IT Security Manager
Listed on 2026-05-24
-
IT/Tech
Cybersecurity, Information Security
The Opportunity
This position oversees the Agency’s Information Technology security and risk management functions for new, existing, and enhanced services critical to the agency. Using an in-depth understanding of industry trends and available technologies, the position partners with peers, internal and external stakeholders to recommend and develop solutions to support the agency mission. The role will provide leadership, direction and oversight to implement and maintain a comprehensive agency‑wide IT plan that aligns with business strategy.
Responsible for advancing shared information systems and security compliant enterprise architecture throughout the agency, including internally developed and externally provided business solutions.
The position is able to effectively articulate to staff the vision and direction of IT and how that fits in with the agency’s overall goals and objectives. Through effective leadership and supervisory skills they foster an environment of performance and accountability where employees feel valued and respected and are empowered to achieve success.
This position is expected to maintain the highest level of cross‑functional technical and business understanding for IT, Cybersecurity, and Risk Management for the Agency.
Essential DetailsWSDA is recruiting for a full‑time permanent IT Security Manager within the Director’s Office. The position is eligible for a flexible/hybrid schedule and reports to the WSDA Headquarters Office located in Olympia, Washington. The position is non‑represented.
Base pay range:
Step A $107,364 – Step L $140,856 annually.
- Develop and maintain Agency Cybersecurity Program and is responsible for the strategic planning and alignment with State and Agency level strategies.
- Evaluate staff provided recommendations of new information security technologies and countermeasures against threats to information or privacy.
- As a member of State Level policy development committees, this position identifies information technology security initiatives and standards for the State Enterprise and develops Agency policy and strategies which align with State goals.
- Manage the development, implementation, and maintenance of the WSDA information security policy, standards, guidelines and procedures.
- Develop the access and authorization controls for everyday operations as well as emergency procedures for data.
- Set the standards for access controls, audit trails, event reporting, encryption and integrity controls.
- Keep abreast of latest security and legislation, regulations, advisories, alerts and vulnerabilities pertaining to WSDA’s IT investments.
- Provide Bill Analysis for proposed legislature that would impact Cybersecurity, IT, and Agency related business operations related to IT by conducting impact and cost analysis and providing expert level feedback used by the legislative body.
- Develop and implement an ongoing risk management program targeting information security and privacy matters.
- Act as the Agency IT Risk Manager.
- Determine the methods for vulnerability detection and remediation and oversee ongoing vulnerability testing.
- Lead the information technology security assessments to identify agency risk due to changes or modifications to the WSDA computing environment.
- Direct the agency security assessments/audits to identify vulnerabilities in security program and policies.
- Control testing of security procedures, mechanisms and measures.
- Collaborate with Federal and State auditors, Agency managers, and subject matter experts for satisfactory completion of compliance and program audits of the WSDA information security program.
- Act as the Incident Commander as defined by the National Incident Management Framework.
- Responsible for all aspects of cybersecurity emergency response; including quickly developing incident objectives, managing all incident operations, application of technical resources as well as responsibility for all persons involved.
- Agency designated manager of security incident reporting and official responses to security incidents (breaches), responds to potential policy…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).