Example Job Description
Chief Information Security Officer
An executive security leader who establishes independent visibility, risk-based protection, incident readiness, and resilient recovery across district information and technology services.
Interview Planning Resource
Possible Interview Q&A: Chief Information Security Officer
How to use this resource: Select questions that measure competencies established through the district’s current job analysis. Ask candidates the same predetermined questions under comparable conditions and evaluate responses against the same job-related criteria.
The indicators below describe evidence a strong response may contain; they are not required scripts or the only acceptable answers.
- How would you establish priorities and a practical annual work plan for district identity, network, endpoint, cloud, application, data, logging, vulnerability, backup, and incident-response capabilities?
Strong response indicators: Connects district goals and user needs to risk, dependencies, capacity, owners, milestones, service measures, communication, and review rather than producing an unranked project list.
- Describe a time you found that a familiar process or report was producing unreliable results. How did you investigate and correct it?
Strong response indicators: Defines the expected result, traces evidence to authoritative sources, distinguishes symptoms from root causes, involves accountable owners, tests the correction, reconciles downstream effects, documents decisions, and monitors recurrence.
- You encounter a suspected compromise affecting student services, confidential information, or district operations. What would you do first, and how would you manage the issue through resolution?
Strong response indicators: Protects people and continuity, establishes scope and authority, preserves evidence, engages the right owners, communicates proportionately, documents decisions, verifies recovery or correction, and completes a lessons-learned review.
- How would you work with executive leaders, CIO and technology teams, privacy and legal staff, school leaders, employees, insurers, law enforcement, vendors, and public partners when they disagree about priorities or the acceptable level of risk?
Strong response indicators: Clarifies decision rights and shared purpose, surfaces evidence and constraints, distinguishes requirements from preferences, documents options and residual risk, facilitates a timely decision, and escalates through established authority when needed.
- What controls would you put in place before making a significant change to district identity, network, endpoint, cloud, application, data, logging, vulnerability, backup, and incident-response capabilities?
Strong response indicators: Includes requirements, ownership, risk and privacy review, representative testing, accessibility where relevant, approvals, change communication, rollback or contingency, validation, monitoring, documentation, and support readiness.
- How would you decide what to automate and what should retain meaningful human review?
Strong response indicators: Selects stable, repeatable, testable work for automation; preserves human authority for exceptions and consequential judgments; addresses access, logging, bias or error, monitoring, failure recovery, documentation, and periodic reassessment.
- How would you explain a serious technical, instructional, operational, or data concern to a leader who does not work in your specialty?
Strong response indicators: States the affected people and services, evidence, uncertainty, consequence, deadline, accountable owners, options, recommendation, residual risk, and next update in plain language.
- What would you do when a request exceeds operational IT ownership, privacy and legal determinations, law-enforcement authority, executive risk acceptance, and communications authority?
Strong response indicators: Recognizes the limit, avoids unauthorized action, clarifies the legitimate need, preserves service where possible, routes the decision to the authorized owner, documents the handoff, and follows through without abandoning the requester.
- How would you protect confidential information while still providing useful service and appropriate access?
Strong response indicators: Applies purpose limitation, minimum necessary access, role-based permissions, secure transmission and storage, approved retention, understandable communication, auditability, timely removal, and incident escalation.
- How would you build staff capability so your office does not become the permanent fixer of every problem?
Strong response indicators: Uses clear ownership, role-based training, usable procedures, coaching, feedback loops, office hours, communities of practice, quality reports, cross-training, and measures whether source practices improve.
- What evidence would you use to determine whether your work is improving material risk reduction, control coverage and effectiveness, detection and response, recovery readiness, vulnerabilities, exceptions, training behavior, and resilience?
Strong response indicators: Uses a balanced set of outcome, implementation, service, risk, equity, and user-experience measures; disaggregates appropriately; explains limitations; establishes baselines and review cadence; and changes course when evidence warrants.
- What would you prioritize during your first 90 days?
Strong response indicators: Would establish executive access and authority, assess critical assets and current threats, review incidents and recovery evidence, validate identity and backup priorities, clarify risk acceptance, and publish a prioritized security roadmap; listens before redesigning, identifies urgent risks, delivers credible early improvements, and creates an achievable longer-term roadmap with owners and measures.
Position Description
Under the direction of the appropriate district administrator, the Chief Information Security Officer leads the district cybersecurity program and advises executive leadership on material information-security risk, controls, incidents, resilience, and investment.
The position connects policy, people, process, information, and technology; establishes repeatable practices; makes unresolved risk visible; and supports continuous improvement without displacing the authority of designated program, legal, privacy, security, fiscal, instructional, or executive decision-makers.
Reports To
Illustrative reporting relationship: Superintendent, chief information officer, chief business official, or other executive with direct escalation access appropriate to local governance. Insert the school district’s approved reporting relationship here.
Required Education and Credentials
Required
- Bachelor’s degree in cybersecurity, information systems, computer science, engineering, public administration, or a related field; a graduate degree is preferred.
- Relevant cybersecurity certification such as CISSP, CISM, CISA, GIAC, or comparable evidence of competence is preferred and may be locally required.
- Successful completion of all district-required employment clearances and assigned privacy, security, accessibility, records, and safety training.
Preferred
- Graduate study, advanced coursework, or current professional learning directly related to the position’s assigned scope.
- Relevant training in project management, facilitation, change management, data-informed improvement, and public-sector service.
Required / Desired Experience
Required Experience
- Progressively responsible cybersecurity leadership spanning governance, risk, architecture, operations, incident response, vendor risk, and workforce development.
- Experience coordinating deadline-driven work with multiple departments, users, or school sites.
- Experience handling confidential information and documenting decisions, exceptions, and completed work.
Desired Experience
- K–12 or public-sector experience implementing the NIST Cybersecurity Framework, CISA guidance, identity security, zero-trust principles, cloud security, testing, recovery, and executive reporting.
- Experience developing procedures, training users, improving processes, and supporting continuity during staff or system changes.
Essential Duties and Responsibilities
Security Governance and Risk
- Develop cybersecurity strategy, charter, policies, standards, risk methodology, control baseline, exception process, and multiyear roadmap.
- Maintain a current view of critical services, information assets, threats, vulnerabilities, dependencies, controls, owners, and residual risk.
- Advise executive leadership and governing bodies on material risk, incidents, investment choices, accepted exceptions, and overdue remediation.
Security Architecture and Operations
- Set security requirements for identity, networks, endpoints, cloud, applications, integrations, data, logging, backups, and administrative access.
- Coordinate vulnerability management, secure configuration, detection engineering, monitoring, penetration testing, remediation validation, and threat intelligence.
- Partner with technology owners to embed security in architecture, acquisition, projects, changes, and service lifecycle decisions.
Incident Response and Resilience
- Maintain and exercise incident-response, ransomware, communications, evidence, continuity, disaster-recovery, and cyber-recovery plans.
- Coordinate triage, containment, investigation, eradication, recovery, notification support, lessons learned, and return-to-service criteria.
- Verify recovery capabilities through protected backups, restoration tests, dependency analysis, alternate procedures, and executive exercises.
Third-Party Risk and Workforce
- Establish proportionate security review and contractual requirements for vendors, cloud services, applications, integrations, and material changes.
- Deliver role-based security awareness, simulations, technical development, and leadership exercises tied to observed risk.
- Develop security staff, metrics, documentation, succession, and partnerships; perform other related duties consistent with classification.
Required Skills and Abilities
Knowledge of
- NIST Cybersecurity Framework, NICE Framework concepts, CISA K–12 guidance, threat and risk management, security architecture, and control assessment
- Identity, network, endpoint, cloud, application, data, vulnerability, logging, detection, response, backup, recovery, and secure configuration practices
- Student and employee privacy, records, breach and incident coordination, vendor risk, cyber insurance, public-sector procurement, and responsible disclosure
- Executive risk communication, policy, audit, workforce development, tabletop exercises, continuity, and crisis leadership
Ability to
- Translate technical findings into decision-ready risk statements, treatment options, owners, deadlines, and residual risk
- Maintain appropriate independence while partnering constructively with technology, privacy, legal, program, and executive leaders
- Lead calm, evidence-preserving incident coordination under uncertainty and time pressure
- Prioritize controls by mission impact and threat rather than tool availability or compliance theater
- Assess vendor and cloud claims critically and require evidence proportionate to risk
- Build a security culture through usable controls, role-based learning, transparent exceptions, and accountable leadership
Work Environment
- Work is performed primarily in district offices, schools, meeting rooms, training environments, and other computer-based professional settings, with remote participation as authorized.
- The position requires extended computer use and detailed review of records, systems, reports, procedures, communications, or technical documentation.
- Work involves frequent coordination with executive leaders, CIO and technology teams, privacy and legal staff, school leaders, employees, insurers, law enforcement, vendors, and public partners.
- The employee may encounter competing priorities, interruptions, confidential matters, fixed deadlines, and time-sensitive problems requiring calm, documented judgment.
- Workload may increase during school opening and closing, reporting cycles, audits, major changes, incidents, and other critical district operations.
Other Requirements
- Successfully complete required criminal-record, fingerprint, and employment clearances.
- Complete a tuberculosis risk assessment and any examination required by applicable law or district policy.
- Complete district-required cybersecurity, privacy, accessibility, nondiscrimination, workplace-safety, and records-management training.
- Maintain professional confidentiality and comply with district policies governing records, information security, acceptable technology use, conflicts of interest, and data access.
- Travel between district offices, schools, meetings, training locations, and professional-development activities as assigned.
- Possess a valid California driver’s license and maintain insurability when driving is an essential function of the position.
- Occasionally work evening, weekend, or extended hours during critical operations, incidents, deadlines, public meetings, or system transitions.
- Regularly sit, stand, walk, speak, hear, read, and operate computers and standard office equipment; occasionally lift, carry, or move records, equipment, or supplies weighing up to 25 pounds.
- Perform the essential functions of the position with or without reasonable accommodation.







































































