IT Risk Manager #W0115

Virginia Information Technologies AgencyRichmond, VA
$121,000 - $130,000Hybrid

About The Position

At the Virginia Department of Social Services, we put people at the center of everything we do. We believe that every Virginian can live a life of dignity and that all voices, ideas and experiences contribute greatly to our pursuit of excellence. Inspired by continuous improvement, we commit ourselves to listening, learning and cultivating environments of trust, respect and positive engagement. Together, we are mission-driven, eager to achieve, and passionate about bringing the best of who we are to those we serve. We design and deliver high-quality human services that help Virginians achieve safety, independence and overall well-being. We are a $2 billion agency – one of the largest in the Commonwealth of Virginia – partnering with 120 local departments of social services and 31 community action agencies, along with faith-based and non-profit organizations, to promote the well-being of children, adults, and families statewide. We proudly serve alongside 1,650 (state) and 12,200 (local) human services professionals throughout the Social Services System, who ensure that thousands of Virginia’s most vulnerable citizens have easy access to the services and benefits available to them. The IT Risk Manager is responsible for implementing the VDSS Risk Management Framework and the VITA Information Technology Risk Standard SEC520. The position provides VDSS Information Security and Risk Management leadership, strategic direction and consultation on information security risk and compliance. The IT Risk Manager leads and facilitates Data Classification with Business Owners, System Owners and the Business Continuity Manager to determine application sensitivity and performs IT Risk Assessments for the all sensitive DSS applications, coordinating with Business Owners, System Owners, and System Administrators to develop a risk-based assessment in accordance with VITA SEC520. The IT Risk Manager coordinates quarterly Risk Treatment Plans with System Owners and VITA Commonwealth Security and Risk Management. Further, the IT Risk Manager is responsible for conducting Control Assessments and System Security Plans for each VDSS application. The IT Risk Manager serves as an agency point of contact for internal and external entities regarding IT Risk Management for VDSS. The position provides VDSS Information Security and Risk Management leadership, strategic direction and consultation on information security risk and compliance and oversees Information Technology and Risk Management staff, including the IT Risk Analysts.

Requirements

  • Comprehensive, advanced, demonstrated, and supervisory experience in Information Systems, business, or related IT risk management fields.
  • Comprehensive, advanced, demonstrated, and supervisory experience in applying complex federal and state statutes, regulations, policies and procedures governing the area of compliance.
  • Advanced experience in evaluating and testing security controls within computer applications.
  • Advanced experience in reviewing and/or writing reports, policies and procedures.
  • Comprehensive experience in working on and/or leading projects and teams.
  • Comprehensive and advanced experience performing IT Risk Assessments.
  • Experience in building and implementing software tools.
  • Experience using or implementing AI-driven governance, risk, and compliance (GRC) tools, or automated risk analytics platforms.
  • Possess a thorough understanding of over SEC530 and other NIST related information security standard security controls across Agency, State, and Federal security frameworks.
  • Experience with developing and updating Risk Assessments, Data Classifications, System Security Plans, Control Assessments, and coordinating Authorities to Operate.
  • Experience or knowledge of system design principles.
  • Ability to gather data from automated and manual sources and through interviews with staff to make risk determinations.
  • Ability to understand state and federal security controls (NIST 800-53A, IRS 1075, CMS MARS-E, SSA, etc.) and determine compliance with those controls.
  • Understand the overlapping uses of Information Systems to support VDSS and to provide assurance on core business processes in risk management and governance.
  • Issue Data Classifications, Security Impact Analyses, Risk Assessments, System Security Plans, Internal Controls Weakness, Control Assessment evaluations for applications.
  • Demonstrated ability to communicate effectively both orally and in writing with diverse groups of organizations and people.
  • Ability to translate complex technical risks into clear, actionable information for leadership.
  • High degree of independent judgement.
  • Become proficient in other members security office duties for contingency operations.
  • Willingness to be very flexible, ability to maintain the highest professional standards, and competence to be accurate, thorough, and productive with all work.
  • Experience in planning and organization projects through Jira.
  • Experience utilizing AI-driven risk management tools to provide solutions to automate risk detection, analyze trends, perform predictive risk modeling, and improve the accuracy and speed of assessments.

Nice To Haves

  • Current Security Credentials like CISA, CISM, CISSP, CRISC, etc.
  • Experience in state government related to IT risk management, technology governance, audit, or cybersecurity.

Responsibilities

  • Implementing the VDSS Risk Management Framework and the VITA Information Technology Risk Standard SEC520.
  • Providing VDSS Information Security and Risk Management leadership, strategic direction and consultation on information security risk and compliance.
  • Leading and facilitating Data Classification with Business Owners, System Owners and the Business Continuity Manager to determine application sensitivity.
  • Performing IT Risk Assessments for all sensitive DSS applications, coordinating with Business Owners, System Owners, and System Administrators to develop a risk-based assessment in accordance with VITA SEC520.
  • Coordinating quarterly Risk Treatment Plans with System Owners and VITA Commonwealth Security and Risk Management.
  • Conducting Control Assessments and System Security Plans for each VDSS application.
  • Serving as an agency point of contact for internal and external entities regarding IT Risk Management for VDSS.
  • Overseeing Information Technology and Risk Management staff, including the IT Risk Analysts.

Benefits

  • excellent health and life insurance benefits
  • pre-tax spending accounts
  • state funded Short and Long Term Disability
  • paid holidays
  • vacation
  • tuition assistance
  • free wellness programs
  • a state retirement plan with options for tax-deferred retirement savings including employer matching
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service