Chief Information Security Officer (Contract)

State of Illinois•Springfield, MO
•Hybrid

About The Position

Serves as the Department's Chief Information Security Officer, leading the agency information security program in coordination with the Department of Innovation and Technology. Establishes, maintains, and enforces the Department's information security policies, standards, and procedures consistent with the Department of Innovation and Technology enterprise security framework, applicable National Institute of Standards and Technology standards, and the Federal Bureau of Investigation Criminal Justice Information Services Security Policy. Develops and administers the Department's information security risk management program, including periodic risk assessments, security control assessments, and plans of action and milestones. Provides administrative input into the development of Department information technology policies, standard operating procedures, and security-related directives. Assesses and evaluates the effectiveness of information security operations, policies, procedures, and internal controls, and drives continuous improvement based on assessment findings, audit results, and threat trends. Advises Department executive leadership on information security posture, emerging risks, and resource requirements. Serves as the Department's designated security official and Information Security Officer for regulated data, ensuring compliance with state and federal information protection requirements. Implements and oversees the technical safeguards required to keep protected health information secure; prevents unauthorized access to protected health information through access controls, authentication, and audit controls; establishes and implements procedures for the secure transmission of electronic protected health information (ePHI), including encryption in transit; and determines and maintains requirements for the proper storage of ePHI, including encryption at rest and retention. Directs the Department's security operations, incident response, and breach notification activities in coordination with the Department of Innovation and Technology. Establishes and maintains the Department's incident response plan and serves as the agency point of accountability for information security incidents. Coordinates detection, containment, investigation, and recovery activities with the Department of Innovation and Technology security operations and, where applicable, law enforcement. Administers breach notification determinations and timelines required under the Personal Information Protection Act and other applicable authorities. Oversees identity and access management, privileged access controls, and insider threat monitoring across Department systems and facilities. Governs the security of connected operational technology across Department facilities, including surveillance, access control, body worn camera, and related systems. Serves as the Department's information security lead for external audits, compliance reviews, and oversight inquiries. Plans, develops, and delivers information security training and awareness across the Department. Performs other duties as required or assigned.

Requirements

  • Bachelor’s degree from an accredited college or university in information security, computer science, information technology, or a closely related field.
  • A minimum of five (5) years of progressively responsible professional experience in information security, including experience developing and administering information security policies and risk management programs.
  • Demonstrated working knowledge of NIST security standards, the FBI CJIS Security Policy, and the HIPAA Security Rule.
  • Ability to pass the IDOC/IDJJ background check.
  • Ability to pass a drug screen.
  • Required to utilize digital technology, tools, platforms, and processes in managing and supporting various digital enhancements for greater efficiency, productivity, and digital transformation efforts within the department.

Responsibilities

  • Serves as the Department's Chief Information Security Officer, leading the agency information security program.
  • Establishes, maintains, and enforces the Department's information security policies, standards, and procedures.
  • Develops and administers the Department's information security risk management program.
  • Provides administrative input into the development of Department information technology policies, standard operating procedures, and security-related directives.
  • Assesses and evaluates the effectiveness of information security operations, policies, procedures, and internal controls.
  • Advises Department executive leadership on information security posture, emerging risks, and resource requirements.
  • Serves as the Department's designated security official and Information Security Officer for regulated data.
  • Implements and oversees the technical safeguards required to keep protected health information secure.
  • Prevents unauthorized access to protected health information through access controls, authentication, and audit controls.
  • Establishes and implements procedures for the secure transmission of electronic protected health information (ePHI), including encryption in transit.
  • Determines and maintains requirements for the proper storage of ePHI, including encryption at rest and retention.
  • Directs the Department's security operations, incident response, and breach notification activities.
  • Establishes and maintains the Department's incident response plan and serves as the agency point of accountability for information security incidents.
  • Coordinates detection, containment, investigation, and recovery activities with the Department of Innovation and Technology security operations and, where applicable, law enforcement.
  • Administers breach notification determinations and timelines required under the Personal Information Protection Act and other applicable authorities.
  • Oversees identity and access management, privileged access controls, and insider threat monitoring across Department systems and facilities.
  • Governs the security of connected operational technology across Department facilities.
  • Serves as the Department's information security lead for external audits, compliance reviews, and oversight inquiries.
  • Coordinates the Department's information security audit response.
  • Tracks open findings, management responses, and remediation status through closure.
  • Prepares security briefing materials, attestations, and exhibits as needed.
  • Designs and conducts security awareness training for Department staff and role based training for staff handling sensitive data.
  • Develops and maintains security reference materials, acceptable use guidance, and incident reporting procedures.
  • Promotes a culture of security awareness and accountability across Department divisions and facilities.
  • Performs other duties as required or assigned.

Benefits

  • health, vision, and dental insurance
  • retirement plan and deferred compensation
  • state holidays and other benefit time off
  • tuition reimbursement
  • pre-tax benefit programs
  • extensive training and career advancement opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service