State Chief Information Security Officer
Job in
Olympia, Thurston County, Washington, 98513, USA
Listed on 2026-07-25
Listing for:
State of Washington
Full Time
position Listed on 2026-07-25
Job specializations:
-
IT/Tech
Cybersecurity, IT Project Manager, IT Consultant, Information Security & Data Protection
Job Description & How to Apply Below
WaTech:
Leading the way forward!
Washington Technology Solutions (WaTech) is at the forefront of integrating cutting-edge technologies that revolutionize how state services are delivered in Washington. By joining the WaTech team, you will contribute to assisting other state agencies in providing essential services to millions of Washingtonians daily. WaTech manages the state's essential technology infrastructure, enhancing governmental efficiency, security and safety.
About the position
The State Chief Information Security Officer (CISO) leads Washington's cybersecurity strategy as the highest authority in the Office of Cybersecurity (OCS), and is accountable for enterprise risk management, strategic investment decisions and cross-agency cybersecurity posture. The State CISO leads OCS in enforcing standards, managing incident responses and auditing compliance with security protocols. As a trusted senior advisor to the Governor, Legislature, and state executive branch leadership, the State CISO provides expert counsel on cybersecurity policies, incident impacts, mitigation strategies and legislative initiatives to protect the state's critical infrastructure and digital assets.
This role reports directly to the State Chief Information Officer (CIO).
Some of what to expect in this role:
* Provide executive oversight of Deputy CISOs, ensuring their sections align with the statewide cybersecurity vision, enterprise priorities and statutory responsibilities.
* Define enterprise cybersecurity risk tolerance, review statewide risk posture reports from Deputy CISOs, and directs cross-agency mitigation strategies.
* Provide oversight of federal, state, and other audits and reviews for agencies.
* Serve on governance committees and represent Washington's cybersecurity interests publicly.
* Collaborate with agency leaders, private sector and federal partners to improve statewide cybersecurity resilience and awareness.
* Develop and implement strategic plans and goals for the state of Washington and the OCS in alignment with the vision and mission of the state's information technology strategic plan.
* Oversee the development of cybersecurity workforce role definitions, skills matrices and career progression pathways.
* Manage OCS's budget, resources, staff, vendors and projects, ensuring efficiency, quality, and alignment with statewide and WaTech goals, policies and standards.
* Retain executive oversight of the state's Information Security Program, delegating day-to-day development and implementation to Deputy CISOs across their respective domains.
* Participate with the responsible, interested parties in developing and implementing statewide business continuity and disaster recovery plans to ensure that these incorporate appropriate cybersecurity measures.
* Ensure proper inventories of information technology assets and software licenses in collaboration with information technology operations.
* Develop and maintain an enterprise cybersecurity performance framework using leading standards (e.g., NIST CSF, CMMI, CIS Controls) to assess maturity, measure outcomes, and guide investment decisions.
Here's what we're looking for:
* Fifteen years of experience in the field of information technology. This experience must include:
* Ten years of recent experience in information security at the enterprise or corporate level.
* Four years of supervisory experience leading technical and information security teams.
* Three years of experience with:
* Budget development, implementation and financial forecasting of business technology services.
* Developing and implementing policies and standards in a large enterprise environment.
* Assessing security threats and recommending appropriate mitigation strategies and compensating controls.
* Identifying security solutions that meet predefined regulatory/compliance requirements.
* A bachelor's or master's degree in computer science, business administration, information security, or a related field may substitute for four or six years, respectively, of the overall 15 years of experience required.
* The ability to take action to learn and grow.
* The ability to take action to meet the needs of others.
* Strong understanding of relevant laws, regulations and compliance requirements with experience analyzing and interpreting legislation and administrative rules to assess their impact on IT security policy and standards implementation.
* Proven ability to convey complex technical issues effectively to technical teams, customer security professionals and non-technical senior management.
* In-depth knowledge of cybersecurity principles, technologies and industry best practices.
* In-depth knowledge of cutting-edge cybersecurity technologies such as cryptography, artificial intelligence for threat detection, and blockchain for secure data management. Experience implementing and innovating in zero-trust architecture, secure Dev Ops, and advanced threat intelligence.
* Proven…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×