IT Risk Manager #W0115

Virginia Department of Social Services

$121K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of supervisory experience in IT risk management or related field.
  • Expertise in federal and state compliance statutes, regulations, and policies.
  • Demonstrated ability in evaluating and testing security controls within applications.
  • Strong background in risk assessment and analysis, especially related to IT.
  • Experience in project management and team leadership.
  • Familiarity with AI-driven governance, risk, and compliance tools.

Responsibilities

  • Implement the VDSS Risk Management Framework and VITA Information Technology Risk Standard SEC520.
  • Conduct IT risk assessments for sensitive DSS applications.
  • Lead data classification initiatives with key stakeholders.
  • Coordinate quarterly Risk Treatment Plans with system owners.
  • Perform Control Assessments and create System Security Plans for VDSS applications.
  • Serve as a key contact for internal and external IT risk management inquiries.

Benefits

  • Excellent health and life insurance benefits.
  • Pre-tax spending accounts and state-funded short and long-term disability.
  • Paid holidays, vacation, and tuition assistance.
  • Free wellness programs available to employees.
  • State retirement plans with options for tax-deferred savings and employer matching.
Full Job Description
IT Risk Manager #W0115

Job no:
Work type: Full-Time (Salaried)
Location: Richmond (City), Virginia
Categories: Information Technology

Title: IT Risk Manager #W0115

State Role Title: Info Technology Specialist III

Hiring Range: $121,000 - $130,000 per year (salary commensurate with experience)

Pay Band: 6

Agency: Department of Social Services

Location: DSS HOME OFFICE

Agency Website: https://www.dss.virginia.gov/

Recruitment Type: General Public - G

Job Duties

The IT Risk Manager is responsible for implementing the VDSS Risk Management Framework and the VITA Information Technology Risk Standard SEC520. The position provides VDSS Information Security and Risk Management leadership, strategic direction and consultation on information security risk and compliance. The IT Risk Manager leads and facilitates Data Classification with Business Owners, System Owners and the Business Continuity Manager to determine application sensitivity and performs IT Risk Assessments for the all sensitive DSS applications, coordinating with Business Owners, System Owners, and System Administrators to develop a risk-based assessment in accordance with VITA SEC520. The IT Risk Manager coordinates quarterly Risk Treatment Plans with System Owners and VITA Commonwealth Security and Risk Management. Further, the IT Risk Manager is responsible for conducting Control Assessments and System Security Plans for each VDSS application. The IT Risk Manager serves as an agency point of contact for internal and external entities regarding IT Risk Management for VDSS. The position provides VDSS Information Security and Risk Management leadership, strategic direction and consultation on information security risk and compliance and oversees Information Technology and Risk Management staff, including the IT Risk Analysts.

Minimum Qualifications
• Comprehensive, advanced, demonstrated, and supervisory experience in Information Systems, business, or related IT risk management fields.
• Comprehensive, advanced, demonstrated, and supervisory experience in applying complex federal and state statutes, regulations, policies and procedures governing the area of compliance.
• Advanced experience in evaluating and testing security controls within computer applications
• Advanced experience in reviewing and/or writing reports, policies and procedures.
• Comprehensive experience in working on and/or leading projects and teams.
• Comprehensive and advanced experience performing IT Risk Assessments
• Experience in building and implementing software tools
• Experience using or implementing AI-driven governance, risk, and compliance (GRC) tools, or automated risk analytics platforms.

KSA's and/or Competencies required to successfully perform the work:
1. Technical and Functional Expertise - Possess a thorough understanding of over SEC530 and other NIST related information security standard security controls across Agency, State, and Federal security frameworks. Experience with developing and updating Risk Assessments, Data Classifications, System Security Plans, Control Assessments, and coordinating Authorities to Operate. Experience or knowledge of system design principles. Ability to gather data from automated and manual sources and through interviews with staff to make risk determinations. Ability to understand state and federal security controls (NIST 800-53A, IRS 1075, CMS MARS-E, SSA, etc.) and determine compliance with those controls.
2. Understanding Business - Understand the overlapping uses of Information Systems to support VDSS and to provide assurance on core business processes in risk management and governance.
3. Results Focused - Issue Data Classifications, Security Impact Analyses, Risk Assessments, System Security Plans, Internal Controls Weakness, Control Assessment evaluations for applications.
4. Interpersonal Communication - Demonstrated ability to communicate effectively both orally and in writing with diverse groups of organizations and people. Ability to translate complex technical risks into clear, actionable information for leadership.
5. Technical and Functional Expertise - High degree of independent judgement. Become proficient in other members security office duties for contingency operations
6. Personal Effectiveness - Willingness to be very flexible, ability to maintain the highest professional standards, and competence to be accurate, thorough, and productive with all work.
7. Project Organization - Experience in planning and organization projects through Jira.
8. Tool adoption - Experience utilizing AI-driven risk management tools to provide solutions to automate risk detection, analyze trends, perform predictive risk modeling, and improve the accuracy and speed of assessments.

Additional Considerations
• Current Security Credentials like CISA, CISM, CISSP, CRISC, etc.
• Experience in state government related to IT risk management, technology governance, audit, or cybersecurity.

Special Instructions

You will be provided a confirmation of receipt when your application and/or résumé is submitted successfully. Please refer to "Your Application" in your account to check the status of your application for this position.

To be considered for this position, you must submit a Commonwealth of Virginia application or resume through the on-line "Virginia Jobs" (PageUp) employment site no later than 11:55 p.m. on the closing date listed. Each application is reviewed for documentation that shows the applicant meets the minimum and additional considerations as stated in the job announcement. The decision to interview an applicant is based on the information provided. Multiple positions may be filled from this recruitment within 90 days of the closing date.

In addition to a rewarding work experience, VDSS offers excellent health and life insurance benefits, pre-tax spending accounts, state funded Short and Long Term Disability, paid holidays, vacation, tuition assistance, free wellness programs, and a state retirement plan with options for tax-deferred retirement savings including employer matching - Employee Benefits.

Contact Information

Name: VDSS - Division of Human Resources

Phone: [email protected]

Email: [email protected]

In support of the Commonwealth's commitment to inclusion, we are encouraging individuals with disabilities to apply through the Commonwealth Alternative Hiring Process. To be considered for this opportunity, applicants will need to provide their AHP Letter (formerly COD) provided by the Department for Aging & Rehabilitative Services (DARS), or the Department for the Blind & Vision Impaired (DBVI). Service-Connected Veterans are encouraged to answer Veteran status questions and submit their disability documentation, if applicable, to DARS/DBVI to get their AHP Letter. Requesting an AHP Letter can be found at AHP Letter or by calling DARS at 800-552-5019.

Note: Applicants who received a Certificate of Disability from DARS or DBVI dated between April 1, 2022- February 29, 2024, can still use that COD as applicable documentation for the Alternative Hiring Process.

Advertised: 27 Aug 2026 Eastern Daylight Time
Applications close:

Whatsapp Facebook LinkedIn Email App

Similar Jobs

More Jobs at Virginia Department of Social Services

More Information Technology Jobs

Find similar IT Risk Manager #W0115 jobs: