WORK DESCRIPTION - DESCRIPTION DE TRAVAIL FUNCTIONAL GENERIC WORK DESCRIPTIONS Job/Generic Number - Numéro d'emploi/de générique GNCS040005 Job/Generic Title - Titre d'emploi/de générique Manager, Security Job/Generic Classification - Classification d'emploi/de générique CS 04 National Occupation Code - Code national des professions 0213 - Computer and Information Systems Managers Supervisor Position Number(s) - Numéro du poste du surveillant Supervisor Position Title(s) - Titre du poste du surveillant Director, Security GNCS050002 Client Service Results - Résultats axés sur le service à la clientèle Management and expert advisory services in the delivery of information technology security and secure electronic service delivery (SESD) strategies, processes and tools for a Department or Agency and its external partner organizations. Key Activities - Activités principales Manages the employees of a unit composed of technical staff led by subordinate team leaders; establishes and manages departmental and interdepartmental teams and committees. Manages allocated budgets. Manages response teams during security threats as required. Manages the development and implementation of SESD according to Government standards. Assigns and manages multi-disciplinary SESD project teams conducting threat/risk assessments of IT and voice/data systems, analysing, developing and implementing SESD initiatives, and proposing, planning, designing and testing procedures and mechanisms to address security problems and issues. Provides and manages the provision of expert technical advice and assistance to clients on the development of strategies, initiatives and projects that will assess emerging security technologies. Manager, Security Page 1 of 7
Represents the IT Organization as the manager responsible for IT Security for the Department in consultation and negotiation with senior managers within the department, senior IT officials of other federal departments or external organizations with authority to seek common ground to move initiatives forward. Brings security files forward for effective corporate decision-making. Chairs or facilitates project-related meetings with project sponsors, other stakeholders and vendor representatives. Chairs or participates in departmental and inter-departmental meetings and committees as required. Maintains knowledge of trends and developments in computer systems analysis, IT risk and security, SESD development and implementation, and security standards, policies and directions. Employee's Statement - Déclaration de l'employé I have been given the opportunity to read and comment on the content of this work description. J'ai eu l'occasion de lire et commenter le contenu de cette description de travail. Name of Employee - Nom de l'employé Signature Date Supervisor's Statement - Déclaration du surveillant This work description accurately describes the work assigned to this position. Cette description de travail décrit adéquatement le travail assigné à ce poste. Name of Supervisor - Nom du surveillant Signature of Supervisor - Signature du surveillant Date Authorization - Authorisation Name of Manager - Nom du gestionnaire Manager's Signature - Signature du gestionnaire Date Manager, Security Page 2 of 7
Skill - Habiletés The work requires the knowledge of: Theories, principles and practices of IT security, IT operations security and SESD development and implementation to serve as an expert on the development of special IT security applications and to manage an organization and related projects. Theories, principles and practices of computer science, application development as it applies to IT risk and security, System Development Life Cycle (SDLC), the development, coordination, implementation, monitoring and maintenance of IT security protocols to manage the development and implementation of secure electronic service delivery linked to Government of Canada security standards. Theories and principles of secure electronic messaging infrastructure development and implementation to manage an organization and projects involved in the development and implementation of secure electronic service delivery linked to Government of Canada security standards. Communication and interconnectivity concepts, operating systems, critical analysis, high and low grade encryption and decryption technologies, peripherals, servers, technology platforms, gateways, firewalls, data warehouse architectures, capacity planning processes, product bench marking and testing methodologies, systems migration and implementation techniques, network intrusion detection technologies, and quality assurance concepts and methodologies, to plan and manage the development and implementation of IT security systems and protocols. Principals and practices of strategic and business analysis and planning, financial management and administrative management at a sufficient level of understanding to apply them to IT security planning, to serve as a source of knowledge for senior managers, and permit the provision of sound planning advice to senior managers on planning and resource utilization for security. Methods and techniques related to project management to conduct related cost-benefit analyses; to manage resources; to develop plans and reports; and, to plan, allocate, monitor and approve the work performed by project team members Policy and program objectives of the Department, departmental client organizations, and external clients to identify and assess potential inter-organizational IT risk and security, and SESD strategies and initiatives management projects and provide expert advice to clients on their implementation. Legislation, regulations and Government policies relevant to the position. Leadership and management theory, principles, and practices to lead committees, project teams, manage a unit through subordinate supervisors and provide guidance to employees. Departmental, federal, Canadian and international standards, trends and developments in IT Manager, Security Page 3 of 7
security and SESD processes and requirements to assess current and future applicability of products and services and Canadian and foreign vendor and consultant proposals; to manage the planning, development and implementation of IT security and SESD initiatives. Trends and developments in the interrelationships between corporate and program management evolution and IT security evolution and their implications for the longer term IT security requirements of clients. The work also requires: Negotiation skills to conduct consultation and negotiation to enforce the application of security policies and for the effective use of security resources, develop service level and project funding agreements; and to negotiate with contractors, suppliers and other technical staff Analytical skills to review reports, plans and proposals; to conceptualise and manage the development of IT security strategies and plans; to develop advice, solutions and recommendations for the implementation and improvement of the IT security infrastructure. Verbal skills to communicate technical security information; to make presentations to senior management dealing with high level technical subject matter; and when representing the IT Organization in consultations and negotiations with senior managers within the Department, senior IT officials in other federal departments and other external organizations. Writing skills to produce contract specifications, strategies, correspondence and documents related to IT security. Effort - Efforts Intellectual: Intellectual effort is required to: Provide technical expertise and leadership in the delivery of IT security and SESD strategies, processes and tools with senior managers within the Department, senior IT officials in other federal departments and external organizations. Develop and recommend to IT senior managers and to departmental clients alternative solutions to address IT security issues requiring emerging electronic security technologies in supporting the achievement of operational and strategic objectives of the Department. Develop and manage security delivery frameworks which involves developing strategies, plans and procedures; managing the design of secure systems; writing reports; advising clients and senior management; negotiating services from suppliers, and developing and evaluating recommendations. Manager, Security Page 4 of 7
Manage the identification of security threats or risks with IT and voice/data systems and the development and implementation of SESD initiatives. Judgment and innovative thinking is required to develop strategies, plans and systems for clients meeting the overall department security goals and objectives. Activities, recommendations and decisions have an impact on the Department and affect: the successful mitigation of security threats, and the planning, development and delivery of the Department s IT security program; the development of business resumption plans; the security of the department s IT systems; the expenditure of funds related to budgets, contracts and capital expenditures; the training of departmental employees on IT security processes; the effective utilization of human resources; the development of IT security frameworks, strategies and policies; the development of IT frameworks, strategies and policies; and the attainment of corporate objectives and the alignment of expected results with planned goals. Physical: The work requires sitting for prolonged periods of time when reviewing data, writing reports, business plans, presentations and memos and participating in lengthy meetings and conference calls. May be required to stand to make presentations. Responsibility - Responsabilités The position is responsible for contacts with senior managers, program specialists and with senior technical staff to obtain agreement on requirements for services or on the resolution of technical issues. Manages the work performed by a unit through subordinate supervisors. Provides technical guidance and direction to the work groups and projects. Assigns specialists to work teams and projects, and directs and schedules their work by setting target dates and milestones. Evaluates the performance of staff and recommends training, provides counselling on career paths and assists career advancement. Analyzes human resource requirements to perform the work of the unit and recommends human resource staffing levels through input into business plans. Prepares business cases to support the development, implementation and maintenance of IT security solutions, and prepares cost estimates and recommendations (including cost benefit, technical and risk analysis) for equipment, software, contracts or professional services. Manages allocated budgets, identifies need for expenditures for supplies, equipment and contract services to support project requirements within approved budgets. Negotiates and manages service level agreements and contracts with suppliers of technical expertise and computer systems hardware or software; commits expenditures within established guidelines and procedures. Initiates contract process for services and approves payments on the fulfillment of contract technical specifications. Responsible for a desktop and/or laptop computer, security hardware and software, and for maintaining data integrity, and confidentiality and security in own work. Manager, Security Page 5 of 7
Manager, Security Page 6 of 7
Physical: The majority of the work is performed in an office environment with exposure to computer glare and ambient office noise. Psychological: The work presents exposure to stress to respond to departmental deadlines, unpredictable operational emergencies, on-going time pressures, conflicting demands, and changing priorities. Manager, Security Page 7 of 7