Govt. IT - Director of IT Security

Sault Ste. Marie Tribe of Chippewa Indians

Sault Ste. Marie (MI)

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

The Sault Ste. Marie Tribe of Chippewa Indians seeks a Director of IT Security to protect all tribe divisions including government, gaming, health, and enterprise systems.

You will develop and enforce security policies, manage vulnerability remediation, and lead a team across on‑premises and cloud environments to maintain a strong security posture. You will oversee security operations, incident response, training, audits, and third‑party risk, reporting to the CIO and Board.

Qualifications

  • Bachelor's degree in CS, IT, or Cybersecurity required; five years of relevant experience may substitute.
  • Five years overseeing IT or cybersecurity team for a medium-to-large organization.
  • Knowledge of NIST CSF, NIST 800-series, and CIS Controls.
  • Experience designing security for on‑premises and cloud environments.
  • Compliance with tribal requirements and background checks.

Responsibilities

  • Develop, implement, and maintain comprehensive security policies and procedures.
  • Identify, assess, and manage security risks; own vulnerability management program.
  • Design and oversee security architecture across on‑premises and cloud.
  • Oversee security operations, monitoring, detection, triage, and response.
  • Lead incident response plans, testing, and training; coordinate security incidents.
  • Define security training programs for employees and promote security awareness.
  • Manage security audits/assessments and address findings.
  • Ensure compliance with HIPAA, PCI-DSS, MICS, CJIS, and tribal data sovereignty.
  • Oversee third‑party risk management and vendor security assessments.
  • Present security metrics and program status to CIO/Executive Leadership/Board.
  • Develop and manage IT security budget; allocate resources.
  • Lead and mentor IT security professionals.

Skills

Security leadership
Vulnerability management
Security architecture
Incident response
Policy development
Security training
Risk assessment
Compliance knowledge

Education

Bachelor’s Degree in Computer Science/IT/Cybersecurity

Tools

Firewalls
IDS/IPS
EDR
SIEM
Encryption
Patch management

Job description

POSITION SUMMARY:

The Director of IT Security is responsible for the resources, processes, systems, policies, procedures, and cyber strategy to protect the entire tribe, including all government, gaming, health, and enterprise divisions. This position works closely with managers and executives across the tribe to promote strong security practices and to understand potential cybersecurity vulnerabilities. The Director of IT Security is responsible for maintaining current knowledge of evolving cyber threats, new security tools, and best practices.

ESSENTIAL FUNCTIONS: (includes, but is not limited to, the following)
  • Develop, implement, and maintain comprehensive security policies and procedures to safeguard the organization’s systems, data, and people.
  • Identify, assess, and manage security risks; own the vulnerability management program including prioritization and remediation reporting.
  • Design and oversee the security architecture across on-premises and cloud environments, ensuring it aligns with business goals and industry best practices.
  • Oversee security operations and continuous monitoring across network, endpoint, and cloud systems; ensure timely detection, triage, and response to threats.
  • Establish and lead incident response plans, including testing and training; coordinate and respond to all security incidents, ensuring timely resolution and minimizing impact.
  • Define, support, and coordinate security training programs to educate employees about security policies, procedures, and best practices, and foster a culture of security awareness across the organization.
  • Manage security audits and assessments to identify vulnerabilities and weaknesses in the organization’s IT infrastructure and take corrective actions to address findings.
  • Ensure compliance with relevant laws, regulations, and industry standards (including HIPAA, PCI-DSS, MICS, CJIS, and tribal data sovereignty requirements).
  • Oversee third-party risk management, including vendor security assessments, contract security clauses, and ongoing supplier risk reviews.
  • Present security posture, risk metrics, threat landscape summaries, and program performance to the CIO, executive leadership, and Board of Directors.
  • Develop and manage the IT Security budget, collaborating with the CIO and Executive Technology Steering Committee on needs and priorities, and allocate available resources effectively to address security priorities.
  • Lead, mentor, and guide a team of IT security professionals, motivating them to deliver on the organization’s security objectives.
ADDITIONAL RESPONSIBILITIES: (includes, but is not limited to, the following)
  • Research and evaluate emerging security technologies and tools; recommend solutions to enhance the organization's security posture.
  • Define and test business continuity and disaster recovery plans for security-relevant systems; lead annual tabletop exercises.
  • Develop and maintain policies governing employee use of generative AI tools and security review of AI-powered products.
  • Partner with IT, DevOps, and engineering teams to embed security requirements into system development, cloud architecture, and deployment pipelines.
CONTACTS:

Immediate peers, peers in other departments, immediate supervisor/manager, managers in other departments, Executives, Board of Directors, customers, and outside vendors/service providers.

PHYSICAL REQUIREMENTS:

Position medium with lifting of 50 pounds maximum and frequent lifting and carrying up to 25 pounds. Physical factors include constant sitting, near and midrange vision, typing; frequent walking, use of hearing, color vision, and driving; and occasional carrying/lifting, pushing/pulling, climbing, stooping, kneeling, crawling, reaching, manual handling, use of smell, far vision/depth perception, field of vision, and bending. Working conditions include occasional exposure to weather, heat, cold, wet/humidity, noise, vibration, and air quality. Potential hazards include constant computer use and occasional exposure to moving mechanical parts, electric shock, high exposed places, chemicals, client contact, and medical equipment use.

Education: Bachelor’s Degree in Computer Science, Information Technology, or Cybersecurity field required. Five years demonstrated ability in relevant experience may be considered in lieu of degree.

Experience: Five years of experience overseeing information technology or cybersecurity team for a medium-to-large organization required, in addition to above stated education requirements.

Certification/License: Must have a valid driver’s license and be insurable by the Sault Tribe Insurance Department. Must comply with annual driver’s license review and insurability standards with the Sault Tribe Insurance Department. Must undergo a criminal background investigation done under the rules of the National Indian Gaming Commission. Must comply with the Sault Tribe’s Drug-Free Workplace Policy which may include random drug tests.

Knowledge, Skills, and Abilities: In-depth knowledge of cybersecurity frameworks (e.g., NIST Cybersecurity Framework, NIST 800 series, CIS Controls) and best industry practices. Expertise in cybersecurity tools and technologies, including firewalls, intrusion detection/prevention systems (IDS/IPS), endpoint detection and response (EDR), data encryption, data backup/restoration solutions, patch management, and security information and event management (SIEM) solutions. Thorough understanding of risk assessment methodologies, threat modeling, cybersecurity tabletop exercises, and vulnerability management principles. Strong knowledge of IT security policies, procedures, and compliance regulations relevant to the organization (including HIPAA, PCI-DSS, GDPR, MICS, CJIS, and tribal data sovereignty concerns). Solid understanding of Identity and Access Management (IAM) principles, access controls, Zero Trust architecture, and modern user authentication methods. Solid understanding of data and voice networking, wireless and Wi‑Fi, internet connectivity, desktops and peripheral devices, Microsoft tools/servers/operating systems, email, and cloud technologies and services. Proven ability to design, implement, and maintain a comprehensive cybersecurity architecture across on‑premises and cloud environments. Ability to create and maintain an Incident Response Plan and lead and manage security incident response activities, including investigation, containment, eradication, and recovery. Excellent written and verbal communication skills to present complex security information, risk posture, and program metrics to both technical and non-technical audiences, including executive leadership and the Board. Strong leadership skills to motivate, mentor, and guide a team of IT security professionals. Skilled in developing and managing the IT security budget effectively. Strong analytical and problem-solving skills to identify, assess, and mitigate cybersecurity risks. Deep understanding of IT infrastructure, networks, and operating systems. Ability to develop and implement a long‑term cybersecurity strategy aligned with the organization’s overall goals. Proven negotiation skills to secure resources and advocate for cybersecurity initiatives. Knowledge of third‑party risk management principles, including vendor security assessments and supplier risk evaluation. Commitment to staying current on emerging cybersecurity threats, technologies, and regulatory changes. Native American preferred.

This job description outlines the general scope and level of responsibilities associated with the position. It is not intended to be an employment contract, nor does it represent a comprehensive list of all duties, responsibilities, or requirements. The Sault Ste. Marie Tribe of Chippewa Indians reserves the right to modify, add, reassign, or combine job duties or positions, in whole or in part, at any time.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Chief IT Security & Risk Architect
Chief IT Security & Risk Architect

Sault Ste. Marie Tribe of Chippewa Indians • Sault Ste. Marie (MI)

On-site
USD 140,000 - 190,000
IT & Security Specialist
IT & Security Specialist

Peoria Tribe • Miami (OK)

On-site
USD 70,000 - 100,000
IT & Security Specialist
IT & Security Specialist

Peoria-Tribe-of-Indians-of-Oklahoma- • Miami (FL)

On-site
USD 60,000 - 95,000
Director - Cybersecurity
Director - Cybersecurity

Morongo Casino Resort & Spa • California (MO)

On-site
USD 150,000 - 230,000
Technologies-Security Engineer
Technologies-Security Engineer

Puyallup Tribe • Tacoma (WA)

On-site
USD 110,000 - 150,000
Employer paid medical
Dental insurance
Vision insurance
+5
TO Saganing Techinical Services Supervisor
TO Saganing Techinical Services Supervisor

Sagchip • Mount Pleasant (MI)

On-site
USD 68,000 - 75,000
Medical, Dental, Vision insurance
401(k) with company match
Flexible schedule and telework options
Cybersecurity Liaison/Information Security Analyst - 304665 Delaware Nation Industries · Full-time · On-site — 4 hours ago
Cybersecurity Liaison/Information Security Analyst - 304665 Delaware Nation Industries · Full-time · On-site — 4 hours ago

Emploive • North Olmsted (OH)

Hybrid
USD 90,000 - 120,000
IT Security Administrator
IT Security Administrator

Daikin Comfort • Waller (TX)

On-site
USD 65,000 - 90,000
Job Posting Title Cybersecurity/RMF Lead
Job Posting Title Cybersecurity/RMF Lead

Ho-Chunk, Inc. • Kentucky

Remote
USD 120,000 - 180,000
Director, Cybersecurity
Director, Cybersecurity

Asset Living • United States

On-site
USD 150,000 - 190,000