Department Manager, Cyber Security
Job Description
Department Manager – Enterprise Cybersecurity
Under the direction of the Chief Information Officer, the Department Manager – Enterprise Cybersecurity establishes, directs, and advances OCTA’s enterprise cybersecurity program, protecting information, technology, transportation operations, and critical infrastructure from evolving cyber risks.
As OCTA’s senior cybersecurity leader, this position provides strategic direction for cybersecurity governance and risk management, security operations and incident response, data privacy and classification, and the secure adoption of cloud, artificial intelligence, operational, and emerging technologies. The role advises executive leadership on cybersecurity posture, material risks, resilience, regulatory obligations, significant incidents, and strategic investment priorities while building a mature, risk-based cybersecurity program that enables OCTA’s business and public-service objectives.
This is an exempt position in Salary Grade 260: Min – $173,180.80 | Mid – $205,753.60 | Max – $238,305.60/year. The starting salary and level will be within this range based on qualifications.
This posting will remain open until a candidate is selected.
What You’ll Do
- Establish and lead OCTA’s enterprise cybersecurity strategy, governance framework, policies, standards, performance objectives, and multi-year cybersecurity roadmap
- Direct cybersecurity risk management across cloud and on-premises environments, enterprise networks, identity and access management, operational and transportation technologies, and critical infrastructure
- Advise the CIO, executive leadership, and, as appropriate, the Board of Directors on cybersecurity posture, material risks, significant incidents, program maturity, remediation efforts, and investment priorities
- Lead cybersecurity incident readiness and response, including incident command, executive communications, stakeholder coordination, evidence preservation, regulatory notifications, recovery priorities, exercises, and after-action reviews
- Establish risk-based vulnerability management, privileged-access, least-privilege, network segmentation, exposure management, and security monitoring practices
- Lead OCTA’s Data Privacy and Data Classification Program, including sensitive-data discovery, information protection, data loss prevention, handling requirements, and data lifecycle considerations
- Establish cybersecurity governance for artificial intelligence and emerging technologies, ensuring appropriate safeguards and human oversight
- Direct third-party and supply-chain cybersecurity risk management, including vendor due diligence, contractual security requirements, monitoring, incident coordination, and remediation
- Promote secure-by-design practices so cybersecurity considerations are incorporated early into technology projects, procurements, cloud modernization, system development, and operational changes
- Partner closely with IS Operations and business leaders to develop practical, risk-informed security solutions that protect OCTA while supporting operational continuity and organizational objectives
- Direct analysis of threat intelligence, security events, vulnerabilities, control performance, audit findings, third-party risks, and emerging technologies to identify trends and required actions
- Lead targeted security awareness and role-based training programs and establish measures to evaluate effectiveness and compliance
- Coordinate cybersecurity audits and assessments and ensure findings and corrective actions are appropriately tracked through closure
- Develop and lead the cybersecurity workforce through mentoring, professional development, cross-training, effective use of consultants and contractors, and knowledge transfer
- Build strategic relationships with transportation agencies, regulators, law enforcement, government partners, information-sharing organizations, vendors, and industry peers to strengthen cyber preparedness and awareness
What We’re Looking For
- Bachelor’s degree in Computer Science, Mathematics, Business, or a related field, or an equivalent combination of education and experience
- Minimum of eight years of related cybersecurity experience in business environments, including at least four years in a cybersecurity management position
- Hands-on experience with network security services and technologies
- Demonstrated experience leading enterprise cybersecurity governance, risk management, security operations, and incident response
- Strong understanding of cybersecurity risks affecting cloud, enterprise infrastructure, identity, operational technology, transportation systems, and critical infrastructure
- Experience developing cybersecurity strategies, policies, standards, performance measures, and multi-year roadmaps
- Strong knowledge of vulnerability and exposure management, identity and privileged-access security, network segmentation, security monitoring, and remediation practices
- Understanding of data privacy, data classification, information protection, and data loss prevention principles
- Knowledge of cybersecurity considerations associated with artificial intelligence, cloud services, emerging technologies, and third-party/supply-chain risk
- Demonstrated ability to lead significant cybersecurity incidents while balancing containment, service continuity, evidence preservation, operational safety, regulatory requirements, and recovery
- Strong business and risk-management judgment with the ability to translate complex cybersecurity issues into clear recommendations for executive and nontechnical audiences
- Proven ability to build strong partnerships with technology operations, business leaders, regulators, vendors, and external stakeholders
- Experience leading and developing cybersecurity professionals, consultants, and contractors
- One current or previously held security-related certification is required, such as CISM, CISSP, CISA, GSNA, GSAE, or comparable certification
- An advanced degree is preferred
Why You’ll Love It Here
- Lead the enterprise cybersecurity program protecting technology and critical transportation infrastructure that supports mobility throughout Orange County
- Serve as a trusted cybersecurity advisor to the CIO and executive leadership
- Shape OCTA’s long-term approach to cyber risk, resilience, data protection, artificial intelligence, cloud security, and emerging technologies
- Lead cybersecurity strategy across both traditional enterprise IT and mission-critical operational and transportation technology environments
- Build and develop a high-performing cybersecurity organization while strengthening partnerships across Information Systems and the agency
- Collaborate with transportation agencies, government partners, regulators, law enforcement, and cybersecurity professionals on evolving threats and industry challenges
- Make a meaningful public-service impact by strengthening the security and resilience of the systems that support OCTA’s customers, employees, and transportation operations
Join a team where innovation, integrity, and strategic thinking are valued. Apply now to lead OCTA’s Enterprise Cybersecurity program and help protect the technology, information, and critical infrastructure that keep Orange County moving.
OCTA is an equal employment opportunity employer that recruits, hires, and promotes qualified people without regard to race, color, religion, creed, ancestry, national origin, age, sex, pregnancy, gender, gender identity and/or expression, sexual orientation, marital status, medical condition, disability, genetic information, military and veteran status, or other legally protected status.