SENIOR INFORMATION SECURITY MANAGER

Arizona Department of Administration

$137K *
US-AnywhereRemote in Phoenix, AZ
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in information security or related field
  • 3+ years of management experience preferred
  • Strong understanding of compliance frameworks like NIST and IRS Pub 1075
  • Proven experience in security engineering or cloud architecture
  • Expertise in DevSecOps and Agile methodologies

Responsibilities

  • Lead the transformation of the security department into a partner for innovation
  • Mentor security staff, promoting a modern security mindset
  • Communicate security concepts in clear, accessible language
  • Drive automation of security processes to improve efficiency
  • Embed security practices into CI/CD pipelines
  • Implement cloud-native security controls and incident response plans
  • Advocate for risk-based decision-making to support business agility

Benefits

  • Affordable medical, dental, life, and disability insurance
  • Participation in Arizona State Retirement System with employer matching
  • 10 paid holidays and vacation time accrual
  • Paid parental leave up to 12 weeks for new children
  • Flexible scheduling options to support work/life balance
  • Tuition reimbursement and career advancement opportunities
Full Job Description
SENIOR INFORMATION SECURITY MANAGER

Job No: 542419
Work Type: Full-time
Location: REMOTE OPTIONS, PHOENIX
Categories: Information Technology/Services

DEPARTMENT OF REVENUE

SENIOR INFORMATION SECURITY MANAGER

Job Location:

Division of Information Technology
Address: 1600 West Monroe Street, Phoenix, AZ 85007


Posting Details:

Salary: $137,000.00/annually

Grade: 30

Closing Date: 8/27/2026

Job Summary:

The Arizona Department of Revenue's Chief Information Security Officer (CISO) is a visionary role that leads our Information Security organization.

This position serves to protect confidentiality, integrity, and availability of ADOR information and information systems by ensuring appropriate security controls, policies, standards, and procedures are in place and effectively implemented. The CISO plans, reports, and implements all ADOR and statewide security efforts through the continuous review of industry best practices as well as the statewide regulatory and security requirements.

The ADOR CISO is not a traditional "Department of No" security leader. The ADOR CISO is an enabler, a partner, and most importantly, a builder. As our CISO, they protect the highly sensitive financial and tax data of Arizona's citizens while actively removing friction for our Business and IT teams. They champion a culture where security accelerates agility, innovation, and continuous improvement.

The CISO has an engineering mindset, a passion for DevSecOps, and believes that the best way to secure an organization is to automate compliance and partner seamlessly with engineers.

Job Duties:

What You Will Do

1. Strategic Leadership & Cultural Transformation
Be the "Department of How": Shift the security paradigm from acting as a gatekeeper to serving as a trusted advisor and partner. When the business wants to move fast and experiment, your default response is, "Here is how we can do that safely and effectively."

Empower the Team: Mentor and elevate existing Infosec talent, fostering a modern security mindset that values collaboration, empathy, and continuous learning. Develop a framework to drive agility in your team to reskill and adapt to the fast pace of change in business, technology, and regulation.

Bridge the Gap: Communicate complex security and risk concepts in clear, business-friendly terms to executive leadership, technical teams, and non-technical stakeholders alike.

2. DevSecOps & Security Engineering

Lead with an Engineering Mindset: Treat infrastructure and security as code. Drive the adoption of automation to eliminate manual security reviews and bottlenecks.

Shift Left: Deeply integrate security into our CI/CD pipelines. Ensure that vulnerability scanning, compliance checks, and secure coding practices are automated and seamlessly woven into the developer experience.

Modernize Defense: Architect and oversee cloud-native security controls, zero-trust architectures, and automated incident response playbooks.

3. Risk Management & Compliance (at the Speed of Agile)

Secure the Mission: Safeguard Arizona taxpayer data and ensure rigorous compliance with critical frameworks (e.g., IRS Publication 1075, NIST, State of Arizona enterprise security policies).

Automate Compliance: Move away from spreadsheet-based compliance and manual controls and processes. Champion "Compliance-as-Code" to ensure continuous audit readiness without slowing down product delivery.

Pragmatic Risk-Taking: Help the organization make informed, risk-based decisions that balance the need for absolute data protection with the need for technological experimentation and modernization.

What You Bring to the Table

The Right Mindset: You are collaborative, open-minded, and driven by a desire to say "yes" to innovation. You view developer friction as a bug, not a feature of security.

Engineering Background: Proven, hands-on experience in security engineering, cloud architecture, or software development. You don't just read policy; you understand the underlying code and infrastructure.

DevSecOps Expertise: Deep familiarity with modern software development lifecycles, Agile methodologies, CI/CD tools, and security automation technologies.

Regulatory Fluency: A strong understanding of the compliance frameworks relevant to government and financial data (NIST 800-53, IRS Pub 1075, CIS Controls), with a track record of meeting these standards through modern, automated means.

Leadership Experience: Demonstrated success in leading, coaching, and growing high-performing technology or security teams.

Knowledge, Skills & Abilities (KSAs):

Knowledge of:

  • Engineering Background: Proven, hands-on experience in security engineering, cloud architecture, or software development. You don't just read policy; you understand the underlying code and infrastructure.
  • Regulatory Fluency: A strong understanding of the compliance frameworks relevant to government and financial data (NIST 800-53, IRS Pub 1075, CIS Controls), with a track record of meeting these standards through modern, automated means.

    Skill in:
  • The Right Mindset: You are collaborative, open-minded, and driven by desire to say "yes" to innovation. You view developer friction as a bug, not a feature of security.
  • DevSecOps Expertise: Deep familiarity with modern software development lifecycles, Agile methodologies, CI/CD tools, and security automation technologies.

    Ability to:
  • Leadership Experience: Demonstrated success in leading, coaching, and growing high-performing technology or security teams.

    At ADOR, you are doing more than just networks; you are protecting the integrity of the systems that fund Arizona's essential services. We offer a culture that embraces continuous improvement and innovation, where your ideas for modernizing government IT will be heard, supported, and implemented.


Selective Preference(s):

  • Bachelor's degree plus 8 or more years of related experience plus 3 or more years of management experience (or equivalent experience)
    Experience with Continuous Improvement or LEAN is preferred.


Benefits:

The Arizona Department of Revenue offers a comprehensive benefits package to include:

  • Affordable medical, dental, life, and short-term disability insurance plans
  • Participation in the Arizona State Retirement System (ASRS) and long-term disability plans
  • 10 paid holidays per year
  • Vacation time accrued at 4.00 hours bi-weekly for the first 3 years
  • Sick time accrued at 3.70 hours bi-weekly
  • Paid Parental Leave-Up to 12 weeks per year paid leave for newborn or newly-placed foster/adopted child (pilot program).
  • Deferred compensation plan
  • Wellness plans
  • Tuition Reimbursement
  • Infant at Work Program
  • Rideshare and Public Transit Subsidy
  • Career Advancement & Employee Development Opportunities
  • Flexible schedules to create a work/life balance

By providing the option of a full-time or part-time remote work schedule, employees enjoy improved work/life balance, report higher job satisfaction, and are more productive. Remote work is a management option and not an employee entitlement or right. An agency may terminate a remote work agreement at its discretion.

Learn more about the Paid Parental Leave program here. For a complete list of benefits provided by The State of Arizona, please visit our benefits page

Retirement:

Top ranked Arizona State Retirement System (ASRS) provides 100% employer matched contributions (enrollment eligibility will be effective after 27 weeks of State employment). ASRS provides a lifelong benefit based on years of service earned, or worked, and your ending salary. Learn more about ASRS at: https://www.azasrs.gov/content/new-and-prospective-members.

Contact Us:

If you have any questions, need assistance, or would like to request a reasonable accommodation, please contact the ADOR Talent Team at [email protected].

Advertised: 17 Jul 2026 US Mountain Standard Time
Applications close: 27 Aug 2026 US Mountain Standard Time

Whatsapp Facebook LinkedIn Email App

Similar Jobs

More Jobs at Arizona Department of Administration

More Information Technology Jobs

Find similar SENIOR INFORMATION SECURITY MANAGER jobs: