It Professional - Information Security
Listed on 2026-05-20
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, IT Project Manager
Qualifications
Information Technology (IT) Professionals analyze, develop, implement, maintain, and modify computer operations, systems, networks, databases, applications, and/or information security. Incumbents may perform duties in one or more IT specialization areas depending on the needs of the agency. Bachelor's degree from an accredited college or university in computer science, management information systems, or a closely related field and five years of professional IT experience relevant to the duties of the position, which may include systems administration, network administration, database administration, applications analysis and development, and/or information security, two years of which were at the advanced journey level or in a supervisory or project management capacity;
OR Bachelor's degree from an accredited college or university in computer science, management information systems, or a closely related field and five years of professional IT experience which may include systems administration, network administration, database administration, applications analysis and development, and/or information security, relevant to the duties of the position, two years of which were at the journey level in information security;
OR two years of relevant experience as an IT Professional III in Nevada State service; OR an equivalent combination of education and experience as described above.
This currently non-supervisory position is located in Carson City within the Governors Technology Office, Office of Information Security and Cyber Defense. The incumbent serves as the Information Security Officer (ISO) for the offices supported under the Governors Technology Office (i.e. Department of Administration and its Divisions), and is responsible for designing, researching, developing, implementing, auditing, testing and reporting on the Department’s information security program;
coordinating the development of Departmental information security policies, standards and procedures; and for the planning and implementation of information security initiatives at the functional, project or program level. The incumbent will coordinate efforts with members of the technical teams in the Office of the CIO Division, and with non GTO Departments and Divisions as required or directed. Incumbents interact with internal and external management and technical levels to provide guidance and direction regarding interpretations of information security policies, standards, and procedures.
Incumbents use and develop solutions, and address applicability of solutions to security advisories, vulnerabilities, or deficiencies. Incumbents must be capable of navigating conflict and providing sensible direction. Incumbents will be required to understand, interpret, apply, and demonstrate compliance with security controls from multiple industry and Federal regulatory frameworks, including CIS, CJIS, HIPAA, FISMA, FIRPA, MARS-E, IRS, SSA, OCSE and NIST, and facilitate, coordinate, participate in, and report on audit activities involving the Governors Technology Office, Department of Administration, and/or its Divisions as either primary or supporting audit subjects.
Incumbents are responsible for the development and administration of the security awareness program for all employees and contractors of the Departments, Divisions, and offices within their purview. Incumbents must recurringly report current state, projections, and progress of the information security program to all levels of management.
Incumbent(s) will be expected to have knowledge, skills and abilities from a previous level.
Working Knowledge- current principles, theories, practices and procedures related to information security management;
- five of the ten information security domains;
- general‑purpose security controls;
- current information security trends and technologies;
- strategic planning and project management at the division/work unit level;
- policy development and implementation;
- methods and techniques used to safeguard against accidental or unauthorized modification, destruction or disclosure of data to meet security needs;
- interagency business practices and principles.
- identify complex information security risks, vulnerabilities and problems;
- select the best course of mitigation actions for security issues;
- assess the security and/or vulnerability of information assets to assist in developing a risk assessment of multiple security domains;
- assess costs and present alternatives for the assigned area of responsibility;
- analyze data, solve problems and make appropriate decisions within five of the ten domains;
- design appropriate solutions to complex security problems.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).