Job Summary - Why you'll love this positionThe
Information Technology Division has an opening for a
Chief Information Security Officer located in
Cole County. Semi-monthly salary: The current rate for this position is
$5,215-$5,631.66. Individual(s) selected for this position may receive a higher rate based on a pay differential (e.g. shift, or time-of-service pay).
Annual Salary: $125,160 - $135,159.84
Job Posting Number: Job Location: This position is located at the
Howerton State Office Building; 615 Howerton Court, Jefferson City, MO.
The
Department of Social Services partners with families and communities to protect children, rehabilitate youth and move families to self-sufficiency so that Missourians can lead safe, healthy and productive lives.
Why you'll love this position: You'll love this position because it offers a deeply collaborative, high-impact architectural challenge where you will bridge the gap between executive strategy and technical execution. Working alongside the Chief Information Officer (CIO), executive stakeholders, and state partners, you will help navigate a major digital transformation. You will get to solve the intricate puzzle of balancing legacy on-premises systems with modern cloud environments, designing secure user provisioning workflows and orchestrating incident response strategies. This isn't a role where you are left on an island; you will be an integral part of an executive team, backed by an organization committed to doing things right.
Responsibilities - What you'll doWhat you'll do: Strategic Leadership & Governance
- Program Ownership: Establish, maintain, and oversee the Department's enterprise-wide information security program to protect sensitive client and operational data.
- Executive Alignment: Collaborate closely with the CIO and executive stakeholders to align security initiatives with departmental goals and service delivery needs.
- Policy Development: Draft, implement, and enforce information security policies, standards, and guidelines across all departmental divisions.
- Culture & Awareness: Lead department-wide security awareness training tailored to social workers and administrative staff who handle highly sensitive data daily.
Regulatory Compliance & Data Protection
- Regulated Data Guardrails: Maintain strict compliance frameworks for protecting multi-jurisdictional data, including HIPAA/HITECH (health data), FTI (Federal Tax Information), and PII (Personally Identifiable Information).
- Audit Management: Serve as the primary point of contact and coordinator for all federal, state, and independent security audits.
- Risk Management: Conduct continuous risk assessments and vulnerability scanning across the enterprise, prioritizing remediation efforts based on risk to client services.
Hybrid Infrastructure & Architecture
- Cloud Security Oversight: Partner with Information Technology (IT) technical teams to govern security configurations across hosted cloud environments (SaaS, PaaS, IaaS), ensuring robust identity boundaries and monitoring.
- Secure Modernization: Advise on security architecture during the ongoing migration of legacy applications to secure cloud architectures.
Identity, Access & User Provisioning
- Identity Governance: Define and oversee user provisioning and de-provisioning workflows, ensuring strict adherence to the principle of "least privilege."
- Access Controls: Standardize and enforce Multi-Factor Authentication (MFA), Single Sign-On (SSO), and role-based access controls across all hybrid systems.
- Offboarding Compliance: Manage the swift, automated revocation of access for departing staff or contractors to mitigate insider threat risks and comply with privacy regulations.
Incident Response & Operations
- Incident Response Command: Lead the Incident Response (IR) team, ensuring readiness to detect, contain, investigate, and recover from security incidents or data breaches.
- Vendor & MSSP Management: Oversee the relationship, performance, and SLAs of third-party Managed Security Service Providers (MSSPs) and external security vendors.
- Resiliency Testing: Design and execute routine tabletop exercises with leadership and technical teams to ensure organizational readiness for scenarios like ransomware or data exfiltration.
Qualifications - All you need for successMinimum Qualifications:Minimum of
8 - 10 years of progressive experience in cybersecurity, information assurance, or IT risk management.
Preferred Qualifications:Bachelor's degree in Computer Science, Management Information Systems, Cyber Security or related field is preferred and 10 years of progressive experience in Information Technology Security. CISSP (Certified information Systems Security Professional), CISM (Certified Information Security Manager), or CRISC (Certified in Risk and Information Systems Control). Experience in leadership or supervisory roles is essential. Demonstrated experience in relevant areas such as cybersecurity, network infrastructure management, cloud environments. Strong familiarity of regulatory knowledge including HIPAA, HITECH, or NIST 800-53.
Training, certification, and/or education in continuous process improvement programs such as Lean Six Sigma as well as completion of Missouri Way, Leadership Academy, and similar programs are preferred.
Lack of post-secondary education will not be used as the sole basis denying consideration to any applicant.Job Details - More reasons to love this positionThe State of Missouri offers an excellent benefits package that includes a defined pension plan, generous amounts of leave and holiday time, and eligibility for health insurance coverage. Your total compensation is more than the dollars you receive in your paycheck. To help demonstrate the value of working for the State of Missouri, we have created an interactive Total Compensation Calculator. This tool provides a comprehensive view of benefits and more that are offered to prospective employees. The Total Compensation Calculator and other applicant resources can be found here.
Contact Details - If you have questions or require any accommodations to participate in the application or interview process please contact:If you have questions about this position, please contact: Toi Wilde at If you experience accessibility issues while applying, please contact Courtney Hall at
Recruitment Area: All qualified applicants.
Application Deadline: August 11, 2026