Information Security Officer - Director's Office - CF051
Virginia.govAbout the role
Title: Information Security Officer - Director's Office - CF051
State Role Title: Info Technology Specialist III
Hiring Range: $120,000 - $140,000
Pay Band: 6
Agency: Department of Forensic Science
Agency Website: https://dfs.virginia.gov/
Recruitment Type: General Public - G
Job Duties
The Virginia Department of Forensic Science has recently moved to a new, state-of-the-art facility in Hanover County.
Join our team as an Information Security Officer and play a vital role in safeguarding the critical information and technology systems that support public safety, forensic science, and the justice system. The Department of Forensic Science (DFS) is seeking an Information Security Officer (ISO) to lead the agency’s Information Security Program and ensure compliance with Virginia Information Technologies Agency (VITA) security standards. Reporting directly to the Agency Director, the ISO collaborates with agency leadership, IT staff, and external partners to protect systems essential to agency operations.
The ISO is responsible for developing and maintaining DFS information security policies and standards; managing system classifications, risk assessments, security exceptions, and required documentation; and administering the IT Security Audit Program. The ISO serves as the primary liaison to the Commonwealth’s Chief Information Security Officer (CISO), VITA officials, auditors, and external partners, and maintains the required annual ISO certification.
Key responsibilities include overseeing IT infrastructure security, vulnerability management, incident response, and continuity and disaster recovery planning. The ISO designs and implements internal controls and procedures aligned with evolving technologies, statutes, regulations, and VITA policies. Additional responsibilities include managing the Security Awareness and Training Program for staff, contractors, and IT service providers; advising leadership on security risks and compliance obligations; supporting the Systems Development Lifecycle (SDLC) by ensuring IT security is integrated into system planning and development; and serving as the agency’s eVA (the Commonwealth’s electronic procurement system) Security Officer.
Telework may be available up to two days per week after completion of agency training and orientation.
The ISO uses DFS and VITA resources to actively monitor the agency’s security posture. Responsibilities also include reviewing and reporting findings from VITA vulnerability scans and expanding monitoring efforts using new VITA-provided tools for server, network, and firewall logging. As VITA deploys enterprise logging and monitoring platforms such as Splunk statewide, the ISO will incorporate these tools into DFS security monitoring to provide real-time awareness of potential threats to sensitive systems.
If you are ready to apply your expertise to protect the integrity of forensic data and the systems that support public safety, we encourage you to apply!
Minimum Qualifications
• Experience developing, implementing, and monitoring information security policies, standards, and procedures
• Experience evaluating and monitoring IT environments for compliance with information security architecture, policies, and standards
• Experience managing or supporting a comprehensive information security program
• Experience in application security, contingency planning, IT risk management and governance, incident management, information security reviews, and security awareness training
• Experience conducting risk assessments and audits, implementing security controls and compliance, and executing security incident response
• Strong project management skills with the ability to prioritize tasks, meet deadlines, and manage multiple concurrent activities
• Ability to effectively communicate complex technical information verbally and in writing to diverse audiences and multiple levels of management
• Ability to interpret technology and security standards and ensure agency compliance
• Ability to implement and validate appropriate controls for IT applications and information resources
• Ability to work in a fast-paced environment and quickly acquire new knowledge or skills to meet organizational needs
• Must obtain and maintain the Commonwealth of Virginia (COV) ISO Certification within the first year of employment, in accordance with VITA requirements, or hold an equivalent professional information security certification s
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s