Class Code:
AF50
General Nature of Work

Directs and oversees professional work examining, evaluating, and/or monitoring conformity with laws, regulations, information security, privacy or other business standards. Directs compliance activities.

Guidelines for Class Use/Distinguishing Characteristics

The class is intended for directors of risk management and compliance activities statewide or for a large state agency.

Examples of Work

Collaborates with management to develop a compliance program that outlines the agency’s compliance vision, mission and goals. Leads the development and maintenance of the agency’s information security program and associated strategies with consideration for the business processes and overall goals of the organization. Facilitates collaboration between business functions (e.g., information technology, privacy, information security) to validate compliance with information security policies, standards, procedures, and controls and better understand risks within business processes and initiatives. Oversees the development and performance of vulnerability and risk assessments for business process, network, and applications. Initiates, facilitates, and promotes communications and training activities to reinforce information security awareness throughout the organization. Reviews and revises the privacy program on a periodic basis in light of changes in laws, regulations, or agency policy. Reports on a periodic basis the status of compliance programs to agency’s stakeholders and/or management. Provides subject matter expertise regarding applicable state policies, standards, procedures and controls to confirm they are appropriately embedded in the agency’s compliance practices. Leverages the data classification schema to establish a procedure to classify the agency’s data to protect its confidentiality, integrity, and availability. Establishes controls to help maintain the privacy of the agency’s data. Leads impact assessments to identify risks and potential impacts associated with processes, data and systems that are privacy-sensitive. Work with the agency’s business units and departments to develop a response plan for privacy and other compliance incidents. May serve as a liaison to regulatory and accrediting bodies. Serves as the overall liaison for any complaints and/or investigations related to privacy and other compliance related issues.

Knowledge, Skills and Abilities

Knowledge of applicable internal and/or external regulatory policies, standards, procedures and controls. Knowledge of governance, risk and compliance (GRC) program management. Understanding of risk assessment process, monitoring, and reporting. Ability to apply information security principles to business solutions. Ability to act as liaison and effectively communicate information security topics (e.g., data constraints, information needs) to both technical and non-technical audiences at all levels of the organization. Knowledge of developing and managing an information security program, including its policies, standards, procedures, technologies, and controls. Knowledge in identifying and managing information security risks, threats, and incidents at an enterprise level.

Minimum Requirements

A bachelor’s degree and relevant experience.

Fed Category:
E1
Band:
10
Salary:
Minimum:
$101,258.00
Midpoint:
$144,299.00
Maximum:
$187,341.00
BACK