> Markdown version of [/jobs/ext/3079363-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/3079363-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer - **Company:** California Department of Public Health - **Location:** Sacramento County, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $136,656.0 - $166,104.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing, Cyber Security, Databases, Data Security, Disaster Recovery, Identity and Access Management, Information Security Management, IT Management, Software Vulnerability Management, Event Driven Architecture, Information Technology, Network Server, Vulnerability Analysis - **Published:** September 25, 2026 - **Apply:** https://www.calcareers.ca.gov/CalHrPublic/Jobs/JobPosting.aspx?JobControlId=532865 ## About the Role In addition to evaluating each candidate's relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate ## Description Under administrative direction of the Department's Chief Information Officer, the Information Technology Manager II (ITM II) serves as the Department's Chief Information Security Officer (CISO) and Department AI Cybersecurity Officer. The CISO is the executive responsible for establishing and directing the Department's enterprise information security, cybersecurity, privacy coordination, data protection, risk and compliance, security architecture and engineering, security operations, technology recovery, and artificial intelligence security programs. The CISO is responsible for establishing and enforcing enterprise information security policies, driving long-range security strategies, and overseeing the Information Security Branch to ensure alignment with the Department's IT strategic direction. The position provides expert leadership in risk management, threat mitigation, vulnerability assessments, security incident investigation, security compliance, security architecture planning, disaster recovery, and security agreements with external partners supporting our programs in Headquarters, the 21 regional centers, and state-operated facilities. The CISO maintains enterprise accountability for safeguarding the Department's IT infrastructure, networks, devices, and data, ensuring the confidentiality, integrity, and availability of critical information assets. This includes developing and maintaining policies and controls necessary to protect Protected Health Information (PHI) and Personally Identifiable Information (PII) for more than five hundred thousand individuals served across highly complex applications, 21 regional centers, state-operated facilities, and over 29,000 community service providers. This recruitment is being conducted in anticipation of budget approval. Final hiring is contingent upon approval of funding. Effective July 1, 2025, State employees are subject to a salary reduction of three percent in exchange for five hours per month of the Personal Leave. Please let us know how you heard about our position by taking this brief survey: https://www.research.net/r/ddsadmin, The California Department of Developmental Services (Department) is the agency through which the State of California provides services and supports to individuals with developmental disabilities. These disabilities include intellectual disability, cerebral palsy, epilepsy, autism and related conditions. Services are provided through state-operated developmental centers and community facilities, and contracts with 21 nonprofit regional centers. The regional centers serve as a local resource to help find and access the services and supports available to individuals with developmental disabilities and their families., Knowledge of: Enterprise information security principles, frameworks, and practices, including security governance, risk management, incident response, vulnerability management, and security architecture; service-oriented and event-driven architecture, systems design, technology integration, and infrastructure platforms/protocols; IT project management methodologies, research and development approaches, IT service management, and organizational change management; regulatory and compliance requirements, including HIPAA, SOX, PCI, NIST, GLBA, CMS, and SSA directives, and how these requirements apply within large public-sector environments; data privacy laws, practices, and safeguards, including secure data acquisition, protection, transmission, retention, and disposal; organization and functions of California State Government, including its policies, principles, and governance structures; technical concepts across major IT domains such as networking, applications, databases, operating systems, cloud platforms, identity management, and endpoint protection; international, federal, state, and local laws governing data security and privacy; enterprise IT disciplines and how they interrelate (infrastructure, servers, networks, databases, applications, security operations, etc.) to support business missions. Ability to: Lead and manage enterprise information security programs, including policy development, risk assessment, incident response, and compliance oversight; develop strategic plans, aligning security initiatives with organizational priorities, and translating complex security requirements into actionable operational activities; supervise, mentor, and develop technical and managerial staff, fostering teamwork, accountability, professional growth, and continuous improvement; analyze, problem-solve, and evaluate complex technical environments, identify risks, and recommend effective mitigation strategies; communicate clearly and effectively with executive leadership, program staff, and technical teams, including the ability to explain complex security concepts to non-technical audiences; evaluate, select, and implement security technologies, tools, and platforms to strengthen enterprise security posture; manage large-scale security projects and initiatives, including timelines, resources, dependencies, and change management; conduct and oversee security assessments, audits, and reviews using automated tools, documentation analysis, and stakeholder interviews; interpret and apply federal and state laws, regulations, and standards governing information security and privacy; build partnerships with program leaders, regional centers, external partners, and state oversight entities to align security expectations and drive compliance; develop and maintain disaster recovery and technology contingency plans, including conducting business impact analyses and coordinating recovery exercises; negotiate, coordinate, and manage vendor relationships related to security products, services, and third-party compliance requirements; oversee and ensure proper handling, protection, and transmission of sensitive and confidential data across complex distributed environments. ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)