Job Class Search

Job Details

Chief Information Security Officer

The Chief Information Security Officer (CISO) serves as the highest-ranking cybersecurity executive within the State of Arkansas, responsible for overseeing the state's overall information security strategy. The CISO plays a critical role in developing and implementing statewide policies, ensuring compliance with legal and regulatory requirements, managing cybersecurity risks, and safeguarding state assets from evolving threats. The CISO works directly with executive leadership, government agencies, and external partners to shape and enforce security protocols that protect the state's data, systems, and infrastructure.

Class Code:

IIE01C

Job Grade:

IST12

Special Job Requirements:

Typical Functions:

Lead the development and execution of the state’s comprehensive cybersecurity strategy, ensuring alignment with state priorities and legal requirements. Serve as the principal advisor to state leadership on all matters related to information security, cyber risks, and data protection policies. Oversee the formation and continuous improvement of statewide security policies, procedures, and standards, ensuring they meet federal, state, and industry best practices. Direct and oversee the statewide risk management process, identifying and mitigating cyber risks to state data, systems, and operations. Lead the response to major cybersecurity incidents, working with key stakeholders to contain and recover from breaches. Establish and manage a coordinated statewide incident response strategy and ensure the development of disaster recovery and business continuity plans. Ensure compliance with federal, state, and industry-specific cybersecurity regulations, including NIST, FISMA, HIPAA, and state-specific requirements. Represent the state in cybersecurity-related matters at federal, state, and industry forums, ensuring Arkansas maintains a strong cybersecurity posture. Provide regular updates to the Governor, legislature, and other state leadership on the status of the state’s cybersecurity efforts, including risk assessments and mitigation strategies. Foster strong relationships with other state agencies, federal authorities, and private-sector partners to collaborate on cybersecurity issues and share intelligence. Manage and direct a team of cybersecurity experts, ensuring continuous professional development and alignment with best practices. Advocate for cybersecurity awareness across all levels of state government, ensuring that all employees understand their role in safeguarding state resources. Assist in maintaining compliance with industry regulations, including NIST, HIPAA, FISMA, and others, by conducting regular audits and assessments.

Knowledge, Abilities, and Skills:

Advanced cybersecurity strategies, frameworks, and risk management principles. Regulatory requirements (e.g., HIPAA, FISMA, NIST, ISO 27001) and legal implications of cybersecurity and data protection. Strategic leadership and management principles, with experience in leading cross-functional teams. Exceptional leadership, strategic thinking, and decision-making abilities. High-level communication skills to articulate complex security issues to non-technical stakeholders. Expertise in governance, risk management, and compliance (GRC) systems. Ability to manage large-scale projects, budgets, and resources in a government environment. Ability to influence senior leadership and drive strategic cybersecurity initiatives across the state. Ability to assess, evaluate, and communicate cyber risks effectively to stakeholders.

Minimum Qualifications:

Bachelor’s degree in Cybersecurity, Information Technology, or related field preferred. Certifications such as CompTIA Security+, Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM) are preferred. At least eight years of experience in information security, with a focus on advanced threat detection, incident response, and system security.

Required Certificates:

N/A OTHER JOB RELATED EDUCATION AND/OR EXPERIENCE MAY BE SUBSTITUTED FOR ALL OR PART OF THESE BASIC REQUIREMENTS, EXCEPT FOR CERTIFICATION OR LICENSURE REQUIREMENTS, UPON APPROVAL OF THE QUALIFICATIONS REVIEW COMMITTEE.

Exempt:

E
Scroll to Top