary reports and / or presentations for the Security Compliance Committee. Updates IT policies annually to align with security controls.
- Serves as the primary point of contact for IT security walkthroughs, data center reviews / visits, and audits with internal and external audit and compliance entities. Completes security and compliance questionnaires for Federal and State government officials, HIPAA, PCI-DSS, risk assessments, and vendor management. Creates and maintains audit compliance flow charts, documentation, and control dependencies.
- Manages and oversees CJIS, HIPAA, and PCI-DSS engagements with external vendors. Acts as the liaison between PCI QSA’s and IT staff. Produces regular progress reports for the CISO and CIO. Consolidates and maintains all necessary artifacts to sustain compliance with each framework. Coordinates with vendors for services such as penetration tests, external network scans, etc.
- Implements, manages, and maintains a vendor management program, including a vendor questionnaire for new partnerships that require remote access to County IT assets or data. Regularly updates the policy, questionnaire, and vendor artifacts as needed.
- Performs other duties as assigned.
Qualifications :
Education and Experience :
Bachelor’s degree in Computer Science, Information Technology, Mathematics, Engineering, Business Administration, or a related field. Six (6) years of related work experience in IT security compliance and audit, with at least one (1) year of supervisory experience. CISA or CISM certification strongly preferred.
Special Requirements / Knowledge, Skills & Abilities :
Must-Have :
Additional Requirements :