State of Iowa

Information Technology Enterprise Expert - Information Security Architect

State of Iowa$85K — $197K *
Information Technology
15+ years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in security architecture or enterprise design.
  • Expertise in implementing NIST and RMF frameworks.
  • Proficient in threat modeling using MITRE ATT&CK and the cyber kill chain.
  • Strong collaboration skills for inter-agency coordination.
  • Ability to translate complex policies into security controls.
  • Forward-thinking mindset toward emerging cybersecurity threats.
  • Preferred certifications include CISSP, CISA, or GSEC.

Responsibilities

  • Develop and enhance the enterprise security architecture framework.
  • Define and enforce security control standards across systems and services.
  • Establish and maintain security controls for consistent statewide posture.
  • Identify compensating controls for scenarios where baseline measures are unfeasible.
  • Ensure compliance with national standards and Iowa's Cyber Strategy.
  • Translate policy requirements into enforceable security measures.
  • Conduct threat modeling to inform architecture decisions.
  • Improve visibility and reporting for security audits and incident responses.
  • Collaborate with leadership on securing design principles.
  • Lead initiatives on project charters and vendor management.
  • Analyze security trends and report on architecture effectiveness.
  • Represent the CISO in strategic planning efforts across agencies.

Benefits

  • Flexible work environment with potential for remote work arrangements.
  • Comprehensive health, dental, and vision insurance coverage.
  • Generous time off including vacation and sick leave.
  • Access to life and disability insurance options.
  • Retirement savings plans including IPERS and RIC.
  • Multiple Flexible Spending Accounts available for healthcare and dependent care.
Full Job Description
Salary : $85,176.00 - $197,704.00 Annually
Location : Des Moines - 50309 - Polk County, IA
Job Type: Full-time
Job Number: 27-00553
Agency: 532 Iowa Department of Management
Opening Date: 08/24/2026
Closing Date: 9/6/2026 11:59 PM Central
LinkedIn Tag: #LI-POST
Point of Contact:

Job Description
Only applicants who meet the Minimum Qualification Requirements and meet all selective requirements (listed below) will be placed on the eligible list.

The Department of Management (DOM), Division of Information Technology (DoIT), is seeking an Information Security Architect to design, implement, and govern the State of Iowa's enterprise security architecture. This position is critical to safeguarding state systems and data by embedding security into technology solutions, aligning with national standards, and advancing the Iowa Cyber Strategy and CyberGUARD framework.

Key Responsibilities
  • Develop, implement, and continuously improve the State's enterprise security architecture framework.
  • Define and enforce standards that integrate security controls across systems, platforms, and services.
  • Establish scalable technical, administrative, and physical controls to maintain a consistent security posture statewide.
  • Serve as the authority for identifying and documenting compensating controls when baseline measures are not feasible.
  • Ensure alignment with NIST SP 800-53, Risk Management Framework (RMF), and the Iowa Cyber Strategy.
  • Translate compliance and policy requirements into measurable, enforceable security controls.
  • Conduct threat modeling using frameworks such as MITRE ATT&CK and the cyber kill chain to inform architecture decisions.
  • Enhance visibility and reporting of controls to support audits, assessments, and incident response.
  • Collaborate with leadership, agency partners, and technical teams to embed secure design principles.
  • Lead enterprise-wide initiatives, including project charters, cost-benefit analyses, and vendor oversight.
  • Analyze statewide security trends and report on performance, risk posture, and architecture effectiveness.
  • Represent the Chief Information Security Officer (CISO) in interagency committees and strategic planning efforts.
  • Promote adoption of CyberGUARD standards and secure architecture practices across agencies.
  • Evaluate emerging technologies and evolving threats to strengthen enterprise security architecture.

What We're Looking For
  • Proven expertise in security architecture and enterprise-level design.
  • Experience with NIST and RMF frameworks for secure system implementation.
  • Knowledge of threat modeling using MITRE ATT&CK and cyber kill chain methodologies.
  • Strong collaboration skills to work across agencies and technical teams.
  • Ability to translate policy into actionable controls for compliance and audit readiness.
  • Forward-thinking approach to address emerging threats and technologies.
  • Preferred certifications: CISSP, CISA, GSEC, or equivalent.

What We Offer
  • Flexible work environment
  • Iowa Public Employees' Retirement System (IPERS)
  • Health, dental, and vision insurance
  • Generous vacation, sick leave, and paid holidays
  • Life and disability insurance
  • Retirement savings options (RIC)
  • Flexible Spending Accounts

Working Arrangement
This position requires onsite work in Des Moines, IA each week. Employees meeting all expectations of their work responsibilities may request remote work and develop a hybrid/remote schedule collaboratively with their manager.

Please note, candidates for this position must reside in the state of Iowa at the time of starting the role.

Selectives

727 Risk Assessment:
6 months' experience, 12 semester hours, or a combination of both in analyzing and identifying risks and the corresponding potential impact to information and information technology systems.

AND

728 Physical Security:
6 months' experience, 12 semester hours, or a combination of both in the physical aspects of securing information technology systems.

AND

990 Cyber Security Planning:
A minimum of 18 months of full-time work experience in cyber security planning at a professional level that included the following major functions: participating in and leading a company-/agency-wide cyber security planning program including the identification of cyber security risks, development of prevention and response plans to minimize cyber-attack damages including mass care and consequences management, and the development of continuation of business operation plans; participating in national cyber security planning initiatives and exercises; responding to and participating in the recovery work from cyber security incidents; and working across governments, private sectors, and non-profit organizations collaboratively on cyber security planning activities and plans for response.
Minimum Qualification Requirements

Applicants must meet at least one of the following minimum requirements to qualify for positions in this job classification:

1) Graduation from an accredited four-year college or university with a degree in any field, and experience equal to five years of full-time work in one or more of the following areas: mainframe computing systems programming; computer-based networking (LAN, WAN); database management systems; applications development, maintenance, and testing; server and workstation operating systems; telecommunications carrier operations; and/or Internet/Intranet development and deployment.
2) All of the following (a and b): a. Five years of full-time work experience in one or more of the following areas: mainframe computing systems programming; computer-based networking (LAN, WAN); database management systems; applications development, maintenance, and testing; server and workstation operating systems; telecommunications carrier operations; and/or Internet/Intranet development and deployment; and b. One of the following (i or ii): i. Twenty-four semester hours of accredited post-high-school course work in one of the specialty areas listed in part a; or ii. Certification from an authorized educational institution or a major computer/software producer in an area directly related to one of the specialty areas listed in part a.
3) A total of nine years of education and/or full-time experience in one or more of the following areas: mainframe computing systems programming; computer-based networking (LAN, WAN); database management systems; applications development, maintenance, and testing; server and workstation operating systems; telecommunications carrier operations; and/or Internet/Intranet development and deployment, where thirty semester hours of accredited college or university coursework in any field equals one year of full-time experience.
4) Current, continuous experience in the state executive branch that includes two years of full-time work as an Information Technology Specialist 5.

About State of Iowa

The State of Iowa is a government entity responsible for providing services and programs to the residents of Iowa. The state government is divided into three branches: the executive branch, the legislative branch, and the judicial branch. The executive branch is headed by the Governor of Iowa, who is responsible for implementing and enforcing state laws. The legislative branch is responsible for making laws, while the judicial branch is responsible for interpreting laws and administering justice. The State of Iowa was admitted to the Union on December 28, 1846, and has since become known for its agriculture, manufacturing, and renewable energy industries.
Learn more about State of Iowa
Size
18,000 employees
Industry

Similar Jobs

More Jobs at State of Iowa

More Information Technology Jobs

Find similar Information Technology Enterprise Expert - Information Security Architect jobs: