Chief Information Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+2 more
Job description
Under administrative direction of the Department’s Chief Information Officer, the Information Technology Manager II (ITM II) serves as the Department’s Chief Information Security Officer (CISO) and Department AI Cybersecurity Officer. The CISO is the executive responsible for establishing and directing the Department’s enterprise information security, cybersecurity, privacy coordination, data protection, risk and compliance, security architecture and engineering, security operations, technology recovery, and artificial intelligence security programs. The CISO is responsible for establishing and enforcing enterprise information security policies, driving long-range security strategies, and overseeing the Information Security Branch to ensure alignment with the Department’s IT strategic direction. The position provides expert leadership in risk management, threat mitigation, vulnerability assessments, security incident investigation, security compliance, security architecture planning, disaster recovery, and security agreements with external partners supporting our programs in Headquarters, the 21 regional centers, and state-operated facilities. The CISO maintains enterprise accountability for safeguarding the Department’s IT infrastructure, networks, devices, and data, ensuring the confidentiality, integrity, and availability of critical information assets. This includes developing and maintaining policies and controls necessary to protect Protected Health Information (PHI) and Personally Identifiable Information (PII) for more than five hundred thousand individuals served across highly complex applications, 21 regional centers, state-operated facilities, and over 29,000 community service providers.
This recruitment is being conducted in anticipation of budget approval. Final hiring is contingent upon approval of funding.
Effective July 1, 2025, State employees are subject to a salary reduction of three percent in exchange for five hours per month of the Personal Leave.
Please let us know how you heard about our position by taking this brief survey:
https://www.research.net/r/ddsadmin, The California Department of Developmental Services (Department) is the agency through which the State of California provides services and supports to individuals with developmental disabilities.
These disabilities include intellectual disability, cerebral palsy, epilepsy, autism and related conditions. Services are provided through state-operated developmental centers and community facilities, and contracts with 21 nonprofit regional centers. The regional centers serve as a local resource to help find and access the services and supports available to individuals with developmental disabilities and their families., Knowledge of: Enterprise information security principles, frameworks, and practices, including security governance, risk management, incident response, vulnerability management, and security architecture; service-oriented and event-driven architecture, systems design, technology integration, and infrastructure platforms/protocols; IT project management methodologies, research and development approaches, IT service management, and organizational change management; regulatory and compliance requirements, including HIPAA, SOX, PCI, NIST, GLBA, CMS, and SSA directives, and how these requirements apply within large public-sector environments; data privacy laws, practices, and safeguards, including secure data acquisition, protection, transmission, retention, and disposal; organization and functions of California State Government, including its policies, principles, and governance structures; technical concepts across major IT domains such as networking, applications, databases, operating systems, cloud platforms, identity management, and endpoint protection; international, federal, state, and local laws governing data security and privacy; enterprise IT disciplines and how they interrelate (infrastructure, servers, networks, databases, applications, security operations, etc.) to support business missions.
Ability to: Lead and manage enterprise information security programs, including policy development, risk assessment, incident response, and compliance oversight; develop strategic plans, aligning security initiatives with organizational priorities, and translating complex security requirements into actionable operational activities; supervise, mentor, and develop technical and managerial staff, fostering teamwork, accountability, professional growth, and continuous improvement; analyze, problem-solve, and evaluate complex technical environments, identify risks, and recommend effective mitigation strategies; communicate clearly and effectively with executive leadership, program staff, and technical teams, including the ability to explain complex security concepts to non-technical audiences; evaluate, select, and implement security technologies, tools, and platforms to strengthen enterprise security posture; manage large-scale security projects and initiatives, including timelines, resources, dependencies, and change management; conduct and oversee security assessments, audits, and reviews using automated tools, documentation analysis, and stakeholder interviews; interpret and apply federal and state laws, regulations, and standards governing information security and privacy; build partnerships with program leaders, regional centers, external partners, and state oversight entities to align security expectations and drive compliance; develop and maintain disaster recovery and technology contingency plans, including conducting business impact analyses and coordinating recovery exercises; negotiate, coordinate, and manage vendor relationships related to security products, services, and third-party compliance requirements; oversee and ensure proper handling, protection, and transmission of sensitive and confidential data across complex distributed environments.
Requirements
In addition to evaluating each candidate’s relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate
Benefits & conditions
Open-spaced partitioned offices. Prolonged periods utilizing a computer most of the time. Occasional travel including overnight or day trips for covered California locations. May require 24/7 on-call support as well as weekend support responsibility.
Under Government Code 14200, this position is a hybrid, in-office/telework position, and may be subject to change. Incumbent can be required to report to the office, or any designated location at any time. Telework agreements can be modified and/or cancelled at any time. All commute expenses to the reporting location will be the responsibility of the selected candidate.
Pursuant to California Government Code requirements, candidates must be residents of the State of California at the time of appointment.
This position requires lawful authorization to work in the United States. The Department does not sponsor employment visas for this position., The Department is located in a modern, sustainable and innovative office building at 1215 “O” Street, Sacramento, California. Some amenities of the building include:
- First floor retail space (separate access from 12^th Street)
- Café with multiple vendors
- Outdoor seating for meal breaks
- Employee fitness center which includes a yoga studio, cardio equipment and weights
- Plaza area with kitchenette on each floor
- Lactation rooms, As a state employee working for the Department of Developmental Services, you and your family will have access to excellent medical, dental and vision insurance benefits in addition to retirement benefits.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 164: AI Agents, AI Blindspots and MCP security problems
The Overflow: Security and Privacy
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Best Paying Jobs in Technology