Information Security Officer #00114
Virginia.govAbout the role
Title: Information Security Officer #00114
State Role Title: Info Technology Specialist III
Hiring Range: $113,000 to $133,600 annually. $5,000 Sign-On Bonus for those new to state service is being offered to the selected candidates. A one-year tenure agreement will be required for sign-on bonus.
Pay Band: 6
Agency: Virginia Department of Agriculture
Location: VDACS CENTRAL HEADQUARTERS
Agency Website: www.vdacs.virginia.gov
Recruitment Type: General Public - G
Job Duties
The Virginia Department of Agriculture and Consumer Services is seeking an experienced Information Security Officer (ISO) to continue to develop and maintain the Agency’s Security Program. The successful candidate will be responsible for ensuring the VDACS Security Program meets or exceeds the requirements of the Commonwealth of Virginia Information Technology Security Policies and Standards to ensure the security of Commonwealth and citizen data stewarded by the agency. The position will serve as a liaison between the agency and Commonwealth Security and Risk Management. The position must effectively communicate risk, security issues, incidents, and vulnerabilities to both technology and agency leadership. This position is responsible for assessment of the sensitivity of all VDACS systems and is responsible for ensuring appropriate policies are in place and reviewed periodically for compliance. The successful candidate will be responsible for managing the agency’s annual and on-boarding security awareness training programs. The position is responsible for ensuring risks, vulnerabilities, and security related issues are mitigated in accordance with risk and system criticality. The position will maintain the system inventory, risk assessments, and system security plans for the agency. This position will be responsible for assisting with the audit process for both internal and external audits. The position will also participate on the Technology Management Team and provide support for all technology projects to ensure systems follow security best practices and maintain compliance with Commonwealth standards. Once onboarded, this position may be eligible for telework opportunities; availability, hours, and duration of telework shall be approved as outlined in the Commonwealth’s telework policy.
Minimum Qualifications
Demonstrated ability to manage the agency's Information Security Program based on the Commonwealth's security standard. Extensive knowledge of the Commonwealth security standards including but not limited to Commonwealth of Virginia SEC530. Comprehensive knowledge of security principles, policies, procedures, risk management and internal controls in a technology environment. Ability to serve as a liaison between the agency, VITA, and outside technical experts as required. Ability to translate and understand federal, state and agency laws, regulations, standards and policies and their effects on information security. Knowledge of security in government and experience with the NIST standards for security. Ability to assess and document risk to agency IT systems and data. Ability to create and manage the disaster recovery preparedness program. Ability to provide technical direction, training and assistance to technology staff related to security features and requirements for development and the infrastructure Ability to analyze, evaluate and recommend security solutions for business and technical requirements. Extensive knowledge of Internet, intranet, networking security requirements and security vulnerabilities. Ability to communicate effectively both verbally and in writing. Demonstrated ability to organize and prioritize work in a team environment and individually while providing exceptional customer service. Experience developing and maintaining a security program compliant with the standards of the Commonwealth of Virginia. Experience developing and maintaining Business Impact Analysis, Risk Assessments, system Security Plans, and Disaster Recovery Plans. Experience developing and maintaining agency policies related to security and technology. Experience managing a Security Awareness Training Program. Experience identifying technical security vulnerabilities and risk and ability to solve technical and security problems. Considerable experience in information technology, information security, and the development process. Experience with firewall technologies, authentication, and authorization methods, and deploying, securing, and managing certificate authorities.
Additional Considerations
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s