Jobs · Information Technology · Texas

Chief Information Security Officer

Texas Health and Human Services · Austin, TX · Yesterday
Information Technology$10k–$17k/moFull-time

Date: Sep 12, 2026

Location: Austin, TX 78751 (4601 W Guadalupe St)

Benefits

  • 100% paid employee health insurance for full‑time eligible employees
  • Defined benefit pension plan
  • Generous time‑off benefits
  • Numerous opportunities for career advancement
  • Additional comprehensive benefits as detailed on the “Benefits of Working at HHS” webpage

Pay

  • Salary range: $10,271.00 – $16,853.13 per month
  • Pay frequency: Monthly
  • Salary group: TEXAS‑B‑31

Schedule

  • Full‑time
  • Shift: Day (Days (First))
  • Telework: Regular
  • Travel: Regular/Temporary – Regular

About the Role

The Texas Health and Human Services Commission (HHSC) is seeking a forward‑thinking Chief Information Security Officer (CISO) to lead cybersecurity for one of the largest and most mission‑critical public‑sector technology environments in Texas. The CISO will protect public trust, support continuity of essential services, enable secure modernization, and prepare the agency for emerging cyber threats such as artificial intelligence, cloud transformation, third‑party risk, and post‑quantum cryptography. Reporting to the Chief Information Officer, the CISO serves as the agency’s Designated Information Security Officer with authority to administer enterprise information security requirements and report risk and control effectiveness to executive leadership.

Responsibilities

  • Enterprise Cybersecurity Leadership and Strategy (25%) – Establish strategy, governance, priorities, and performance measures aligned with HHSC’s mission, regulatory requirements, the Texas Cybersecurity Framework, and NIST guidance; lead initiatives in cyber resilience, zero trust, cloud security, identity management, data protection, and post‑quantum readiness; advise executive leadership on risks, emerging threats, compliance, and investment priorities.
  • Information Security Governance, Risk, and Compliance (25%) – Develop and maintain enterprise security policies, standards, and controls; ensure compliance with state and federal requirements; integrate security into technology planning, procurement, operations, and third‑party relationships; lead risk management, audits, corrective actions, and executive reporting.
  • Cybersecurity Operations, Incident Response, and Resilience (20%) – Provide strategic oversight of threat detection, vulnerability management, incident response, and cyber‑resilience capabilities; ensure the agency can prevent, respond to, and recover from incidents while maintaining critical services; promote continuous improvement through metrics, exercises, and lessons learned.
  • Emerging Technology, Post‑Quantum Readiness, and Secure Modernization (15%) – Guide security architecture, cryptographic modernization, cloud security, AI security, and secure technology adoption; embed security requirements throughout procurement, system development, implementation, and operations.
  • Workforce, Culture, and Stakeholder Engagement (10%) – Build and develop a high‑performing cybersecurity workforce; promote a culture of accountability, collaboration, and continuous improvement; oversee security awareness and training; represent HHS on cybersecurity matters with state agencies, business partners, and external stakeholders.
  • Budget, Contracts, Metrics, and Executive Visibility (5%) – Oversee cybersecurity budgets, contracts, resource planning, and performance measures; communicate risks, priorities, and outcomes to executive leadership through metrics, reporting, and strategic recommendations.

Knowledge, Skills, and Abilities

  • Extensive knowledge of enterprise cybersecurity strategy, governance, risk management, security operations, incident response, and applicable regulatory requirements in a large public‑sector environment.
  • Deep familiarity with federal and state cybersecurity frameworks and standards, including NIST guidance, Texas Administrative Code Chapter 202, and the Texas Cybersecurity Framework.
  • Understanding of emerging trends such as post‑quantum cryptography, zero‑trust architecture, cloud security, identity and access management, data protection, AI security, and cyber resilience.
  • Knowledge of business continuity, disaster recovery, vendor management, contract oversight, and third‑party technology risk management.
  • Proven skill in leading large, complex cybersecurity programs and developing enterprise security strategies, governance structures, policies, and measurable outcomes.
  • Ability to translate cybersecurity risks into actionable business decisions and communicate effectively with executives, technical staff, public officials, auditors, and other stakeholders.
  • Experience building collaborative relationships and leading security assessments, risk analyses, incident response efforts, audits, and remediation activities.
  • Capability to manage large‑scale initiatives, budgets, contracts, competing priorities, and develop high‑performing cybersecurity teams.
  • Visionary leadership, sound judgment, and the ability to foster a proactive, risk‑informed, mission‑focused security culture.
  • Skill in balancing security, compliance, operational needs, modernization efforts, and user experience while delivering effective solutions to complex challenges.
  • Ability to anticipate and address emerging cybersecurity threats, including post‑quantum risks, and maintain the security and integrity of critical systems.
  • Commitment to independent judgment, confidentiality, and the highest standards of ethics and professionalism.
  • Understanding of national‑security and foreign‑ownership restrictions related to critical infrastructure systems.

Qualifications

  • Graduation from an accredited four‑year college or university with major coursework in cybersecurity, computer science, information technology, management information systems, engineering, public administration, business administration, or a related field. Relevant senior‑level experience may substitute for education.
  • At least 10 years of progressively responsible experience in cybersecurity, information security, technology risk management, security operations, enterprise technology leadership, or a closely related field.
  • Significant experience leading cybersecurity, information security, technology risk, or technical teams in a large, complex organization.
  • Experience advising executive leadership on cybersecurity strategy, risk, compliance, incident response, investment priorities, or enterprise security posture.
  • Experience with cybersecurity frameworks, regulatory compliance, audit coordination, risk management, or security governance in a public‑sector, healthcare, financial, critical‑infrastructure, or similarly regulated environment.
  • Preference for professional certifications such as CISSP, CISM, CISA, CRISC, GIAC, cloud‑security certifications, or comparable advanced cybersecurity credentials.
  • U.S. citizenship or permanent residency (position open to U.S. citizens and permanent residents).
  • Willingness to work onsite in Austin, Texas (5 days per week in the office).
  • Subject to a pre‑employment security review and contingent upon available budgeted funds.

Similar jobs