Chief Information Security Officer (0933 Manager V) – Department of Public Health
Location : San Francisco, CA
Application Opening :
Friday, November 21, 2025
Application Deadline :
Friday, January 9, 2026
Salary :
$180,440 – $230,308 annually (Range A)
Appointment Type :
Permanent Civil Service
Recruitment ID : PBT-0933-160818
The Department of Public Health prioritizes equitable and inclusive access to quality healthcare for its community and values diversity in its workforce. All employees work to advance equity, inclusion, and diversity with a focus on race, ethnicity, gender, sex, sexuality, disability, and immigration status.
Mission
The San Francisco Department of Public Health (SFDPH) protects and promotes the health of all San Franciscans, working through several divisions including the San Francisco Health Network, Population Health Division, Behavioral Health Services, and Central Administration.
Role Description
The Chief Information Security Officer (CISO) is a dynamic and experienced cybersecurity professional who will lead a team of cybersecurity professionals within the SFDPH IT division, develop and execute a comprehensive information security strategy that safeguards the department’s systems, data, and services, and serve as a trusted advisor to senior leadership.
Responsibilities
Provides strategic leadership in evaluating and mitigating information security threats across the organization using a structured, risk‑based methodology. Advises executive leadership on identified risks and ensures timely execution of mitigation and remediation plans with integrity and discretion.
Directs the ongoing development of the department’s information security program, including project portfolio management, incident response, policy frameworks, compliance activities, threat and vulnerability management, and third‑party risk management.
Allocates and manages resources to support a robust security strategy. Identifies and advocates for strategic investments, oversees capital and operating budgets, and delivers ROI analyses and budget recommendations.
Partners with the Office of Compliance and Privacy Affairs to assess data security risks related to contracts, projects, artificial intelligence solutions, and other initiatives. Develops tools and interventions to mitigate risks, establishes performance metrics, and monitors compliance through audits and assessments.
Builds alignment and support for security goals and initiatives across internal and external stakeholders. Communicates effectively with leadership at all levels on trends, risks, and the overall effectiveness of the security program.
Promotes awareness and understanding of regulatory requirements across the organization. Leads or collaborates on testing and auditing activities to ensure ongoing compliance and successful certifications.
Analyzes security requirements and ensures compliance with industry standards such as HIPAA, NIST, and PCI‑DSS.
Establishes and maintains comprehensive policies and procedures to support effective and sustainable security operations.
Serves as the department’s representative in security‑related matters with City agencies and partners.
Continuously monitors emerging trends, technologies, and best practices in cybersecurity to ensure the department’s security posture remains current and effective.
Qualifications
Education :
Bachelor’s degree from an accredited college or university; AND
Experience :
Five (5) years of professional healthcare information systems security experience, of which three (3) years must include supervising IT professionals.
Education substitution is available on a year‑for‑year basis. One (1) year is equivalent to thirty (30) semester units / forty‑five (45) quarter units.
Desirable Qualifications
Possession of a Certified Information Systems Security Professional (CISSP) and / or Certified Information Security Manager (CISM) certification.
Selection Procedures
Candidates deemed qualified must complete a Supplemental Questionnaire (SQ) examination (Weight : 100%). The SQ evaluates knowledge of local, state, and federal laws, information security technologies, frameworks and standards, and managerial competencies. Successful candidates will be placed on the confidential eligible list. Additional selection processes may be conducted by the hiring department.
Applicants may be required to submit verification of qualifying education and experience at any point during the recruitment and selection process.
Equal Employment Opportunity Statement
The City and County of San Francisco encourages women, minorities and persons with disabilities to apply. Applicants will be considered regardless of their sex, race, age, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, HIV / AIDS status, genetic information, marital status, sexual orientation, gender identity, gender expression, military and veteran status, or other protected category under the law.
How to Apply
All job applications for the City and County of San Francisco must be submitted through the online portal at https : / / careers.sf.gov / . Applicants may be contacted by email about this recruitment. Please use a personal email address that you check regularly.
Contact
For questions regarding this recruitment or application process, contact Marielle Saldajeno at
marielle.saldajeno@sfdph.org
or (628) 271‑6820.
Computers are available at the Department of Human Resources lobby and City Career Center for online applications.
#J-18808-Ljbffr
Chief Information Security Officer • San Francisco, California, United States