Job Description
Education/Certification:
- Bachelor's Degree required, preferably with coursework or concentration in cybersecurity, information technology, computer science, information systems, or a related field;
- Master's Degree preferred
- Current and progressive cybersecurity training required to support evolving security threats, technologies, and compliance expectations
- At least one or more of the following certifications is required or must be obtained within two years of hire:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Systems Security Certified Practitioner (SSCP)
- CompTIA Advanced Security Practitioner (CASP+)
- Certified Information Systems Auditor (CISA)
- Certified Ethical Hacker (CEH)
- Security+
Technology Proficiency:
- Advanced proficiency with enterprise technology environments, including operating systems, networks, endpoint security, identity and access management, productivity platforms, cloud-based systems, AI-enabled tools, systems analysis, and software or application support.
- Advanced proficiency support student, financial, administrative, or other enterprise systems in a complex organizational environment
Experience:
- Minimum of five years of progressively responsible cybersecurity, information security, IT risk, or related technology experience in a large, multi-department organization required
Special Knowledge/Skills:
- Extensive knowledge of enterprise cybersecurity programs, information security best practices, data protection principles, AI governance, change management oversight, risk management, compliance, and policy development for securing applications, devices, networks, systems, AI-enabled tools, and electronic data.
- Knowledge of K-12 and governmental cybersecurity and privacy requirements and recognized frameworks, including applicable Texas requirements, FERPA, COPPA, CIPA, PPRA, HIPAA, NIST, Cybersecurity Framework, NIST SP 800-53, NIST SP 800-61, Texas Cybersecurity Framework, CIS Critical Security Controls, ISO/IEC 27001 and 27002, COBIT, ITIL, PCI DSS, and other applicable laws, regulations, standards, and frameworks as needed.
- Knowledge of network security protocols, identity and access controls, system and server management, endpoint protection, security monitoring tools, threat intelligence, vulnerability testing, scanning tools, vulnerability management systems, and incident response practices.
- Ability to establish and maintain security standards and controls; assess risk; identify, analyze, and resolve complex vulnerabilities and security issues; evaluate data and security applications; and make timely, sound decisions.
- Knowledge of responsible AI use, AI-related privacy and security risks, data governance considerations, and the evaluation of AI-enabled tools for appropriate, secure, and compliant District use.
Personal Required:
- Communicates clearly, professionally, and respectfully with District staff, leadership, vendors, customers, and community stakeholders.
- Demonstrates strong organizational, interpersonal, verbal, written, presentation, analytical, problem-solving, and executive communication skills with attention to detail
- Works independently and collaboratively, demonstrates initiative, exercises sound judgement, maintains confidentiality, and supports training or knowledge-sharing with others.
- Provides responsive customer service and remains professional, composed, and solution-focused under pressure.
Function
The Information Security Officer leads the District's cybersecurity, information security, data privacy, AI risk, IT risk management, technology change management, and change control programs. The position establishes governance and risk-based security requirements that protect District systems, applications, networks, data, AI-enabled tools, and technology resources while supporting instructional and operational priorities.
The information Security Officer works with high degree of independence and provides strategic guidance to District leaders, departments, and Technology Services staff. This position supports risk-informed decision-making, strengthens cybersecurity and AI governance, promotes secure and responsible technology use, oversees technology change management practices, and helps ensure District resources and confidential information as protected.
Reports To:
Director of Information Systems
Responsibilities:
- Lead the District's cybersecurity, information security, data privacy, AI risk, IT risk management, technology change management, and change control programs by establishing governance frameworks, minimum control requirements, implementation roadmaps, strategic plans, maturity targets, standards, procedures, guidelines, and continuous improvement priorities aligned with federal, state, local, District, regulatory, and industry requirements.
- Supervise and direct Information Security team, assigned personnel, and cybersecurity-related vendors, including staff assignments, project oversight, hiring, training, evaluations, corrective action, complaint resolution, and compliance with District policies and applicable laws.
- Establish and monitor security requirements for secure configuration, identity and access management, privileged access, data protection, vulnerability management, security monitoring, application security, cloud security, technology lifecycle management, and related SB820 requirements
- Oversee technology change management by reviewing significant system, application, infrastructure, cybersecurity, AI-enabled tool, cloud service, and vendor-related changes for security impact, operational risk, privacy considerations, communication needs, documentation, approvals, implementation readiness, and post-change review.
- Perform or coordinate cybersecurity, privacy, AI, vendor, architecture, and technology risk assessments; maintain the District cybersecurity risk register; document risk-based recommendations, assigned owners, treatment plans, due dates, residual risk, approved exceptions, dependencies, unresolved risks, and escalation status
- Establish and administer a security exception and risk acceptance process requiring documented business justification, compensating controls, accountable approval by the appropriate executive, department, data, business, or system owner, expiration dates, periodic review, and escalation of material or persistent risk.
- Coordinate audits, compliance activities, vulnerability assessments, mitigations plans, remediation tracking, management responses, cybersecurity key performance indicators, key risk indicators, control-effectiveness measures, maturity reporting, executive dashboards, and required incident reporting or notifications in accordance with applicable law, District policy, and governance processes.
- Coordinate District data privacy governance, including review of student, employee, and confidential data use, data sharing agreements, privacy impact assessments, data classification, retention, minimization, encryption, secure disposal, and compliance with applicable privacy requirements
- Oversee third-party cybersecurity risk management throughout the vendor lifecycle, including pre-acquisition reviews, contract security and notification requirements, ongoing monitoring, renewal review, secure termination, and data disposition for technology vendors, cloud services, and software providers.
- Support District AI governance throughout the lifecycle of AI-enabled tools, including inventory, data-use review, approval conditions, material-change review, human oversight, monitoring, incident handling, decommissioning, responsible use, privacy, cybersecurity, and alignment with District standards.
- Develop, implement, test, and continuously improve incident response, security monitoring, threat intelligence, escalation, communication, recovery, lessons-learned, and follow-up processes for cybersecurity events involving District systems, networks, applications, data or confidential information
- Coordinate security operations and resilience activities, including centralized logging, alert triage, threat detection, managed security services, vulnerability and exposure management, penetration testing, emergency containment, digital forensics, evidence preservation, chain of custody, backup security, restoration testing, business continuity, disaster recovery preparedness, and related exercises with responsible departments and authorized parties.
- Implement and maintain cybersecurity education, awareness, phishing simulation, required training compliance, tabletop exercise, role-based readiness, committee coordination, communication, partnership, and continuous improvement programs that foster shared accountability for cybersecurity, privacy, responsible AI, and secure technology use.
- Provide strategic cybersecurity, privacy, AI risk, and compliance consultation for Technology Services projects, software and vendor evaluations, enterprise systems, security solutions, emerging technologies, infrastructure modernization, cloud initiatives, and District departmental partnership.
- Serve as the District's designated Cybersecurity Coordinator and liaison for cybersecurity matters with applicable state, federal, regulatory, law enforcement, cyber insurance, forensic, educational, professional, and information-sharing organizations, including coordination of grant opportunities, program requirements, and reporting activities.
- Prepare and present accurate cybersecurity, privacy, AI governance, compliance, risk, incident, remediation, maturity, metrics, recommendations, and program-effectiveness reports to executive leadership, Superintendent-level committees, and the Board of Trustees, as assigned
- Perform other duties as assigned
SUPERVISORY RESPONSIBILITIES:
- Supervises and directs the application security specialist, vendors performing cybersecurity-related work, and other assigned personnel as needed.
WORKING CONDITIONS:
- Willing to work occasional prolonged, irregular, or non-scheduled hours, including planned maintenance, incident response, or other operational needs.
- Ability to maintain emotional control under stress.
- District-wide and out-of-District travel travel required; must maintain a valid Texas driver's license
- Ability to receive and convey information or instructions to internal and external customers through spoken communication
- Ability to see detailed information, naturally or with correction, and manipulate tools, equipment, and keyboards
- Work may involve conditions associated with installing, configuring, lifting, moving, and accessing computer equipment and networks, including bending, kneeling, and crawling
- Ability to see detailed information, naturally or with correction.
- Conditions associated with installing and configuring computer equipment and networks.
- Lifting, moving, bending, kneeling, and crawling are frequently required.
TERMS OF EMPLOYMENT:
- This job description describes the general purpose and responsibilities assigned to this job and are not an exhaustive list of all responsibilities, duties, and skills that may be required. Other duties may be assigned as deemed appropriate. The pay grade, pay code, and work year listed are intended to be informational and not contractual in nature.
Job Description Revised September 18, 2026
For assistance or more information, see our Jobs and Applications Page
or you may contact:
CCISD Human Resources - (361) 695-7250
Auxiliary Applicant Tracking / Applications
CCISDhr@ccisd.us
CCISD Human Resources
801 Leopard
Corpus Christi, Texas
(Please include the Job Posting Number with any correspondence.)
Salary: INTA/307: Salary range is $333.88 to $467.76 daily (individual salary calculation is based on applicable experience)
See the CCISD Salary Schedule handbook for information regarding initial salary placement.
Days: 226