The Virginia Economic Development Partnership (VEDP) is seeking a strategic and experienced Information Security Officer to lead VEDP's Information Security Program. The successful candidate will be responsible for developing, implementing, and maintaining a comprehensive information security program that protects the confidentiality, integrity, and availability of VEDP's information assets and technology resources. This role serves as the designated Information Security Officer (ISO) and provides leadership in cybersecurity governance, risk management, compliance, security operations, incident response, and security awareness across the organization. The position works closely with executive leadership, business units, technology teams, auditors, and external partners to ensure VEDP maintains a mature and effective security posture.Responsibilities: Serve as VEDP's designated Information Security Officer (ISO)Develop and manage an information security program that meets or exceeds the requirements of Commonwealth of Virginia (COV) IT security policies and standards in a manner commensurate with riskDevelop and maintain information security policies, standards, procedures, and guidelinesDevelop and maintain an information security awareness and training program for agency staff, including contractors and IT service providersImplement and maintain the appropriate balance of preventative, detective and corrective controls for VEDP IT systems commensurate with data sensitivity, risk and systems criticality in conjunction with IT leadershipLead system audit and assessment activities by coordinating with internal and external partners, managing audit requests through completionLead cybersecurity governance, risk management, privacy, and compliance initiativesOversee third-party security reviews, vendor risk assessments, and security-related contractual requirementsPartner with IT leadership and technology teams to implement security operations, change management, threat management, vulnerability management, and incident responseCoordinate with leadership on business continuity, disaster recovery, and cyber resilience planning effortsDevelop and deliver executive-level reporting for the leadership and metrics on cybersecurity risks and program effectiveness Skills: Experience implementing and managing cybersecurity controls aligned with NIST-based frameworks, including COV SEC530 or similarAbility to balance security requirements with business objectivesExperience developing and enforcing security policies, standards, and proceduresExperience with security awareness and organizational change management initiativesKnowledge of security operations, threat management, vulnerability management, and incident responseStrong analytical and problem-solving skillsExcellent written and verbal communication skillsAbility to communicate technical risks to executive and non-technical audiencesStrong leadership, project management, and stakeholder engagement skills Experience: Minimum of 8-10 years of progressive experience in information security, cybersecurity, or IT risk managementMinimum of 3-5 years of security leadership experience managing enterprise security programsExperience working within public-sector or regulated environments preferredProfessional security certification(s) such as CISSP, CISM, CISA, or equivalentExperience conducting risk assessments, security audits, and compliance reviews Being authorized to work in the U.S. is a precondition of employment. VEDP uses the E-Verify system and does not provide sponsorship.All candidates must apply through our website . A valid Virginia driver's license is required. Salary Range: $120,000-$160,000. Application deadline: July 17, 2026. VEDP is an Equal Opportunity Employer. All applicants are considered for employment without regard to race, sex, color, national origin, religion, sexual orientation, gender identity or expression, age, veteran status, political affiliation, genetics, or
Not specified in the original listing.
Not specified in the original listing.