POSITION SUMMARY:
The Director of IT Security is responsible for the resources, processes, systems, policies, procedures, and cyber strategy to protect the entire tribe, including all government, gaming, health, and enterprise divisions. This position works closely with managers and executives across the tribe to promote strong security practices and to understand potential cybersecurity vulnerabilities. The Director of IT Security is responsible for maintaining current knowledge of evolving cyber threats, new security tools, and best practices.
ESSENTIAL FUNCTIONS: (includes, but is not limited to, the following)
ADDITIONAL RESPONSIBILITIES: (includes, but is not limited to, the following)
CONTACTS:
Immediate peers, peers in other departments, immediate supervisor/manager, managers in other departments, Executives, Board of Directors, customers, and outside vendors/service providers.
PHYSICAL REQUIREMENTS:
Position medium with lifting of 50 pounds maximum and frequent lifting and carrying up to 25 pounds. Physical factors include constant sitting, near and midrange vision, typing; frequent walking, use of hearing, color vision, and driving; and occasional carrying/lifting, pushing/pulling, climbing, stooping, kneeling, crawling, reaching, manual handling, use of smell, far vision/depth perception, field of vision, and bending. Working conditions include occasional exposure to weather, heat, cold, wet/humidity, noise, vibration, and air quality. Potential hazards include constant computer use and occasional exposure to moving mechanical parts, electric shock, high exposed places, chemicals, client contact, and medical equipment use.
Education: Bachelor's Degree in Computer Science, Information Technology, or Cybersecurity field required. Five years demonstrated ability in relevant experience may be considered in lieu of degree.
Experience: Five years of experience overseeing information technology or cybersecurity team for a medium-to-large organization required, in addition to above stated education requirements.
Certification/License: Must have a valid driver's license and be insurable by the Sault Tribe Insurance Department. Must comply with annual driver's license review and insurability standards with the Sault Tribe Insurance Department. Must undergo a criminal background investigation done under the rules of the National Indian Gaming Commission. Must comply with the Sault Tribe's Drug-Free Workplace Policy which may include random drug tests.
Knowledge, Skills, and Abilities: In-depth knowledge of cybersecurity frameworks (e.g., NIST Cybersecurity Framework, NIST 800 series, CIS Controls) and best industry practices. Expertise in cybersecurity tools and technologies, including firewalls, intrusion detection/prevention systems (IDS/IPS), endpoint detection and response (EDR), data encryption, data backup/restoration solutions, patch management, and security information and event management (SIEM) solutions. Thorough understanding of risk assessment methodologies, threat modeling, cybersecurity tabletop exercises, and vulnerability management principles. Strong knowledge of IT security policies, procedures, and compliance regulations relevant to the organization (including HIPAA, PCI-DSS, GDPR, MICS, CJIS, and tribal data sovereignty concerns). Solid understanding of Identity and Access Management (IAM) principles, access controls, Zero Trust architecture, and modern user authentication methods. Solid understanding of data and voice networking, wireless and Wi-Fi, internet connectivity, desktops and peripheral devices, Microsoft tools/servers/operating systems, email, and cloud technologies and services. Proven ability to design, implement, and maintain a comprehensive cybersecurity architecture across on-premises and cloud environments. Ability to create and maintain an Incident Response Plan and lead and manage security incident response activities, including investigation, containment, eradication, and recovery. Excellent written and verbal communication skills to present complex security information, risk posture, and program metrics to both technical and non-technical audiences, including executive leadership and the Board. Strong leadership skills to motivate, mentor, and guide a team of IT security professionals. Skilled in developing and managing the IT security budget effectively. Strong analytical and problem-solving skills to identify, assess, and mitigate cybersecurity risks. Deep understanding of IT infrastructure, networks, and operating systems. Ability to develop and implement a long-term cybersecurity strategy aligned with the organization's overall goals. Proven negotiation skills to secure resources and advocate for cybersecurity initiatives. Knowledge of third-party risk management principles, including vendor security assessments and supplier risk evaluation. Commitment to staying current on emerging cybersecurity threats, technologies, and regulatory changes. Native American preferred.
This job description outlines the general scope and level of responsibilities associated with the position. It is not intended to be an employment contract, nor does it represent a comprehensive list of all duties, responsibilities, or requirements. The Sault Ste. Marie Tribe of Chippewa Indians reserves the right to modify, add, reassign, or combine job duties or positions, in whole or in part, at any time.
| Location | MI |