Information Security Officer

State of Connecticut

• $95K — $115K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in IT operations, programming, or software development.
  • 1 year of experience in a security-focused IT role.
  • Strong understanding of systems analysis, design, and computer programming principles.
  • Familiarity with compliance standards including HIPAA and NIST guidelines.
  • Proven experience with security platforms like SIEM/SOAR and endpoint detection.

Responsibilities

  • Lead adoption and configuration of statewide security platforms in DMHAS.
  • Assess and enhance DMHAS's security capabilities against state benchmarks.
  • Develop security documentation and training programs for staff.
  • Maintain compliance with HIPAA and 42 CFR Part 2 regulations.
  • Coordinate incident tracking and response with the Statewide Cybersecurity team.

Benefits

  • Hybrid work model allowing both telework and on-site work.
  • Professional development opportunities to build IT security expertise.
  • Flexible first shift schedule with typical hours from 8:00 A.M. to 4:30 P.M.
  • Potential for training and advancement within the Statewide Cybersecurity team.
Full Job Description
POSITION HIGHLIGHTS

  • Schedule: Full-Time (40 Hours), First Shift (8:00 A.M. - 4:30 P.M.), Monday - Friday, Hybrid (Telework/On-site)
  • Location: Middletown, CT

THE ROLE

This position leads the maturation and scaling of statewide security platforms, tools, practices, and expertise into DMHAS. It acts as DMHAS's system security officer of record (principal advisor on technical and administrative matters involving the security of DMHAS's information systems) while embedded within DMHAS IT and working in close, ongoing coordination with the Statewide Cybersecurity team.

DISCOVER THE OPPORTUNITY TO

  • Serve as DMHAS's embedded partner to the Statewide Cybersecurity team, ensuring DMHAS tooling, architecture, and practices align to enterprise security standards.
  • Lead adoption, configuration, and maturation of statewide-deployed security platforms (endpoint detection and response, SIEM/SOAR, vulnerability management, and others) within DMHAS.
  • Assess DMHAS's security program against statewide maturity benchmarks and execute roadmaps to close identified gaps.
  • Build internal DMHAS security capability, including documentation, repeatable practices, staff expertise reducing reliance on ad-hoc knowledge.
  • Act as DMHAS's system security officer of record and principal advisor on technical and administrative security matters.
  • Maintain DMHAS compliance with the HIPAA Security Rule and 42 CFR Part 2 confidentiality requirements for substance use disorder treatment records.
  • Work to align DHMAS policy & governance controls to statewide. Cybersecurity Policies, identify gaps or opportunities, maintain compliance consistent with NIST standards, HHS guidance, and statewide policy.
  • Lead DHMAS incident tracking, response and reporting, coordinating with the Statewide Cybersecurity team on enterprise-level incidents.
  • Prepare and represent DMHAS in audits, regulatory inquiries, and statewide security reviews.
  • Design and deliver security and privacy training and awareness programs for DMHAS staff, including PHI/HIPAA-specific new-employees.
  • Other duties as identified by Statewide Cybersecurity team.
  • Although exceptionally rare, on-call may be required, such as extended hours and some weekends.


PURPOSE OF JOB CLASS (NATURE OF WORK)

In a state agency Information Technology (IT) environment this class is accountable for performing the most complex and technical support work and/or acting as a working supervisor of Information Technology Analysts engaged in information systems development or technical support.

EXAMPLES OF DUTIES

All Functional Areas

  • Diagnoses host system problems and develops and coordinates resolutions;
  • Manages planning, analysis, design, selection, installation and implementation of new technologies;
  • Evaluates new technologies;
  • Tests and evaluates new hardware and/or software;
  • Makes recommendations for hardware and/or software purchases;
  • Determines interface and utility requirements and creates design specifications;
  • Acts as liaison to hardware and/or software vendors, system developers, programmers and management;
  • Develops and implements network and system security guidelines;
  • Makes recommendations for migration and upgrade directions;
  • Trains operators, systems developers and users on new procedures;
  • Conducts system performance analysis, tuning or storage management;
  • Conducts technical training programs for IT staff;
  • Acts as project coordinator overseeing other technical staff and support personnel;
  • Plans, coordinates and directs multiple projects of assigned staff;
  • Reviews work of assigned personnel;
  • Calculates project time and cost estimates;
  • Prepares necessary procedural specifications to meet design requirements;
  • Arranges necessary hardware and software availability;
  • Oversees hardware and software vendors;
  • Manages project budgets and schedules;
  • Reviews work of assigned Information Technology Analysts and serves as consultant and/or troubleshooter;
  • Reviews documentation work of assigned staff;
  • Communicates with business owners and management;
  • Facilitates meetings;
  • Assists in the development of information technology policies, procedures and standards;
  • Participates in Request for Proposal (RFP) process;
  • Implements disaster recovery plans, assists in determining critical applications and personnel, or ensures offsite backups;
  • Defines data flow;
  • Performs related duties as required.


Systems Programming

  • Performs the most complex duties related to application development;
  • Develops and implements system programming standards;
  • Configures and installs host-based application packages;
  • Maintains host operating systems;
  • Installs and upgrades host and/or Front End Processor (FEP) operating system software;
  • Performs related duties as required.


Network Support

  • Designs and implements complex communications networks;
  • Diagnoses and resolves problems using network management systems and utilities;
  • Performs related duties as required.


IT Security

  • Develops, tests and maintains agency disaster recovery plans designed to restore IT system operability;
  • Develops processes and procedures in support of IT Business Continuity Planning;
  • Conducts platform recoverability assessments and Business Impact Analysis (BIA) to determine and assess the impacts associated with disruptions to business functions;
  • Conducts risk analysis of IT environments by assessing administrative, technical and physical safeguards;
  • Performs IT investigations to include maintaining chain of custody procedures;
  • Performs forensics and documents detailed reports of findings;
  • Performs related duties as required.


KNOWLEDGE, SKILL AND ABILITY

  • Considerable knowledge of
    • principles and techniques of systems analysis, design, development, and computer programming;
    • principles of information systems;
    • principles and theories of business and planning functions;
    • programming languages;
    • project management principles and techniques;
    • principles, problems and techniques of data processing and data communication operations;
    • data processing and data communications equipment and diagnostic tools;
    • methods and procedures used to conduct detailed analysis and design of computer systems;
    • principles of complex computer operating systems;
  • Knowledge of
    • principles and techniques of business information systems re-engineering;
    • network protocols and architecture;
    • practices and issues of systems security and disaster recovery;
    • applications systems development principles and techniques;
    • principles and practices of database management;
  • Considerable
    • interpersonal skills;
    • oral and written communication skills;
    • skill in problem solving;
    • skill in technical problem solving;
    • skill in analysis;
  • Considerable ability to
    • prepare correspondence, manuals, reports and documentation;
    • analyze and resolve operational and communications problems;
    • analyze and debug complex software programs;
    • identify, analyze and resolve complex business and technical problems;
  • Supervisory ability.


MINIMUM QUALIFICATIONS - GENERAL EXPERIENCE

Seven (7) years of experience in information technology (IT) operations, programming, systems/software development or another IT-related field.

MINIMUM QUALIFICATIONS - SPECIAL EXPERIENCE

One (1) year of the General Exp

Similar Jobs

More Jobs at State of Connecticut

More Healthcare Jobs

Find similar Information Security Officer jobs: