Deputy Chief Information Security Officer (Hybrid Work Schedule)
Virginia.govAbout the role
Title: Deputy Chief Information Security Officer (Hybrid Work Schedule)
State Role Title: Technology
Hiring Range: $174,447 - $190,000
Pay Band: UG
Agency: Virginia Retirement System
Location: Virginia Retirement System
Agency Website: www.varetire.org/careers
Recruitment Type: General Public - G
Job Duties
The Virginia Retirement System (VRS) is seeking a Deputy Chief Information Security Officer to direct and oversee the technology security operations program for the Investments organization within VRS, focusing on efforts to assure their security program allows their team to function with specific policies, procedures, and controls matched to their requirements.
Under the direction of the Chief Information Security Officer (CISO) this position will serve as a key advisor across the enterprise, including identifying key corporate security initiatives and standards. This position provides subject matter expertise to the VRS security staff developing and implementing technology that will protect the confidentiality, integrity and availability of VRS IT systems and data from unauthorized access and intrusion attempts. In concert with the CISO, this position ensures Technology Security Services staff act as expert resources for the agency and analyzes business needs for the purpose of providing enhanced security solutions and to support agency goals. Additionally, this position will develop and direct all counter-intelligence operations in coordination with Satte and Federal authorities and collaborates with the agency Information Security Officer (ISO) to ensure timely reports to VITA and reconciliation of identified compliance gaps.
Essential functions include but are not limited to:
• Assists CISO with overseeing the Enterprise information technology security program and operations.
• Possesses and applies a broad range of advanced expertise of technology and security principles, best practices, policies and procedures to direct other technology staff in the completion of difficult and complex assignments crossing multiple functional areas.
• Coordinates and provides senior level technical guidance to security staff.
• Assists CISO and CTSO and other technology managers in project selection and scoping, project management, change management, technology evaluations and planning, procurements, and integration of various technologies for VRS.
• Mentors, and directs other technical staff with project selection and scoping, project management, change management, technology evaluations and planning, procurements, best practices and approaches for secure analysis/design, and integration of various technologies for VRS as required.
• Ensures that all components of the program work collaboratively to protect VRS data and systems and evolve as necessary to address emerging threats.
• Verifies all sensitive systems have documented/approved system security plans.
• Establishes the CRS counterintelligence program in concert with Local, State, and Federal Authorities
• Coordinates with the CISO and the ISO to ensure all VITA standards and expectations are operationalized.
• Manages all outsourced contracts in collaboration with the CISO, and ensures that procurement policies are updated and followed.
• With the CISO verifies VRS policies align with Commonwealth of Virginia’s security policies and standards.
• Collaborates with the CISO and engages with the agency’s cyber fraud analytics program to ensure fraud prevention and detection.
• Actively assists the CISO and the CTSO in leading the office and ensuring that technology and security is proactively applied to solve business problems and achieve business goals.
• Ensures that staff are focused on all aspects of security, especially protection of sensitive customer information.
• Oversees physical and logical building security.
• Stays abreast of security vulnerabilities, risk assessments and investigates suspicious activity. Monitors advancements in hacking/anti-hacking and other security technologies.
• Oversees, coordinates, and performs penetration testing and vulnerability risk assessments internally, externally and with third party business partners.
• Maintains 24x7x365 Security Operations Center functionality monitoring, reporting and responding to incidents.
• Collaborates with various auditors to remediate, respond, and coordinate responses to potential findings or observations.
• Directs and oversees business continuity planning, disaster r
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s