Chief Information Security Officer
Listed on 2026-07-19
-
IT/Tech
Cybersecurity, Information Security
Job Overview
Title:
Chief Information Security Officer (CISO) – Director VI (Posting #19093)
Agency:
Texas Health and Human Services Commission (HHSC), Health & Human Services Comm. Department: CHIEF INFO SECURITY OFFICE.
Location:
4601 W GUADALUPE ST, Austin, TX. Full‑time, day shift. Telework may be eligible. Closing Date: 09/14/2026.
Salary Range: $10,271.00 – $16,853.13 monthly, exempt.
Job DescriptionThe Texas Health and Human Services Commission (HHSC) is seeking an exceptional, forward‑thinking CISO to lead cybersecurity for one of the largest public‑sector technology environments in Texas. The role protects public trust, ensures continuity of essential services, enables secure modernization, and prepares the agency for emerging cyber threats, including artificial intelligence, cloud transformation, third‑party risk, and post‑quantum cryptography.
The CISO reports to the Chief Information Officer, serves as the agency’s Designated Information Security Officer, and administers enterprise information security requirements, coordinates agency‑wide security governance, and reports cybersecurity risk and control effectiveness to executive‑level management in accordance with Texas Government Code and TAC Chapter 202.
Essential Job Functions- Enterprise Cybersecurity Leadership and Strategy – 25%:
Provides executive leadership, establishes strategy, governance, priorities, and performance measures aligned with HHSC’s mission, regulatory requirements, the Texas Cybersecurity Framework, and NIST guidance. Leads enterprise security initiatives—cyber resilience, zero trust, cloud security, identity management, data protection, and post‑quantum readiness. Advises executive leadership on cybersecurity risks, emerging threats, compliance, and investment priorities. - Information Security Governance, Risk, and Compliance – 25%:
Directs the development and maintenance of enterprise security policies, standards, and controls. Ensures compliance with applicable state and federal cybersecurity requirements, integrates security into technology planning, procurement, operations, and third‑party relationships, and leads risk management, audits, corrective actions, and executive reporting. - Cybersecurity Operations, Incident Response, and Resilience – 20%:
Provides strategic oversight of cybersecurity operations, threat detection, vulnerability management, incident response, and cyber resilience capabilities. Ensures the agency can effectively prevent, respond to, and recover from cyber incidents while maintaining critical services. Promotes continuous improvement through metrics, exercises, lessons learned, and risk‑based security investments. - Emerging Technology, Post‑Quantum Readiness, and Secure Modernization – 15%:
Leads enterprise cybersecurity efforts supporting emerging technologies, secure modernization, and post‑quantum preparedness. Guides security architecture, cryptographic modernization, cloud security, artificial intelligence security, and secure technology adoption. Ensures security requirements are integrated throughout procurement, system development, implementation, and operations. - Workforce, Culture, and Stakeholder Engagement – 10%:
Builds and develops a high‑performing cybersecurity workforce, promotes a culture of accountability, collaboration, and continuous improvement, oversees security awareness and training programs, and represents HHS on cybersecurity matters with state agencies, business partners, and external stakeholders. - Budget, Contracts, Metrics, and Executive Visibility – 5%:
Oversees cybersecurity budgets, contracts, resource planning, and performance measures. Communicates cybersecurity risks, priorities, and outcomes to executive leadership through metrics, reporting, and strategic recommendations.
- Extensive knowledge of enterprise cybersecurity strategy, governance, risk management, security operations, incident response, and applicable regulatory requirements in a large public‑sector environment.
- Extensive federal and state knowledge of cybersecurity frameworks and standards, including NIST guidance, Texas Administrative Code Chapter 202, the…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).