WT: CISO/ISM - 41500700

Date:  Sep 25, 2026


The State Personnel System is an E-Verify employer. For more information click on our E-Verify Website.

Requisition No: 884362 

Agency: Florida Gaming Control Commission

Working Title: WT: CISO/ISM - 41500700

 Pay Plan: SES

Position Number: 41500700 

Salary:  $100,000.00 - $110,000.00 annually 

Posting Closing Date: 09/29/2026 

Total Compensation Estimator Tool

FLORIDA GAMING CONTROL COMMISSION

Division of Administration

Office of Information Technology

 

Class Title: Info Tech Business Consultant Mgr - SES

Working Title: Chief Information Security Officer/Information Security Manager

Position Number: 41500700

 

Hiring Salary Range: $100,000 - $110,000 annually

 

***Open Competitive***

 

*Anticipated Vacancy*

 

Overview:

The Florida Gaming Control Commission is responsible for exercising all regulatory and executive powers of the state with respect to legal gaming, including pari-mutuel wagering, cardrooms, slot machine facilities, oversight of gaming compacts, and other forms of gambling authorized by state law, excluding the Lottery, as well as directly enforcing Florida’s gaming laws and combatting illegal gambling activities.

 

The agency is overseen by five Commissioners who are appointed by the Governor, with Commissioners appointing an Executive Director who leads a team of more than 200 staff members. The mission of the Florida Gaming Control Commission is to preserve and protect the integrity of gaming activities through fair regulation, licensing, effective criminal investigation, and enforcement.

 

The Commission offers a supportive work environment that fosters growth and collaboration.

 

Position Duties and Responsibilities:

This position serves as the Chief Information Security Officer (CISO) and Information Security Manager (ISM) for the Florida Gaming Control Commission and is responsible for developing, maintaining, and enforcing the Agency’s information security policies. The CISO/ISM is responsible for developing, implementing, and maintaining a strategic, comprehensive enterprise information security and IT risk management program, which includes procedures and policies designed to protect enterprise communications, systems, and assets from both internal and external threats, and enforces compliance with State and Federal requirements across all technology projects, systems, and services.

 

Duties include, but are not limited to:

 

  • Developing, implementing, and monitoring a strategic, comprehensive enterprise information security and IT risk management program;
  • Assisting resource owners and IT staff in understanding and responding to security audit failures reported by auditors;
  • Ensuring audit trails, system logs, and other monitoring data sources are reviewed periodically to ensure compliance with policies, audit requirements, and regulatory standards;
  • Designing, coordinating, and overseeing security testing procedures to verify the security of systems, networks, and applications, and manage the remediation of identified risks;
  • Developing and enhancing an information security management framework;
  • Creating, maintaining, and enforcing security policies, standards, procedures, controls, and guidelines that meet State and Federal requirements;
  • Leading incident response activities, including detection, analysis, containment, eradication, recovery, documentation, and notifications; oversee and coordinating the CSIRT;
  • Conducting and coordinating vulnerability assessments, security testing, and risk remediation efforts; manage continuous threat and vulnerability management operations;
  • Guiding development, testing, and maintenance of disaster recovery and business continuity plans;
  • Overseeing identity and access management governance, including access reviews, certifications, and privileged accmanagingount monitoring;
  • Developing, maintaining, and measuring the effectiveness of the agency's cybersecurity awareness program, including phishing, smishing, vishing, and other human-factor risk reduction initiatives; and
  • Providing leadership to the enterprise's information security organization and participating in strategic technology planning and governance.

 

Required Knowledge, Skills, and Abilities:

  • Knowledge of distributed processing operations, software, procedures, and equipment;
  • Knowledge of Information Security, principles, and best practices;
  • Knowledge of problem-solving techniques;
  • Knowledge of computers and software;
  • Knowledge of the principles, practices, and techniques of computer systems analysis;
  • Knowledge of the principles of networking and telecommunication;
  • Knowledge of telecommunications principles, equipment, procedures, and terminology;
  • Knowledge of audit procedures;
  • Knowledge of the principles of cryptography and cryptanalysis;
  • Knowledge of application and system technology security testing;
  • Ability to develop and maintain policies, procedures, standards, and guidelines;
  • Ability to process information logically and solve problems;
  • Ability to develop training programs related to distributed processing operations and procedures;
  • Ability to monitor, troubleshoot, and resolve problems with distributed computer systems components;
  • Ability to identify and define user needs;
  • Ability to communicate effectively;
  • Ability to establish and maintain effective working relationships with others;
  • Ability to prioritize, plan, organize, and coordinate work assignments;
  • Ability to author technical reports; and
  • Ability to analyze security requirements and relate them to the appropriate security controls.

 

Minimum Qualifications:

  • Four (4) years of information security experience with at least three (3) years responding to security incidents; OR
  • An associate's degree from an accredited college or university and two (2) years of experience responding to security incidents.
  • One (1) year of experience managing security projects, efforts, or teams.
  • Experience with various regulatory requirements, laws, and security frameworks, such as NIST, ISO 27001, PCI DSS, HIPAA, HITECH, SOX, GDPR, CCPA, CIS, or SOC 2.
  • Ability to manage a project, internal/external contractors’ team, vendors, budget, and initiatives.

 

Preferred Qualifications, not required:

  • A bachelor’s degree from an accredited college or university in information technology, computer engineering, business administration or a related field.
  • Industry recognized certifications such as: CISSP, CISM, CCSP, OSCP, CEH/CND, CySA+, Sec+, or related GIAC certification.
  • Experience securing cloud environments like Microsoft Azure, Amazon Web Services, or Google Cloud Platform.
  • Experience with firewalls and IAM/PAM systems and vendors.

 

Where you will work:

This position is located in Tallahassee, Florida. This is not a telework position.

 

Applicants are required to apply through the People First system by the closing date, by applying online.  All required documentation must be received by the closing date of the advertisement.  If you have any questions regarding your application, you may call 1-877-562-7287.

 

Benefits of Working For The State of Florida:

Working for the State of Florida is more than a paycheck. The state offers a comprehensive compensation package for our employees that features a highly competitive set of benefits including:

  • Low premium health, dental, vision, life, and supplemental coverage options!
  • Paid personal time that includes annual leave, sick leave, nine paid holidays, and one personal holiday!
  • Paid administrative leave for mentoring, volunteering, voting, and more!
  • Family planning support that includes adoption benefits and paid/unpaid leave options for family and medical responsibilities!
  • Retirement plans that include employer contributions (For more information, visit www.myfrs.com)!
  • Deferred compensation plans!
  • FREE basic life insurance plus additional options for you, your spouse, and children!
  • Flexible Spending Accounts!
  • Tuition waivers!

 

IMPORTANT NOTICES:

  • The Florida Gaming Control Commission has employment restrictions for all commission employees referenced in sections 16.713 and 16.715, Florida Statutes.
  • This position requires a Level 2 background screening, including fingerprinting, as a condition of employment and participation in direct deposit. You may be required to provide your Social Security Number (SSN) and/or State Issued Photo Identification in order to conduct the background investigation.

 

Special Reminders:

Male applicants born on or after October 1, 1962, will not be eligible for hire or promotion unless they are registered with the Selective Services System (SSS) before their 26th birthday, or have a Letter of Registration Exemption from the SSS. For more information, please visit the SSS website: http://www.sss.gov.

 

If you are a retiree of the Florida Retirement System (FRS), please check with the FRS on how your current benefits will be affected if you are re-employed with the State of Florida. Your current retirement benefits may be canceled, suspended or deemed ineligible depending upon the date of your retirement.

 

We hire only U. S. citizens and lawfully authorized alien workers. Our agency participates in the E-Verify System which is a federal government electronic database available for employers to use to verify the identity and employment eligibility of all persons hired to work in the United States.

 

The Florida Gaming Control Commission is committed to increasing recruitment and hiring of individuals with

disabilities and improving employment outcomes.

 

The Commission values the service veterans and their family members have given to our country

and supports the hiring of returning service members and military spouses.

 

Candidates requiring a reasonable accommodation, as defined by the Americans with Disabilities Act, must notify the FGCC Office of Human Resources by phone at (850) 794-8030 or by email at ADA.Coordinator@flgaming.gov.  The FGCC requires that applicants provide notification in advance to allow sufficient time to provide the accommodation.

Candidates requiring a reasonable accommodation, as defined by the Americans with Disabilities Act, must notify the agency hiring authority and/or People First Service Center (1-866-663-4735). Notification to the hiring authority must be made in advance to allow sufficient time to provide the accommodation.

The State of Florida supports a Drug-Free workplace. All employees are subject to reasonable suspicion drug testing in accordance with Section 112.0455, F.S., Drug-Free Workplace Act.

Location: 

TALLAHASSEE, FL, US, 32301 TALLAHASSEE, FL, US, 32316 TALLAHASSEE, FL, US, 32399 TALLAHASSEE, FL, US, 32317 TALLAHASSEE, FL, US, 32312 TALLAHASSEE, FL, US, 32305 TALLAHASSEE, FL, US, 32303 TALLAHASSEE, FL, US, 32302 TALLAHASSEE, FL, US, 32308 TALLAHASSEE, FL, US, 32304 TALLAHASSEE, FL, US, 32310 TALLAHASSEE, FL, US, 32309 TALLAHASSEE, FL, US, 32307 TALLAHASSEE, FL, US, 32311


Nearest Major Market: Tallahassee