Chief Information Security Officer
About the role
This position is open to U.S. Citizens and permanent residents. This onsite role requires the selected candidate to work from an HHS office in Austin, Texas. The Texas Health and Human Services Commission (HHSC) is seeking an exceptional, forward-thinking Chief Information Security Officer (CISO) to lead cybersecurity for one of the largest and most mission-critical public-sector technology environments in Texas.
Responsibilities
- Provides executive leadership for the HHS cybersecurity program, establishing strategy, governance, priorities, and performance measures aligned with HHSC's mission, regulatory requirements, the Texas Cybersecurity Framework, and NIST guidance.
- Led enterprise security initiatives, including cyber resilience, zero trust, cloud security, identity management, data protection, and post-quantum readiness.
- Advises executive leadership on cybersecurity risks, emerging threats, compliance, and investment priorities.
- Directs the development and maintenance of enterprise security policies, standards, and controls.
- Ensures compliance with applicable state and federal cybersecurity requirements and integrates security into technology planning, procurement, operations, and third-party relationships.
- Led risk management, audits, corrective actions, and executive reporting on security posture while ensuring stakeholders fulfill their information security responsibilities.
- Provides strategic oversight of cybersecurity operations, threat detection, vulnerability management, incident response, and cyber resilience capabilities.
- Ensures the agency can effectively prevent, respond to, and recover from cyber incidents while maintaining critical services.
- Promotes continuous improvement through performance metrics, exercises, lessons learned, and risk-based security investments.
- Leads enterprise cybersecurity efforts supporting emerging technologies, secure modernization, and post-quantum preparedness.
- Guides security architecture, cryptographic modernization, cloud security, artificial intelligence security, and secure technology adoption.
- Ensures security requirements are integrated throughout procurement, system development, implementation, and operations.
- Buils and develops a high-performing cybersecurity workforce and promotes a culture of accountability, collaboration, and continuous improvement.
- Oversees security awareness and training programs and represents HHS on cybersecurity matters with state agencies, business partners, and external stakeholders.
- Oversees cybersecurity budgets, contracts, resource planning, and performance measures.
- Communicates cybersecurity risks, priorities, and outcomes to executive leadership through metrics, reporting, and strategic recommendations.
Requirements
Extensive knowledge of enterprise cybersecurity strategy, governance, risk management, security operations, incident response, and applicable regulatory requirements in a large public-sector environment.
- Extensive federal and state knowledge of cybersecurity frameworks and standards, including NIST guidance, Texas Administrative Code Chapter 202, the Texas Cybersecurity Framework, and risk-based security controls.
- Knowledge of emerging cybersecurity trends and technologies, including post-quantum cryptography, zero trust architecture, cloud security, identity and access management, data protection, artificial intelligence security, and cyber resilience.
- Knowledge of business continuity, disaster recovery, vendor management, contract oversight, and third-party technology risk management.
- Skill in leading large, complex cybersecurity programs and developing enterprise security strategies, governance structures, policies, and measurable outcomes.
- Skill in translating cybersecurity risks into actionable business decisions and communicating effectively with executives, technical staff, public officials, auditors, and other stakeholders.
- Skill in building collaborative relationships and leading security assessments, risk analyses, incident response efforts, audits, and remediation activities.
- Skill in managing large-scale initiatives, budgets, contracts, competing priorities, and developing high-performing cybersecurity teams.
- Ability to provide visionary leadership, exercise sound judgment, and foster a proactive, risk-informed, and mission-focused security culture.
- Ability to balance security, compliance, operational needs, modernization efforts, and user experience while implementing effective solutions to complex challenges.
- Ability to anticipate and address emerging cybersecurity threats, including post-quantum risks, and maintain the security and integrity of critical systems.
- Ability to exercise independent judgment, manage confidential information, and uphold the highest standards of ethics and professionalism.
- Ability to maintain the security and integrity of critical infrastructure systems by preventing unauthorized access and ensuring compliance with laws and regulations related to national security and foreign ownership restrictions.
Qualifications
Graduation from an accredited four-year college or university with major coursework in cybersecurity, computer science, information technology, management information systems, engineering, public administration, business administration, or a related field.
- Relevant senior-level experience may be considered as a substitution for education, consistent with HHSC Human Resources requirements.
- At least 10 years of progressively responsible experience in cybersecurity, information security, technology risk management, security operations, enterprise technology leadership, or a closely related field.
- Significant experience leading cybersecurity, information security, technology risk, or technical teams in a large, complex organization.
- Experience advising executive leadership on cybersecurity strategy, risk, compliance, incident response, investment priorities, or enterprise security posture.
- Experience with cybersecurity frameworks, regulatory compliance, audit coordination, risk management, or security governance in a public-sector, healthcare, financial, critical infrastructure, or similarly regulated environment.