Chief Information Security Officer

Texas Health and Human Services

Austin (TX)

On-site

USD 114,624 - 188,079

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Telework may be permitted

Job summary

Texas Health and Human Services Commission (HHSC) seeks a Chief Information Security Officer (CISO) – Director VI to lead cybersecurity for a large public-sector technology environment in Texas. The role reports to the CIO, leads enterprise security governance, and manages risk, compliance, and post-quantum readiness across the agency.

With 10+ years in cybersecurity leadership, you will guide strategy, executive communications, and large-scale initiatives while overseeing budgets, vendor

Qualifications

  • Graduation from an accredited four-year college or university with major coursework in cybersecurity, information technology, or a closely related field.
  • At least 10 years of progressively responsible experience in cybersecurity, information security, technology risk management, or related leadership roles.
  • Experience leading large, complex cybersecurity programs in a large public-sector or similarly regulated environment.
  • Experience advising executive leadership on strategy, risk, compliance, incident response, or enterprise security posture.
  • Professional credentials such as CISSP, CISM, CISA, CRISC, GIAC or cloud security cert are preferred.

Responsibilities

  • Provide executive leadership and strategy for enterprise cybersecurity aligned with regulatory requirements and recognized frameworks.
  • Direct development of security policies, standards, and controls; ensure regulatory compliance and risk reporting.
  • Oversee threat detection, vulnerability management, incident response, and resilience across the agency.
  • Lead security modernization efforts including post-quantum readiness, cloud security, and identity management.
  • Develop a high-performing cybersecurity workforce and foster accountability and collaboration across stakeholders.
  • Oversee budgets, contracts, and performance metrics; report cybersecurity posture to executive leadership.

Skills

Cybersecurity Strategy
Governance & Compliance
Incident Response
Risk Management
Executive Communication

Education

Bachelor's degree

Job description

Job Overview

Title: Chief Information Security Officer (CISO) – Director VI (Posting #19093)

Agency: Texas Health and Human Services Commission (HHSC), Health & Human Services Comm. Department: CHIEF INFO SECURITY OFFICE.

Location: 4601 W GUADALUPE ST, Austin, TX. Full‑time, day shift. Telework may be eligible. Closing Date: 09/14/2026.

Salary Range: $10,271.00 – $16,853.13 monthly, exempt.

Job Description

The Texas Health and Human Services Commission (HHSC) is seeking an exceptional, forward‑thinking CISO to lead cybersecurity for one of the largest public‑sector technology environments in Texas. The role protects public trust, ensures continuity of essential services, enables secure modernization, and prepares the agency for emerging cyber threats, including artificial intelligence, cloud transformation, third‑party risk, and post‑quantum cryptography.

The CISO reports to the Chief Information Officer, serves as the agency’s Designated Information Security Officer, and administers enterprise information security requirements, coordinates agency‑wide security governance, and reports cybersecurity risk and control effectiveness to executive‑level management in accordance with Texas Government Code 2063.401 and TAC Chapter 202.

Essential Job Functions
  • Enterprise Cybersecurity Leadership and Strategy – 25%: Provides executive leadership, establishes strategy, governance, priorities, and performance measures aligned with HHSC’s mission, regulatory requirements, the Texas Cybersecurity Framework, and NIST guidance. Leads enterprise security initiatives—cyber resilience, zero trust, cloud security, identity management, data protection, and post‑quantum readiness. Advises executive leadership on cybersecurity risks, emerging threats, compliance, and investment priorities.
  • Information Security Governance, Risk, and Compliance – 25%: Directs the development and maintenance of enterprise security policies, standards, and controls. Ensures compliance with applicable state and federal cybersecurity requirements, integrates security into technology planning, procurement, operations, and third‑party relationships, and leads risk management, audits, corrective actions, and executive reporting.
  • Cybersecurity Operations, Incident Response, and Resilience – 20%: Provides strategic oversight of cybersecurity operations, threat detection, vulnerability management, incident response, and cyber resilience capabilities. Ensures the agency can effectively prevent, respond to, and recover from cyber incidents while maintaining critical services. Promotes continuous improvement through metrics, exercises, lessons learned, and risk‑based security investments.
  • Emerging Technology, Post‑Quantum Readiness, and Secure Modernization – 15%: Leads enterprise cybersecurity efforts supporting emerging technologies, secure modernization, and post‑quantum preparedness. Guides security architecture, cryptographic modernization, cloud security, artificial intelligence security, and secure technology adoption. Ensures security requirements are integrated throughout procurement, system development, implementation, and operations.
  • Workforce, Culture, and Stakeholder Engagement – 10%: Builds and develops a high‑performing cybersecurity workforce, promotes a culture of accountability, collaboration, and continuous improvement, oversees security awareness and training programs, and represents HHS on cybersecurity matters with state agencies, business partners, and external stakeholders.
  • Budget, Contracts, Metrics, and Executive Visibility – 5%: Oversees cybersecurity budgets, contracts, resource planning, and performance measures. Communicates cybersecurity risks, priorities, and outcomes to executive leadership through metrics, reporting, and strategic recommendations.
Knowledge, Skills & Abilities (KSAs)
  • Extensive knowledge of enterprise cybersecurity strategy, governance, risk management, security operations, incident response, and applicable regulatory requirements in a large public‑sector environment.
  • Extensive federal and state knowledge of cybersecurity frameworks and standards, including NIST guidance, Texas Administrative Code Chapter 202, the Texas Cybersecurity Framework, and risk‑based security controls.
  • Knowledge of emerging cybersecurity trends and technologies—post‑quantum cryptography, zero‑trust architecture, cloud security, identity and access management, data protection, artificial intelligence security, and cyber resilience.
  • Knowledge of business continuity, disaster recovery, vendor management, contract oversight, and third‑party technology risk management.
  • Skill in leading large, complex cybersecurity programs and developing enterprise security strategies, governance structures, policies, and measurable outcomes.
  • Skill in translating cybersecurity risks into actionable business decisions and communicating effectively with executives, technical staff, auditors, and other stakeholders.
  • Skill in building collaborative relationships and leading security assessments, risk analyses, incident response efforts, audits, and remediation activities.
  • Skill in managing large‑scale initiatives, budgets, contracts, competing priorities, and developing high‑performing cybersecurity teams.
  • Ability to provide visionary leadership, exercise sound judgment, and foster a proactive, risk‑informed, and mission‑focused security culture.
  • Ability to balance security, compliance, operational needs, modernization efforts, and user experience while implementing effective solutions to complex challenges.
  • Ability to anticipate and address emerging cybersecurity threats, including post‑quantum risks, and maintain the security and integrity of critical systems.
  • Ability to exercise independent judgment, manage confidential information, and uphold the highest standards of ethics and professionalism.
  • Ability to maintain the security and integrity of critical infrastructure systems by preventing unauthorized access and ensuring compliance with laws and regulations related to national security and foreign ownership restrictions.
Initial Screening Criteria
  • Graduation from an accredited four‑year college or university with major coursework in cybersecurity, computer science, information technology, management information systems, engineering, public administration, business administration, or a related field. Senior‑level experience may be considered as300 a substitution for education.
  • At least 10 years of progressively responsible experience in cybersecurity, information security, technology risk management, security operations, enterprise technology leadership, or a closely related field.
  • Significant experience leading cybersecurity, information security, technology risk, or technical teams in a large, complex organization.
  • Experience advising executive leadership on cybersecurity strategy, risk, compliance, incident response, investment priorities, or enterprise security posture.
  • Experience with cybersecurity frameworks, regulatory compliance, audit coordination, risk management, or security governance in a public‑sector, healthcare, financial, or similarly regulated environment.
Required Credentials
  • Professional certification such as CISSP, CISM, CISA, CRISC, GIAC, cloud security certification, or comparable advanced cybersecurity credentials is preferred.
Additional Information

The position is onsite with five (5) days in office required. Candidates will be subject to a pre‑employment security review to determine employment eligibility.

Applicants must be U.S. Citizen or permanent resident. The role is open from the Texas Health and Human Services Commission.

EEO Statement

HHSC is an equal‑opportunity employer and is committed to hiring a diverse workforce that reflects the people of Texas. All qualified applicants, regardless of age, color, creed, disability, family or marital status, military or veteran status, or any other protected characteristic, may apply for this position.

Application Process

Applicants may be contacted for background and other due diligence checks. HHSC uses E‑Verify. Bring your I‑9 documentation on your first day of work.

Telework Disclaimer

Telework may be permitted, subject to state and agency telework policies.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CISO & Enterprise Cybersecurity Leader (Telework Eligible)
CISO & Enterprise Cybersecurity Leader (Telework Eligible)

Texas Health and Human Services • Austin (TX)

On-site
Telework may be permitted
Cybersecurity Operations Center Engineer
Cybersecurity Operations Center Engineer

FALL CREEK FARM & NURSERY • Austin (TX)

On-site
USD 78,000 - 132,000
100% paid employee health insurance
Defined benefit pension
Generous time off benefits
Cybersecurity Operations Center Analyst
Cybersecurity Operations Center Analyst

FALL CREEK FARM & NURSERY • Austin (TX)

On-site
USD 78,000 - 132,000
Full health insurance
Defined benefit pension
Generous leave
Cybersecurity Operations Center Engineer
Cybersecurity Operations Center Engineer

Texas Health and Human Services • Austin (TX)

On-site
USD 78,000 - 132,000
Health insurance
Pension plan
Time off
+1
Cybersecurity Operations Center Analyst
Cybersecurity Operations Center Analyst

Texas Health and Human Services • Austin (TX)

On-site
USD 78,000 - 132,000
Health insurance
Pension plan
Paid time off
+1
Chief Information Security Officer | Enterprise Information Security
Chief Information Security Officer | Enterprise Information Security

Texas Attorney General • Austin (TX)

On-site
USD 120,000 - 160,000
Excellent benefits
Opportunities for career growth
Positive work environment
CTO Architect
CTO Architect

FALL CREEK FARM & NURSERY • Austin (TX)

On-site
USD 78,000 - 105,000
Health insurance
Pension plan
Paid time off
+1
Cloud DevOps Engineer
Cloud DevOps Engineer

FALL CREEK FARM & NURSERY • Austin (TX)

On-site
USD 95,000 - 130,000
100% paid employee health insurance
Defined benefit pension plan
Generous time off benefits
+2
CTO Architect
CTO Architect

Texas Health and Human Services • Austin (TX)

On-site
USD 78,000 - 105,000
Enterprise Technology Coordinator
Enterprise Technology Coordinator

FALL CREEK FARM & NURSERY • Austin (TX)

On-site
USD 78,000 - 116,000
Health insurance
Defined benefit pension
Paid time off