-
The Position
-
The Port of Portland is hiring a Senior Manager- Cybersecurity. Lead the Port of Portland's cybersecurity program to protect critical infrastructure, information systems, and data. This role would establish strategy, governance, and risk management practices. This position would oversee security operations and incident responses while ensuring regulatory compliance. You would also be advising the CIO and executive leadership on cybersecurity risk and priorities on a regular basis. From the Hiring Manager: "Safeguard the Future of the Port of Portland. Are you ready to protect the critical infrastructure, data, and information systems of one of the region's most vital hubs? We are looking for a strategic and visionary Sr. Manager, Cybersecurity to establish and execute the Port of Portland's long-term security framework. In this high-impact, flexible hybrid role, you will be the Port's primary cybersecurity ambassador. Reporting directly to the Chief Information Officer, you will advise executive leadership and drive decisions that influence all business lines. Key highlights of your impact: * Directly supervise a team of three security professionals. * Establish the enterprise cybersecurity program and ensure compliance with strict federal and state regulations, including DHS and PCI-DSS. * Lead a year-round Port-wide culture strategy, transforming security into a shared organizational responsibility. This role goes beyond just technology; it is about building strategic partnerships, championing a culture of awareness, and translating complex threats into actionable business strategies." We offer a flexible hybrid schedule to support both work-life balance and team collaboration. This role CANNOT be performed remotely.
-
Essential Job Duties
-
Risk Management & Compliance:
- Establish and oversee formal enterprise information security risk management program for information security with continuous security posture evaluations through audits, assessments, and compliance reviews.
- Ensure compliance with applicable requirements such as PCI-DSS, CJIS, DHS (TSA & USCG) and state/federal laws.
- Develop Key Performance Indicators (KPIs), Key Goal Indicators (KGIs), and Key Risk Factors (KRIs) evaluating the effectiveness of the organization's cybersecurity strategies and risk management efforts.
- Report findings to both CIO and senior stakeholders on a scheduled basis, communicating cybersecurity threats and risks in business terms.
- Author and update security policies, procedures, and standards ensuring coordinated efforts with Legal, Risk, Internal Audit, Contract & Procurement, and other Port business units.
- Conduct regular information security risk assessments and drive mitigation efforts to acceptable levels.
- Advise project leadership on change risks, adoption barriers, and mitigation strategies.
Strategic Leadership & Governance
- Define and execute the Port's cybersecurity vision, long-term strategy, framework, and road maps, addressing both the regulatory compliance and security risk.
- Provide regular briefings and strategic recommendations to the CIO, executive leadership, and the Commission.
- Establish and maintain governance frameworks, policies, and standards to ensure robust security posture.
Culture & Awareness
- Lead Port-wide cybersecurity culture strategy, ensuring security is understood as a shared organizational responsibility.
- Oversee a year-round security awareness program that delivers clear, consistent messaging and practical training.
- Develop engaging awareness content and campaigns that address current threats and drive measurable behavior change.
- Partner with Communications and business units to promote cybersecurity best practices across all channels.
Cyber Incident Response & Operations
- Lead the organization's Cyber Incident Response Program, including planning, execution, and post-incident analysis.
- Serve as Incident Commander during significant cybersecurity events.
- Develop, implement, and continuously enhance a formal, enterprise-wide vulnerability management program.
Stakeholder Engagement & External Relations
- Build strategic partnerships with government agencies, industry leaders, and regional technology partners.
- Represent the Port with external agencies, industry groups, and regional partners.
Full job description available upon request.
-
Minimum Qualifications
-
Education & Experience
- Eight (8)+ years of experience of progressive IT security experience.
- Three (3)+ years of experience with leadership/management and cybersecurity experience.
- A bachelor's degree in information technology, computer science, or a related field.
- MBS/MA/MS preferred.
- Or equivalent combination of relevant experience.
Licenses & Certifications
- (Required) Ability to obtain and maintain security clearance.
- (Required) Certified Information Systems Security Professional (CISSP), GIAC Information Security Professional (GISP), or equivalent.
- (Preferred) Information Systems Security Management Professional (ISSMP), Certified Information Security Management (CISM), GIAC Security Leadership (GSLC), or equivalent.
Demonstrated Skills & Abilities
- Senior - Information security program development and management.
- Senior - IT infrastructure, cloud, and network security.
- Senior - Enterprise risk management and regulatory compliance (e.g. PCI-DSS, CJIS, etc.)
- Senior - Enterprise Architecture: Expertise in the design, engineering, and secure integration of foundational business-driving technologies.
- Senior - IT Governance: service management frameworks.
- Senior - Budget and contract management.
- Advanced - IT Incident Response: Familiarity with FEMA Incident Command Systems (ICS) standards and practices
-
Supplemental and Selection Information
-
Selection Process: (tentative schedule):
- A minimum qualification evaluation of the education, training, and experience of submitted application packets will take place by Human Resources the week of March 16th.
- A Subject Matter Expert (SME) Panel will perform an evaluation of experience and training taken from your employment application materials.
- Our goal is to schedule the virtual first round of interviews with candidates who successfully passed the SME evaluation on March 23rd. Panel Interviews will be held on April 1st.
-
About us: At the Port of Portland, we use everything we have - our three airports, three working marine terminals, six business parks, and all the resources, expertise, and experience behind them - to move with purpose, connecting people with powerful opportunities and creating value for our region. We know that every person we hire, business we work with, contract we sign and decision we make is a chance to make someone's life better. And we'll use our power and influence to unlock new opportunities and ensure more people share in our region's success. With YOUR help - together with our partners, customers, and community - we'll help drive meaningful change! Do you have questions about this job? Contact us: careers@portofportland.com
Safety: The Port promotes safety as a Core value and we seek to eliminate harm through a culture of active prevention, curiosity, evaluation, and action. We comply with safety and health policies and procedures and consistently look for improvements that support operational excellence. Equal Opportunity Employer: The Port of Portland is dedicated to maintaining and improving a work environment, which extends equal opportunity to all individuals, regardless of their race, color, sex, age, religion, national origin, marital status, veteran status, disability or sexual orientation. Employment decisions shall be made in such a manner as to further the principle of equal employment opportunity and to comply with state, federal and local laws. We affirm through this policy statement our continuing commitment to the principles of nondiscrimination. Veterans Preference: Under Oregon law, qualified veterans may be eligible for veterans' preference when applying for Port of Portland positions. If you are a veteran and would like to be considered for a veteran's preference for this job, please provide the qualifying documents as instructed during the application process. Background Checks and Drug Testing: The Port of Portland will conduct background checks and/or drug tests for positions where such tests are required by regulation and for other safety-sensitive positions. ADA Accommodation: Accommodations will be considered for applicants or candidates with a qualifying disability that prevents them from participating in this process. Accommodations will be made where the Port can reasonably do so without imposing an undue hardship on the business or compromising the integrity of the recruitment process. An applicant with any disability who believes that they need an accommodation should contact Human Resources: call 503-415-6690 or email careers@portofportland.com. Know Your Rights: Workplace Discrimination is Illegal https://www.eeoc.gov/know-your-rights-workplace-discrimination-illegal
|