Information Security Officer
Core
Lead the Information Security Program to maintain a mature security posture, ensuring compliance with Commonwealth of Virginia IT security policies and standards.
Role type
Senior Information Security Officer (Program Lead)
Builds
Enterprise information security program, policies, controls, and governance frameworks
Domain
Public sector / Regulated environment / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Risk assessment, security audits, compliance reviews, NIST-based framework implementation, security policy development, security awareness training, third-party risk management, incident response, vulnerability management, executive reporting
Preferred skills
Public-sector experience, regulated environment experience
Technologies
Security TDD
Responsibilities
Develop and manage an information security program meeting state policies; create and maintain security policies, standards, and procedures; build and sustain security awareness and training programs; implement preventive, detective, and corrective controls; lead system audit and assessment activities; lead cybersecurity governance, risk management, privacy, and compliance initiatives; oversee third-party security reviews and vendor risk assessments; partner with IT leadership on security operations and incident response; coordinate business continuity and disaster recovery planning; prepare executive-level reporting on cybersecurity risk.
Seniority
Senior, hands-on IC with leadership responsibilities