Job Description
Posting number: FY27-00017
Department: IT Services
Job classification: IT Security Risk & Compliance Officer
Posting type: Open (External and Internal)
Categories: IT and Computers, Professional, Miscellaneous
Summary
One City. One Secure Future. One Stronger Digital Community.
In today’s digital world, cybersecurity is more than protecting systems—it’s about protecting the information, services, and people who rely on them every day. As the IT Security Officer, you’ll play a critical role in strengthening the City’s cybersecurity foundation by leading governance, compliance, risk management, and security initiatives that help keep our organization resilient and prepared for what’s next.
This is an opportunity to make an impact behind the scenes while helping safeguard the technology that keeps the City of Wilmington connected, innovative, and moving forward.
Why This Position Is Important
Cybersecurity touches every part of the organization. The work of this position helps ensure that the City’s technology, information, and operations are protected against evolving threats while remaining aligned with industry standards, regulatory requirements, and organizational goals.
As the Security Officer, you will:
- Lead cybersecurity governance and regulatory compliance efforts across the organization.
- Develop, implement, and maintain security policies, procedures, and compliance frameworks.
- Conduct risk assessments and monitor vulnerabilities to identify and address potential threats.
- Coordinate audits and compliance activities to strengthen accountability and security practices.
- Partner with IT divisions, leadership, and other stakeholders to promote consistent security standards.
- Provide guidance on cybersecurity best practices and help translate complex security requirements into practical solutions.
- Lead initiatives that continuously strengthen the City's overall security posture while supporting business and operational needs.
Your expertise will help the City stay ahead of emerging threats, protect critical information, and build a culture where security is everyone's responsibility.
Examples of duties
- Develop and maintain an enterprise-wide cybersecurity strategy aligned with organizational goals.
- Lead the cybersecurity program, including governance, architecture, operations, and incident response.
- Provide regular briefings to executive leadership and City Council on security risks and posture.
- Develop and enforce security policies.
- Oversee risk assessments and audits.
- Coordinate security training and engagement across departments, including the development, implementation, and oversight of training programs.
- Serve on committees and review technology upgrade requests.
- Ensure secure design of IT systems, cloud platforms, networks, and applications.
- Guide secure configuration management and change management processes.
- Evaluate and approve security controls for new systems and technologies.
- Oversee organization-wide cybersecurity training and phishing simulation programs.
- Promote a culture of security through continuous awareness initiatives.
- Assess the security posture of technology vendors and hosted/cloud solutions.
- Ensure contractual security requirements are defined and enforced.
- Present to leadership and council as needed.
Qualifications
- Bachelor’s degree in Information Technology, Cybersecurity, or related field (Master’s preferred).
- Five (5) years progressive experience in IT and cybersecurity, including leadership roles. Experience in government, critical infrastructure, or regulated environments is preferred but not required.
Certifications:
- CISSP, CISM, CISA, CRISC, CGCIO (for public sector) or a related credential is preferred but not required.
Knowledge of:
- Familiarity with established frameworks like NIST, CIS Controls, and Risk Management methodologies so they can develop informed policies and evaluate compliance effectively.
- Current issues, trends, and management theories related to technology plan development, implementation and maintenance.
- Knowledge of technology plan development and compliance frameworks.
Skilled in:
- Ability to clearly articulate complex IT concepts and solutions in a way that is understandable to non-technical stakeholders
- Proven ability to design and deliver effective cybersecurity training programs and communicate security solutions that enhance user awareness and compliance.
- Skilled in creating and enforcing security policies aligned with frameworks like NIST and CIS Controls.
Ability to:
- Troubleshoot, organize, and simplify complex technical problems to effectively scope and delegate projects and tasks.
- Analyze, interpret, summarize, and present administrative and technical information and data in an effective manner.
- Ability to respond quickly and effectively to security incidents, ensuring continuity of operations and minimizing impact.
- Ability to guide and support a team while fostering collaboration and achieving shared goals.
Supplemental information
PHYSICAL DEMANDS:
· Office Work: Primarily sedentary, involving prolonged sitting, computer use, telephone and office equipment operation, and standard office tasks. Requires visual acuity, hearing, and manual dexterity for reviewing documents, analyzing data, and completing administrative responsibilities.
· General Requirements: The position involves occasional travel to meetings, evening events, or after-hours response. All work is performed in compliance with applicable State and Federal OSHA regulations, including hazard communication, personal protective equipment, and slip, trip, and fall prevention.
WORKING CONDITIONS:
This position is primarily office-based, utilizing standard office equipment in a climate-controlled setting and adhering to applicable safety and ergonomic guidelines.
The position functions in a fast-paced, collaborative, and public-facing municipal environment, involving interaction with elected officials, employees, community members, and external partners. Attendance at evening meetings and occasional after-hours or emergency response may be required.