Chief Information Security Officer
Commonwealth of MassachusettsAbout the role
Description
Executive Office of Housing and Livable Communities (EOHLC) is seeking a Chief Information Security Officer in the Information Technology Unit!
AGENCY MISSION:
The Executive Office of Housing and Livable Communities (EOHLC) is charged with creating more homes in Massachusetts and lowering housing costs for residents.
Formerly known as the Department of Housing and Community Development (DHCD), EOHLC works with municipalities, local housing authorities, non-profit organizations, and development partners to provide affordable housing options, financial assistance, and other support to Massachusetts communities.
OVERVIEW OF ROLE:
As the Commonwealth of Massachusetts advances its mission to enhance information technology (IT) efficiencies and effectiveness, the EOHLC Chief Information Security Officer (CISO) will assess, design, deploy, monitor and continuously improve upon the Executive Office of Housing and Livable Communities (EOHLC) security posture.
Working in partnership with the Commonwealth Secretariat Chief Information Officer (SCIO), the dedicated EOHLC Secretariat CISO provides strategic and tactical information security direction for the Executive office, and each of the divisions within the Secretariat. The EOHLC-CISO is a member of the strategic IT organizational pillars working to transform the delivery of IT services and secured availability of data within the EOHLC Secretariat.
Working for the EOHLC SCIO and in partnership with the Executive Office of Technology Services and Security (EOTSS) CISO, responsibilities may include the following:
· Implements EOTSS security framework and ensures compliance
· Participates in the change management process with the EOTSS CISO
· Responds to Executive order changes regarding security and confidentiality of citizen information.
DUTIES AND RESPONSIBILITIES (NOT ALL INCLUSIVE):
1.Design, Deploy & Monitor
· Implements a security, governance and control framework for EOHLC.
· Develops, initiates, maintains and revises security policies and procedures.
· Monitors emerging technologies for potential impacts to operations and long-term strategy.
· Ensures adherence to legal standards regarding information security compliance; implements and follows industry standards and best practices for security compliance; and develops reliable, efficient, and effective project development processes.
2. Risk Assessment:
· Identifies potential areas of compliance vulnerability and risk.
· Directs the development and implementation of corrective action plans for resolution of identified issues.
· Coordinates risk management and internal audit to direct compliance issues to appropriate reviewing bodies.
3. Interagency Security Operations:
· Provides strategic and tactical advice to address existing and evolving security threats.
·
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s