State of Arizona

Job Page

State of Arizona$100K — $109K *
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent experience required, plus four years in IT security or related field.
  • Strong supervisory experience in IT disciplines, particularly in security, operations, or infrastructure.
  • Expertise in NIST Cybersecurity Framework, CIS Controls, and state government cybersecurity requirements.
  • Proficiency in incident response frameworks and evidence handling best practices.
  • Familiarity with Microsoft security technologies, cloud security, and Zero Trust principles.

Responsibilities

  • Establish and enhance the organization's security program through hands-on leadership.
  • Oversee cybersecurity operations and coordinate response to incidents and breaches.
  • Develop compliance roadmaps aligning with regulatory standards and internal policies.
  • Lead vulnerability management initiatives and track remediation efforts effectively.
  • Provide security guidance and collaborate with IT leadership on cross-functional initiatives.

Benefits

  • Affordable medical, dental, life, and short-term disability insurance plans.
  • Top-ranked retirement and long-term disability plans.
  • Ten paid holidays per year.
  • Vacation and sick time accrual.
  • Paid parental leave of up to 12 weeks for newborn or newly-placed foster/adopted children.
Full Job Description
Information Technology Security Manager
Job Location:

Address: Information Technology Division
Phoenix, AZ 85007


Posting Details:

Salary: $100,000 - $109,700 Grade: 28 Closing Date: 09/22/23

Job Summary:
• This position serves as the agency's Information Technology Security Manager responsible for establishing, operating, and continuously improving the organization's security program. This position combines cybersecurity governance, risk management, compliance, security architecture, and operational security responsibilities into a hands-on leadership role.
• The position serves as the primary technical security authority for the agency and works closely with executive leadership, infrastructure teams, security analysts, and business stakeholders to reduce cybersecurity risk and ensure compliance with applicable regulatory and security requirements.
• This position is expected to maintain direct technical involvement in security operations, architecture, incident response, vulnerability management, identity management, and audit remediation activities.
• Occasional in-state travel is required for this position.

The Arizona Department of Education currently utilizes a hybrid work environment, with up to two days of remote work (contingent upon business needs). Candidates should apply with an ability and willingness to work in-office up to five days per week as business needs necessitate.

Job Duties:

Governance Risk & Compliance
• Track audit findings, corrective action plans, risk acceptances, and remediation activities through closure.
• Develop and maintain agency cybersecurity compliance roadmaps aligned to NIST, CIS Controls, statutory requirements, Homeland Security requirements, and organizational risk priorities.
• Manage security awareness, phishing testing, and mandatory cybersecurity training programs across the agency.
• In conjunction with Data Governance provide support for eDiscovery, litigation holds, forensic data preservation, and legal investigations.
Security Operations & Incident Response
• Lead day-to-day cyber security operations.
• Develop and maintain security monitoring strategies across cloud, server, endpoint, network, and application environments.
• Identify logging gaps and establish enterprise standards for security: log collection, retention, monitoring, and alerting.
• Coordinate security incident response activities including detection, containment, eradication, recovery, and post-incident reviews.
• Responsible to provide day-to-day leadership and guidance to the cyber security staff.
• Lead the digital forensic investigations and evidence preservation following cyber security incidents along side the analyst.
• Develop and maintain security incident response playbooks and operational procedures.
• Perform threat modeling utilizing STRIDE, PASTA, attack trees, abuse cases, and adversarial risk analysis methodologies.
• Map MITRE ATT&CK techniques to security controls, detections, response capabilities, and defensive gaps.
• Responsible for all internal software reviews and operational approval/denial.
Vulnerability & Patch Management
• Lead vulnerability management activities including vulnerability identification, prioritization, remediation tracking, risk acceptance, and executive reporting.
• Establish risk-based vulnerability remediation standards leveraging CVSS, exploit intelligence, asset criticality, and threat exposure.
• Coordinate internal and external security scanning activities including network, cloud, application, configuration, and penetration testing assessments.
Security Program & Planning
• Develop and maintain the agency cybersecurity roadmap ensuring integration with operational priorities, and technology modernization efforts.
• Provide quarterly cybersecurity risk assessments, security posture reporting, and strategic recommendations to executive leadership.
• Primary contact for cybersecurity vendors, managed security service providers, and consulting partners.
• Develop security standards, procedures, and security baselines, in alignment with NIST, CIS Controls, statutory requirements, Homeland Security requirements. Measure and report cybersecurity performance through metrics, KPIs, risk indicators, and maturity assessments.
• Identify, analyze, prioritize, and implement security controls necessary to reduce organizational risk.
Collaboration
• Provide cyber security guidance to all IT disciplines as it relates to all security initiatives.
• Work within established IT Governance processes to drive cross functional security initiatives.
• Serve as the primary cybersecurity advisor to IT leadership regarding risk, operational security, and compliance matters.
• Contribute to the security architecture reviews for new technologies, major projects, and system implementations.
• Other duties as assigned as related to the position.

Knowledge, Skills & Abilities (KSAs):

Knowledge in:
• NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-61, and NIST Risk Management Framework principles, CIS Critical Security Controls and cybersecurity maturity assessment methodologies, and state government cybersecurity requirements.
• Risk management principles, risk acceptance processes, corrective action planning, and audit remediation tracking.
• Security policies, standards, procedures, and baseline development.
• Monitoring strategies and threat detection methodologies.
• Security logging, SIEM technologies, alerting frameworks, and event correlation techniques.
• Incident response frameworks, evidence handling, chain of custody requirements, and forensic investigation practices.
• MITRE ATT&CK, cyber kill chain concepts, adversary tactics, techniques, and procedures (TTPs).
• Threat modeling methodologies including STRIDE, PASTA, attack trees, and abuse cases.
• Vulnerability assessment methodologies and remediation processes.
• CVSS scoring, exploit intelligence, threat priorities, and risk-based vulnerability management.
• Penetration testing concepts, attack surface analysis, and security scanning tools.
• Cloud security concepts for Microsoft Azure, Microsoft 365, and hybrid environments.
• Network security architecture, endpoint security, identity and access management, and cloud security controls.
• Zero Trust security principles.
• MS Defender, MS Sentinel, Entra ID, Intune, and related MS security technologies.
• Enterprise systems, infrastructure, networking, and application security principles.
• A Bachelors degree, plus four or more years of related experience, or equivalent experience to substitute for the degree, is required.
• Applicants must have supervisory experience in an Information Technology discipline such as Security, Operations, or Infrastructure

Skills in:
• Managing competing priorities, projects, and security initiatives.
• Building collaborative relationships across IT teams, business units, leadership, and external partners.
• Facilitating decision-making and driving accountability for remediation activities.
• Performing cybersecurity risk assessments and risk analysis.
• Developing compliance roadmaps.
• Auditing security controls and tracking remediation activities to closure.
• Developing and managing incident response processes and playbooks.
• Investigating and coordinating responses to cybersecurity incidents.
• Identifying monitoring gaps and designing detection strategies.
• Conducting threat analysis and mapping controls to MITRE ATT&CK techniques.
• Prioritizing vulnerabilities based on risk, exploitability, and business impact.
• Coordinating remediation activities across technical teams.
• Analyzing vulnerability and penetration testing results.
• Developing executive reporting and metrics related to security posture.
• Presenting cybersecurity risk information to executive leadership.
• Writing standards, procedures, and technical documentation.
• Implementing cybersecurity awareness and training programs.
• Communicating effectively with auditors, regulators, vendors, and law enforcement when necessary.
• Intermediate to advanced skill in using Microsoft Outlook, Word, and Excel.

Ability to:
• Analyze complex cybersecurity incidents and determine appropriate response actions.
• Assess security risks and prioritize mitigation efforts based on organizational impact.
• Identify security control gaps and recommend effective compensating controls.
• Interpret threat intelligence and apply it to organizational defenses.
• Lead cross-functional cybersecurity initiatives without direct authority.
• Build consensus among technical and non-technical stakeholders.
• Function as the agency's trusted cybersecurity advisor.
• Manage multiple security programs simultaneously while meeting deadlines.
• Coordinate response activities during high-pressure cybersecurity incidents.
• Preserve confidentiality and handle sensitive information appropriately.
• Produce accurate and meaningful security metrics, dashboards, and executive reports.

Selective Preference(s):

Preference will be given to those applicants with:
• Preferred Certifications: CISSP: Certified Information Systems Security Professional; CISM: Certified Information Security Manager; CEH: Certified Ethical Hacker; GSEC / GCIH / GCIA: GIAC Security Certifications

Pre-Employment Requirements:

Offers are contingent upon successful completion of all background and reference checks, required documents and, if applicable, a post-offer medical/physical evaluation.

If this position requires driving or the use of a vehicle as an essential function of the job to conduct State business, then the following requirements apply: Driver's License Requirements.

Benefits:

The State of Arizona provides an excellent comprehensive benefits package including:
• Affordable medical, dental, life, and short-term disability insurance plans
• Top-ranked retirement and long-term disability plans
• Ten paid holidays per year
• Vacation time accrued at 4.00 hours bi-weekly for the first 3 years
• Sick time accrued at 3.70 hours bi-weekly
• Paid Parental Leave-Up to 12 weeks per year paid leave for newborn or newly-placed foster/adopted child (pilot program).
• Deferred compensation plan
• Wellness plans

Learn more about the Paid Parental Leave program here . For a complete list of benefits provided by The State of Arizona, please visit our benefits page

Retirement:

You will be required to participate in the Arizona State Retirement System (ASRS) upon your 27th week of employment, subject to waiting period. On or shortly after, your first day of employment you will be provided with enrollment instructions and effective date.

Contact Us:

About State of Arizona

The State of Arizona is a government entity responsible for providing a variety of services to its residents, including education, healthcare, and public safety. The state was admitted to the Union in 1912 and has since grown to become the 14th largest state in the United States. Arizona is known for its diverse geography, including the Grand Canyon and other natural wonders. The state government is committed to promoting economic growth and improving the quality of life for all Arizonans.
Learn more about State of Arizona
Size
52,000 employees
Industry

Similar Jobs

More Jobs at State of Arizona

  • State of Arizona
    Job Page
    $100K — $109K *
    Phoenix, AZ 85032 (Maricopa County)
    Education, Government & Non-Profit
    In-Person
  • State of Arizona
    Job Page
    $85K — $100K *
    Phoenix, AZ 85032 (Maricopa County)
    Energy & Utilities
    In-Person
  • State of Arizona
    Job Page
    $80K — $87K *
    Remote
    Healthcare
    Remote in Phoenix, AZ
  • State of Arizona
    Job Page
    $80K — $87K *
    Phoenix, AZ 85032 (Maricopa County)
    Healthcare
    In-Person
  • State of Arizona
    Job Page
    $86K *
    Phoenix, AZ 85032 (Maricopa County)
    Healthcare
    In-Person

More Education, Government & Non-Profit Jobs

Find similar Job Page jobs: