Vice President, Information Security & Risk
ThresholdsAbout the role
The Vice President (VP), Information Security & Risk is responsible for leading the execution and continuous improvement of the Thresholds information security and risk management program. The scope of the program is the protection of Thresholds’ information and technology assets as well as Thresholds’ digital data in the cloud. The VP, Information Security & Risk is accountable for fulfilling the program’s protection and compliance requirements while enabling innovation, analytics, and digital transformation in a secure and compliant manner; provides strong technical leadership; and serves as a trusted advisor to the Chief Information Officer and agency leaders in addition to serving as the agency’s designated security official.
ESSENTIAL DUTIES & RESPONSIBILITIES:
Security Operations and Execution
- Manages the day-to-day information security operations, including security posture and event monitoring, threat and vulnerability identification, policy violation, access control and attack surface monitoring, monitoring the effectiveness of email and URL filtering, and incident response activities.
- Manages the remediation of security issues, policy violation, ineffective rules for access control, attack surface reduction, and email/URL filtering as well as the creation and maintenance of standard operating procedures for security operations.
- Develops and maintains dashboard(s) of security operations KPI’s for Information Technology (IT/ITS) management review.
Application, Cloud, Digital, Infrastructure and Platform Security
- Supports secure implementation and operation of applications, cloud services, infrastructure, and platforms (cloud, digital, end-user, and server).
- Partners with Information Technology Services (ITS) and digital teams to incorporate needed security controls into the design, development, and deployment of Thresholds applications, cloud services, infrastructure, and platforms.
- Performs and/or coordinates risk reviews of application and digital systems, and their underlying configurations.
Data Security and Privacy
- Manages the IT Risk Management Program using Thresholds’ risk management tool to record and assess identified risks, assign a risk owner, track risk treatment progress in the risk register, and provide risk management reporting to ITS leadership.
- Leads enterprise, regulatory, service provider, and project IT risk assessments.
- Supports internal and external audits, regulatory reviews, and customer or partner security inquiries.
Policy, Awareness & Documentation
- Owns development and enforcement of the Information Security & Risk Management Program’s policies, standards, and procedures, as well as the agency’s Acceptable Use Policies.
- Leads or oversees security awareness and training programs for the agency and the ITS staff.
- Maintains and improves the Incident Response Playbook.
Collaboration and Continuous Improvement
- Serves as a trusted advisor to business units and project teams on matters related to AI security, application security, information security, network security, AI risk, IT risk, regulatory compliance, emerging threats, social engineering, data classification; promoting security as a mission enabler for Thresholds.
- Promotes a strong, practical security/risk culture that balances protection with usability and business needs.
- Influences decisions by clearly articulating risk, tradeoffs, and recommendations.
Program Leadership and Strategy Execution
- Embeds security by design principles into system implementations, vendor selection, and operational processes.
- Translates security strategy into actionable roadmaps, initiatives, and measurable outcomes.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s