In addition to evaluating each candidate's relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate:
Knowledge of: Enterprise information security principles, frameworks, and practices, including security governance, risk management, incident response, vulnerability management, and security architecture; service-oriented and event-driven architecture, systems design, technology integration, and infrastructure platforms/protocols; IT project management methodologies, research and development approaches, IT service management, and organizational change management; regulatory and compliance requirements, including HIPAA, SOX, PCI, NIST, GLBA, CMS, and SSA directives, and how these requirements apply within large public-sector environments; data privacy laws, practices, and safeguards, including secure data acquisition, protection, transmission, retention, and disposal; organization and functions of California State Government, including its policies, principles, and governance structures; technical concepts across major IT domains such as networking, applications, databases, operating systems, cloud platforms, identity management, and endpoint protection; international, federal, state, and local laws governing data security and privacy; enterprise IT disciplines and how they interrelate (infrastructure, servers, networks, databases, applications, security operations, etc.) to support business missions.
Ability to: Lead and manage enterprise information security programs, including policy development, risk assessment, incident response, and compliance oversight; develop strategic plans, aligning security initiatives with organizational priorities, and translating complex security requirements into actionable operational activities; supervise, mentor, and develop technical and managerial staff, fostering teamwork, accountability, professional growth, and continuous improvement; analyze, problem-solve, and evaluate complex technical environments, identify risks, and recommend effective mitigation strategies; communicate clearly and effectively with executive leadership, program staff, and technical teams, including the ability to explain complex security concepts to non-technical audiences; evaluate, select, and implement security technologies, tools, and platforms to strengthen enterprise security posture; manage large-scale security projects and initiatives, including timelines, resources, dependencies, and change management; conduct and oversee security assessments, audits, and reviews using automated tools, documentation analysis, and stakeholder interviews; interpret and apply federal and state laws, regulations, and standards governing information security and privacy; build partnerships with program leaders, regional centers, external partners, and state oversight entities to align security expectations and drive compliance; develop and maintain disaster recovery and technology contingency plans, including conducting business impact analyses and coordinating recovery exercises; negotiate, coordinate, and manage vendor relationships related to security products, services, and third-party compliance requirements; oversee and ensure proper handling, protection, and transmission of sensitive and confidential data across complex distributed environments.