Information Security Officer; ISO) in Richmond, VA
Listed on 2026-09-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
The Unisys Information Security Officer (ISO) provides dedicated cybersecurity leadership in support of the client. This role is responsible for helping the client implement, manage, and govern information security programs that protect the information systems, services, and data. The Unisys ISO works closely with the Unisys account management team and delivery teams to ensure Unisys services meet the client’s security standards.
The Unisys ISO is the functional lead for a team of security professionals providing technical guidance and support in the context of delivering the services. The Unisys ISO is the key contact point for the client's CISO team, agency leadership, and stakeholders across the Commonwealth to ensure statewide compliance with IT security standards, perform risk assessments, support incident response, and deliver strategic security guidance.
Main liaison for Unisys account management for cybersecurity and compliance matters;
Service Delivery Manager for cybersecurity services and solutions provided to the client;
Technical lead for cybersecurity professionals in a matrixed organization;
Provide updates for Unisys leadership related to cybersecurity delivery;
Serve as the escalation point for internal Unisys cybersecurity issues affecting the client.
Develop, refine, and maintain agency-aligned security policies, controls, and documentation;
Assist the client and assigned agencies with audits, compliance reviews, and remediation planning in accordance with Unisys contractual obligations;
Ensure adoption of NIST-aligned risk management and security control frameworks.
Conduct or assist with enterprise risk assessments, data classification, and security control evaluations for the client and supported agencies;
Identify security gaps and recommend risk-based remediation strategies;
Support the development of System Security Plans (SSPs), Business Impact Assessments (BIAs), and agency risk registers;
Provide guidance on Continuity of Operations Plan (COOP) and Incident Response Plan development.
Act as an incident response resource to the client, helping coordinate cybersecurity investigations, analysis, and documentation;
Collaborate with the client's SOC, the Virginia Fusion Center, and agency staff during active events;
Deliver after-action reporting, root cause analysis, and improvement recommendations.
Assist the client in evaluating IT solutions, cloud services, and enterprise initiatives for security compliance;
Review designs, contracts, and procurements to ensure required security controls are incorporated;
Provide recommendations aligned with Zero Trust, identity management best practices, encryption, logging, and network security principles.
Support cybersecurity awareness programs across the client and partner agencies;
Act as one of the primary Unisys security liaisons connecting with leadership;
Communicate risks, emerging threats, and mitigation options to technical and non-technical audiences;
Offer security guidance to project teams, application developers, and business units.
Contribute to enterprise cybersecurity strategy and statewide security initiatives;
Recommend modern tools, frameworks, and processes to enhance the Commonwealth’s security posture;
Take part in governance boards, working groups, and cross-agency cybersecurity committees;
Support Unisys in delivering high-quality, contract-aligned services that enhance VITA’s mission.
You will be successful in this role if you…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).