Job Description:
- As the Agency Information Security Officer, you’ll serve as a trusted security advisor supporting executive agencies through cybersecurity engagement, risk management, operational planning, and enterprise security initiatives.
- This is an opportunity to work directly with agency leaders, IT teams, and security stakeholders to help protect critical public services while strengthening how cybersecurity is managed.
- Reporting Agency Information Security Officer Manager, this role provides consultative, strategic, and operational support across agency and IT environments to help strengthen security programs, guide cross-functional efforts, and support statewide security priorities.
- This position plays a key role in advancing enterprise security planning, coordinating cybersecurity activities across agencies and IT divisions, supporting incident response and operational recovery efforts, and helping align security practices with National Institute of Standards and Technology (NIST) guidance and statewide cybersecurity objectives.
- The role also supports program planning, stakeholder communication, operational readiness efforts, and continuous improvement initiatives tied to the Information Security Program.
- You’ll collaborate with agency leadership, technical teams, operational stakeholders, vendors, and security personnel to identify risks, support security planning initiatives, and help strengthen cybersecurity practices.
What You’ll Do
- No two days look quite the same in IT’s Information Security Office. In general, you can expect to:
- Lead Security Coordination: Manage and coordinate cybersecurity program plans, stakeholder engagement, and cross-functional initiatives aligned to agency and statewide priorities.
- Partner with Agencies: Collaborate with agency leadership, technical personnel, business teams, and security stakeholders to support risk management and security planning.
- Coordinate Incident Response Efforts: Assist with incident response support, escalation management, communication planning, and restoration activities supporting continuity of business operations.
- Support Security Planning: Contribute to the development, implementation, maintenance, and review of security plans, procedures, workflows, and program documentation supporting enterprise cybersecurity operations.
- Evaluate Security Gaps: Review technical and business information to help identify security gaps, process improvements, and opportunities to strengthen cybersecurity coordination efforts.
- Advance Cross-Functional Collaboration: Work with agencies, IT divisions, contractors, vendors, and external stakeholders to align security priorities, timelines, deliverables, and organizational objectives.
- Contribute to Continuous Improvement Efforts: Support updates to cybersecurity documentation, processes, security procedures, and program management activities based on lessons learned, business needs, and evolving security priorities.
Why This Role Stands Out
- As a cybersecurity professional you have a lot of options when it comes to your career. We get it. Here’s what sets our role apart:
- Strategic Impact: Help shape security practices that support agencies in safely delivering essential services to the State and its communities.
- Statewide Visibility: Collaborate with agencies, technical teams, leadership, and operational stakeholders supporting cybersecurity coordination across diverse environments.
- Professional Growth: Expand your experience supporting enterprise security operations, incident coordination, risk management, and statewide cybersecurity initiatives.
- Work That Matters: Strengthen the security of public services so residents can rely on government systems that operate safely and securely.
If you are seeking a culture that supports growth, fosters success, and want to play a key role in maintaining the confidentiality, integrity, and availability of data and systems, then the client is where you need to be! With the IT Information Security Office, you can expect:
- Generous Telework Opportunities: This position has the opportunity to work 90%-100% remotely.
- Meaningful & Impactful Work: Play a vital role supporting statewide cybersecurity coordination and operational resilience efforts.
- Supportive Team: Join a collaborative, professional environment that invests in your development.
- Work-Life Balance: Flexible scheduling and a healthy balance of professional and personal time.
- Innovative Culture: Be part of a team that values innovation and continuous improvement.
Minimum Qualifications:
- Bachelor’s degree in cybersecurity, information technology, computer science, information systems, or a related field. Equivalent combinations of education, training, certifications, and relevant experience will also be considered.
- A minimum of 5 years of professional experience in cybersecurity, information security, risk management, security governance, compliance, security program support, or related disciplines.
- Experience supporting or applying cybersecurity frameworks, standards, or guidance, including NIST-based security practices.
Preference will be given to candidates with:
- Understanding of cybersecurity governance concepts, risk management principles, and security planning practices
- Demonstrated success building collaborative relationships across business, technical, and leadership stakeholder groups
- Ability to communicate security risks, priorities, and recommendations to varied audiences
- Background supporting incident coordination, security planning initiatives, or enterprise cybersecurity programs
Preferred Competencies:
- Relationship Management: Builds trusted working relationships across agencies, technical teams, and leadership groups supporting statewide cybersecurity efforts.
- Risk Awareness: Able to recognize operational and security concerns, evaluate potential impacts, and support risk-based decision-making.
- Security Framework Familiarity: Understanding of cybersecurity standards, regulatory expectations, and NIST-aligned security practices.
- Consultative Approach: Comfortable advising stakeholders, facilitating discussions, and helping teams navigate security planning and incident-related matters.
- Executive Communication: Able to present technical and security information clearly to both technical and non-technical audiences.
- Prioritization: Capable of balancing competing priorities, managing sensitive situations, and working effectively within dynamic environments.
#LI-Remote




