Job Description:
***Crop to Crop resumes are accepted
Location Requirement: 100% Remote unless they reside in Maine. If they reside in Maine, they will need to report onsite Once every 2 weeks. (Will only consider candidates in the Eastern and Central time zones)
As the Agency Information Security Officer, you’ll serve as a trusted security advisor supporting Maine’s executive agencies through cybersecurity engagement, risk management, operational planning, and enterprise security initiatives. This is an opportunity to work directly with agency leaders, MaineIT teams, and security stakeholders to help protect critical public services while strengthening how cybersecurity is managed across the State of Maine.
Reporting Agency Information Security Officer Manager, this role provides consultative, strategic, and operational support across agency and MaineIT environments to help strengthen security programs, guide cross-functional efforts, and support statewide security priorities.
This position plays a key role in advancing enterprise security planning, coordinating cybersecurity activities across agencies and MaineIT divisions, supporting incident response and operational recovery efforts, and helping align security practices with National Institute of Standards and Technology (NIST) guidance and statewide cybersecurity objectives. The role also supports program planning, stakeholder communication, operational readiness efforts, and continuous improvement initiatives tied to Maine’s Information Security Program.
You’ll collaborate with agency leadership, technical teams, operational stakeholders, vendors, and security personnel to identify risks, support security planning initiatives, and help strengthen cybersecurity practices across the State of Maine.
What You’ll Do
No two days look quite the same in MaineIT’s Information Security Office. In general, you can expect to:
Lead Security Coordination: Manage and coordinate cybersecurity program plans, stakeholder engagement, and cross-functional initiatives aligned to agency and statewide priorities.
Partner with Agencies: Collaborate with agency leadership, technical personnel, business teams, and security stakeholders to support risk management and security planning.
Coordinate Incident Response Efforts: Assist with incident response support, escalation management, communication planning, and restoration activities supporting continuity of business operations.
Support Security Planning: Contribute to the development, implementation, maintenance, and review of security plans, procedures, workflows, and program documentation supporting enterprise cybersecurity operations.
Evaluate Security Gaps: Review technical and business information to help identify security gaps, process improvements, and opportunities to strengthen cybersecurity coordination efforts.
Advance Cross-Functional Collaboration: Work with agencies, MaineIT divisions, contractors, vendors, and external stakeholders to align security priorities, timelines, deliverables, and organizational objectives.
Contribute to Continuous Improvement Efforts: Support updates to cybersecurity documentation, processes, security procedures, and program management activities based on lessons learned, business needs, and evolving security priorities.
Why This Role Stands Out
As a cybersecurity professional you have a lot of options when it comes to your career. We get it. Here’s what sets our role apart:
Strategic Impact: Help shape security practices that support agencies in safely delivering essential services to the State and its communities.
Statewide Visibility: Collaborate with agencies, technical teams, leadership, and operational stakeholders supporting cybersecurity coordination across diverse environments.
Professional Growth: Expand your experience supporting enterprise security operations, incident coordination, risk management, and statewide cybersecurity initiatives.
Work That Matters: Strengthen the security of Maine’s public services so residents can rely on government systems that operate safely and securely.
If you are seeking a culture that supports growth, fosters success, and want to play a key role in maintaining the confidentiality, integrity, and availability of State of Maine data and systems, then MaineIT is where you need to be! With the MaineIT Information Security Office, you can expect:
- Generous Telework Opportunities: This position has the opportunity to work 90%-100% remotely.
- Meaningful & Impactful Work: Play a vital role supporting statewide cybersecurity coordination and operational resilience efforts.
- Supportive Team: Join a collaborative, professional environment that invests in your development.
- Work-Life Balance: Flexible scheduling and a healthy balance of professional and personal time.
- Innovative Culture: Be part of a team that values innovation and continuous improvement.
MINIMUM QUALIFICATIONS:
- Bachelor’s degree in cybersecurity, information technology, computer science, information systems, or a related field. Equivalent combinations of education, training, certifications, and relevant experience will also be considered.
- A minimum of 5 years of professional experience in cybersecurity, information security, risk management, security governance, compliance, security program support, or related disciplines.
- Experience supporting or applying cybersecurity frameworks, standards, or guidance, including NIST-based security practices.
Preference will be given to candidates with:
- Understanding of cybersecurity governance concepts, risk management principles, and security planning practices
- Demonstrated success building collaborative relationships across business, technical, and leadership stakeholder groups
- Ability to communicate security risks, priorities, and recommendations to varied audiences
- Background supporting incident coordination, security planning initiatives, or enterprise cybersecurity programs
Preferred Competencies:
- Relationship Management: Builds trusted working relationships across agencies, technical teams, and leadership groups supporting statewide cybersecurity efforts.
- Risk Awareness: Able to recognize operational and security concerns, evaluate potential impacts, and support risk-based decision-making.
- Security Framework Familiarity: Understanding of cybersecurity standards, regulatory expectations, and NIST-aligned security practices.
- Consultative Approach: Comfortable advising stakeholders, facilitating discussions, and helping teams navigate security planning and incident-related matters.
- Executive Communication: Able to present technical and security information clearly to both technical and non-technical audiences.
- Prioritization: Capable of balancing competing priorities, managing sensitive situations, and working effectively within dynamic environments.
Required Skills:
- 5 to 7 years of experience in a leadership role, information security, relationship management, and cross-functional goal achievement
- Regulatory compliance & policy implementation
- Incident response & threat mitigation
Desired Skills:
- Experience with support functions - such as consolidated data centers and disaster recovery sites
- State and or/local government experience
- Bachelor's degree in information technology or related field. Four years of direct experience with information security consultancy may be used in lieu of a degree