State Chief Information Security Officer

Inc Washington
Olympia, WA, United States
16 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$150,000.0 - $200,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Capability Maturity Model Integration Cyber Security Information Systems Data Security DevOps Digital Assets Information Security Management Information Technology Operations Intrusion Detection and Prevention Information Systems Security Architecture Professional Blockchain
+3 more
Zero Trust Network Access Information Technology CIS Benchmarks

Job description

Washington Technology Solutions (WaTech) is at the forefront of integrating cutting-edge technologies that revolutionize how state services are delivered in Washington. By joining the WaTech team, you will contribute to assisting other state agencies in providing essential services to millions of Washingtonians daily. WaTech manages the state’s essential technology infrastructure, enhancing governmental efficiency, security and safety.

About the position

The State Chief Information Security Officer (CISO) leads Washington’s cybersecurity strategy as the highest authority in the Office of Cybersecurity (OCS), and is accountable for enterprise risk management, strategic investment decisions and cross-agency cybersecurity posture. The State CISO leads OCS in enforcing standards, managing incident responses and auditing compliance with security protocols. As a trusted senior advisor to the Governor, Legislature, and state executive branch leadership, the State CISO provides expert counsel on cybersecurity policies, incident impacts, mitigation strategies and legislative initiatives to protect the state’s critical infrastructure and digital assets. This role reports directly to the State Chief Information Officer (CIO).

Duties

Some of what to expect in this role:

  • Provide executive oversight of Deputy CISOs, ensuring their sections align with the statewide cybersecurity vision, enterprise priorities and statutory responsibilities.
  • Define enterprise cybersecurity risk tolerance, review statewide risk posture reports from Deputy CISOs, and directs cross-agency mitigation strategies.
  • Provide oversight of federal, state, and other audits and reviews for agencies.
  • Serve on governance committees and represent Washington’s cybersecurity interests publicly.
  • Collaborate with agency leaders, private sector and federal partners to improve statewide cybersecurity resilience and awareness.
  • Develop and implement strategic plans and goals for the state of Washington and the OCS in alignment with the vision and mission of the state’s information technology strategic plan.
  • Oversee the development of cybersecurity workforce role definitions, skills matrices and career progression pathways.
  • Manage OCS’s budget, resources, staff, vendors and projects, ensuring efficiency, quality, and alignment with statewide and WaTech goals, policies and standards.
  • Retain executive oversight of the state’s Information Security Program, delegating day-to-day development and implementation to Deputy CISOs across their respective domains.
  • Participate with the responsible, interested parties in developing and implementing statewide business continuity and disaster recovery plans to ensure that these incorporate appropriate cybersecurity measures.
  • Ensure proper inventories of information technology assets and software licenses in collaboration with information technology operations.
  • Develop and maintain an enterprise cybersecurity performance framework using leading standards (e.g., NIST CSF, CMMI, CIS Controls) to assess maturity, measure outcomes, and guide investment decisions., * Applications with missing or incomplete fields, or supplemental question responses such as ā€œsee resumeā€ may be considered incomplete and removed from consideration.
  • WaTech complies with the employment eligibility verification requirements of the federal Form I-9. The selected candidate must be able to provide proof of identity and eligibility to work in the United States. WaTech does not use the E-Verify system. We are not eligible to extend STEM Optional Practice Training (OPT) opportunities. For more information, please visit https://www.uscis.gov.
  • Applicants wishing to claim Veterans Preference should attach a copy of their DD-214 (Member 4 copy), NGB 22, or signed verification of service letter from the United States Department of Veterans Affairs to their application. (Please redact any personally identifiable data such as social security number and date of birth prior to submittal.)

By submitting your materials, you affirm that all information is true and correct. Any untruthful information is cause for removal from the applicant pool. If hired as a result of this recruitment, the discovery of incorrect or falsified information may lead to disciplinary action or dismissal.

Recruitment process:

The first round of application assessments will be conducted seven days after the initial job posting date. The hiring authority reserves the right to offer the position at any time after the initial seven-day job posting date. It is to the applicant’s advantage to apply as early as possible. There will be an assignment as a part of the assessment process.

The salary range reflected above reflects the full potential for this position. The base pay offered to the selected candidate will consider the candidate’s specific qualifying experience and internal equity of the existing team.

Requirements

Here’s what we’re looking for:

  • Fifteen years of experience in the field of information technology. This experience must include:
  • Ten years of recent experience in information security at the enterprise or corporate level.
  • Four years of supervisory experience leading technical and information security teams.
  • Three years of experience with: o Budget development, implementation and financial forecasting of business technology services. o Developing and implementing policies and standards in a large enterprise environment. o Assessing security threats and recommending appropriate mitigation strategies and compensating controls. o Identifying security solutions that meet predefined regulatory/compliance requirements.

  • A bachelor’s or master’s degree in computer science, business administration, information security, or a related field may substitute for four or six years, respectively, of the overall 15 years of experience required.

  • The ability to take action to learn and grow.
  • The ability to take action to meet the needs of others.
  • Strong understanding of relevant laws, regulations and compliance requirements with experience analyzing and interpreting legislation and administrative rules to assess their impact on IT security policy and standards implementation.
  • Proven ability to convey complex technical issues effectively to technical teams, customer security professionals and non-technical senior management.
  • In-depth knowledge of cybersecurity principles, technologies and industry best practices.
  • In-depth knowledge of cutting-edge cybersecurity technologies such as cryptography, artificial intelligence for threat detection, and blockchain for secure data management. Experience implementing and innovating in zero-trust architecture, secure DevOps, and advanced threat intelligence.
  • Proven expertise in developing budgets, implementing financial plans and forecasting for information technology services.
  • Proven expertise in negotiating and overseeing third-party vendor contracts.

Preference may be granted to applicants with the following:

  • A master’s degree in computer science, business administration, information security, or a related field.
  • Applicable industry-accepted certifications, including but not limited to:
  • Certified Information Systems Security Professional (CISSP).
  • Holistic Information Security Practitioner (HISP).
  • Certified Information Security Manager (CISM).
  • Certified Information Systems Auditor (CISA).
  • Certified in Risk and Information Systems Controls (CRISC).
  • Department of Homeland Security (DHS) secret-level clearance.
  • Ability to speak effectively and persuasively before a large audience.
  • Demonstrated experience in project management, including managing multiple projects with strong organizational and time-management skills.
  • Demonstrated commitment to continuous learning and professional development, such as participation in professional organizations (e.g., ISACA, ISC2) and attendance at industry conferences.

Benefits & conditions

3.43.4 out of 5 stars Olympia, WA Hybrid work $150,000 - $200,000 a year, Pulled from the full job description

  • Health insurance
  • Retirement plan
  • Dental insurance
  • Paid holidays
  • Flexible schedule

About the company

This position is authorized for telework; however, the incumbent will be required to report to WaTech’s Olympia, Washington office two to three days per week, as well as for any security-related meetings, incidents or design sessions. The incumbent must reside within a 60-mile radius of our Olympia, Washington office. Should the selected candidate reside outside this radius, they will be required to commit to relocating within the designated area within an approved timeframe.

We value diversity and different perspectives:

WaTech is committed to providing equal access and opportunities to all qualified applicants and employees. We seek to attract and retain a diverse staff and welcome your experiences, perspectives and unique identity. We invite you to include your preferred name and pronouns in your material to ensure we address you correctly throughout the application process.

What WaTech offers:

As an employee of WaTech, you’ll have access to an outstanding employee benefits package that includes medical and dental plan options for you and your family, paid leave and holidays, retirement plan options and more.

While WaTech is headquartered in Olympia, Washington, which is near some of the country’s most scenic national parks, we are able to offer many of our positions telework and flexible schedule options to help support a healthy work-life balance.

To learn more about WaTech and what our employees enjoy about working here, please visit our website.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum Ā· WWC Europe 2026

4:12 min

Using contract managers for blockchain operations

Soumaya Erradi Ā· LIVE

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 Ā· WWC 2024

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark Ā· LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin Ā· WWC 2022

Videos

See all

Related articles

See all