Agency Information Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The AISO (IT Manager II) leads the planning and development of the Agency’s Information Security Strategy and related policies/standards, and drives corresponding tactical activities aimed at increasing the information security maturity level of CalHHS entities information assets, working closely with all CalHHS entities, the California Department of Technology (CDT) Office of Information security (OSI), and the California Office of Emergency Services (Cal OES), Cyber Security Integration Center (Cal-CSIC) to understand needs and priorities.
The AISO supports department information security efforts and assesses compliance with key Agency information security initiatives through oversight and support, working closely with entity Information Security Officers (ISOs) and solution architects. The incumbent acts as an expert and consultant to the CalHHS entities on the implementation of internal and external policies and standards, laws, trends, and best practices regarding information security.
The AISO is the CalHHS liaison to the CDT/OIS & CDT IT Policy functions, representing the needs of CalHHS and its entities and communicating CDT policy, guidelines, and requirements to the CalHHS entities ISOs., This position is currently eligible for one telework day per-week and is required to report in-person a minimum of four days per week. The amount of telework is at the discretion of the OTSI and is subject to operational needs., Business travel may be required. All commute expenses to the reporting location will be the responsibility of the selected candidate., Form 700: This position is responsible for the making, participating in the making, or influencing the making of governmental decisions that may potentially have a material effect on personal financial interests. As a result, this position is subject to the California Health and Human Services Agency (CalHHS) Conflict of Interest Code. The selected candidate is required to file a Statement of Economic Interests (Form 700) when assuming office, annually while in office, and upon leaving office.
Requirements
Individuals who are currently in the classification, eligible for lateral transfer, eligible for reinstatement, have list or LEAP eligibility, are in the process of obtaining list eligibility, or have SROA and/or Surplus eligibility (please attach your letter, if available). SROA and Surplus candidates are given priority; therefore, individuals with other eligibility may be considered in the event no SROA or Surplus candidates apply. Individuals who are eligible for a Training and Development assignment may also be considered for this position(s)., In addition to evaluating each candidate’s relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate:
-
Experience as an Information Security Officer or a Chief Information Officer with specific cyber-Security and Privacy-related responsibilities, including incident response, development/monitoring of compliance, development/implementation of a Plan of Action and Milestone (POAM) associated with security compliance maturity.
-
Demonstrated experience overseeing the application and/or implementation of information security and data privacy technologies.
-
Knowledge of information security and data privacy industry best practices.
-
Demonstrated experience preparing and leading the execution of enterprise security strategies and/or tactical road maps.
-
Demonstrated experience assessing planned enterprise and solution/service architectures to determine alignment with enterprise security strategies, standards and policies.
-
Demonstrated ability to collaborate, coordinate, and communicate effectively across all levels of an organization and with external partners and stakeholders including those with regulatory control functions.
-
Experience developing, implementing, and acting as an advocate for information security best practices and security awareness.
-
Demonstrated use of and application of cybersecurity, risk management and control frameworks (such as National Institute of Standards and Technology (NIST) Cybersecurity Framework, NIST Risk Management Framework, and NIST 800-53 controls); working knowledge of regulatory requirements including Health Insurance Portability and Accountability Act (HIPAA) and familiarity with MARS-E requirements and the California Information Practices Act.
-
Demonstrated experience developing and/or providing information security training.
Benefits & conditions
OTSI is dedicated to creating an innovative workplace for its team members that is inclusive, diverse, and interactive! Here are a few of the ways we stay engaged with our team:
- Ongoing professional development and engagement opportunities.
- Employee Assistance Program (EAP).
- Free Parking!
Additionally, as a team member of the State of California, you may be eligible for many benefits, such as:
- Medical, including health, dental, and vision insurance.
- Paid Holidays and vacation/leave
- Defined retirement program
- Savings Plus Program (401(k), 457)
- Medical/Dependent Care Reimbursement Accounts, When responding to the Statement of Qualifications, applicants must follow these below instructions. Failure to follow these instructions may result in disqualification from this exam/hiring process.:
- Responses must be typewritten on 8 1/2” x 11” paper, no more than 2 page(s) in length, and using font no smaller than size 11.
- Responses are to be complete, specific, clear, and concise.
- Responses to the questions should be easily identified (e.g. by numbering the response to the corresponding question, or repeating the prompt in response).
- After reviewing the duty statement and desirable qualifications, please describe your knowledge, skills, and experience, and explain why they make you the best fit for this role.
About the company
Why Join California Health and Human Services Agency Office of Technology and Solutions Integration (CalHHS OTSI or OTSI)?
At OTSI, your work directly improves the health and well-being of Californians. We exist to be the trusted partner to CalHHS and its 12 state departments to deliver high-impact IT and data solutions that strengthen health and human services programs statewide.
We bring leadership, expertise, and capacity together and work collaboratively with our partners to design, deliver, and support IT and data solutions that accelerate the delivery of health and human service program outcomes and service value. Our culture is grounded in accountability, respect, integrity, and collaboration, and we integrate those values in how we lead, how we work, and how we serve.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
The Overflow: Security and Privacy
Best Paying Jobs in Technology