Sault Tribe logo
Sault TribePosted 4 weeks ago

Govt. Director of IT Security

On-siteSault Ste. Marie, Michigan, United States

Full TimeSenior Level

Job Summary

Develop, implement, and maintain comprehensive security policies, procedures, and cyber strategy to protect government, gaming, health, and enterprise divisions. Identify, assess, and manage security risks while overseeing vulnerability management, prioritization, and remediation reporting. Design and oversee security architecture across on-premises and cloud environments; ensure timely detection, triage, and response to threats through continuous monitoring. Establish incident response plans, coordinate security incidents, and lead annual tabletop exercises for business continuity. Define security training programs, manage third-party risk assessments, and ensure compliance with HIPAA, PCI-DSS, MICS, CJIS, and tribal data sovereignty requirements. Present security posture and risk metrics to executive leadership and the Board of Directors. Lead, mentor, and guide a team of IT security professionals while managing the security budget and collaborating with IT and DevOps teams to embed security into system development.

Required Qualifications

  • Bachelor's Degree in Computer Science, Information Technology, or Cybersecurity field
  • Five years demonstrated ability in relevant experience
  • Five years of experience overseeing information technology or cybersecurity team for a medium-to-large organization
  • Valid driver's license
  • Insurable by the Sault Tribe Insurance Department
  • Compliance with annual driver's license review and insurability standards with the Sault Tribe Insurance Department
  • Criminal background investigation done under the rules of the National Indian Gaming Commission
  • Compliance with the Sault Tribe's Drug-Free Workplace Policy which may include random drug tests
  • In-depth knowledge of cybersecurity frameworks (e.g., NIST Cybersecurity Framework, NIST 800 series, CIS Controls) and best industry practices
  • Expertise in cybersecurity tools and technologies, including firewalls, intrusion detection/prevention systems (IDS/IPS), endpoint detection and response (EDR), data encryption, data backup/restoration solutions, patch management, and security information and event management (SIEM) solutions
  • Thorough understanding of risk assessment methodologies, threat modeling, cybersecurity tabletop exercises, and vulnerability management principles
  • Strong knowledge of IT security policies, procedures, and compliance regulations relevant to the organization (including HIPAA, PCI-DSS, GDPR, MICS, CJIS, and tribal data sovereignty concerns)
  • Solid understanding of Identity and Access Management (IAM) principles, access controls, Zero Trust architecture, and modern user authentication methods
  • Solid understanding of data and voice networking, wireless and Wi-Fi, internet connectivity, desktops and peripheral devices, Microsoft tools/servers/operating systems, email, and cloud technologies and services
  • Proven ability to design, implement, and maintain a comprehensive cybersecurity architecture across on-premises and cloud environments
  • Ability to create and maintain an Incident Response Plan and lead and manage security incident response activities, including investigation, containment, eradication, and recovery
  • Excellent written and verbal communication skills to present complex security information, risk posture, and program metrics to both technical and non-technical audiences, including executive leadership and the Board
  • Strong leadership skills to motivate, mentor, and guide a team of IT security professionals
  • Skilled in developing and managing the IT security budget effectively
  • Strong analytical and problem-solving skills to identify, assess, and mitigate cybersecurity risks
  • Deep understanding of IT infrastructure, networks, and operating systems
  • Ability to develop and implement a long-term cybersecurity strategy aligned with the organization's overall goals
  • Proven negotiation skills to secure resources and advocate for cybersecurity initiatives
  • Knowledge of third-party risk management principles, including vendor security assessments and supplier risk evaluation
  • Commitment to staying current on emerging cybersecurity threats, technologies, and regulatory changes
  • Native American preferred

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce