Shape the Future of AIJoin one of the UK's fastest-growing companies and become a Professional Development Expert in Artificial Intelligence.

View Roles

Information Security Officer

Commonwealth of Virginia
Derbyshire
1 week ago
Create job alert

Title:Information Security Officer

Agency:VCCS-System Office

Location:Chesterfield - 041

FLSA:Exempt

Hiring Range:$80,000 - $100,000

Full Time or Part Time:Full Time


Job Description:


Virginia's community colleges have a 50-year track record of educational excellence and innovation to serve the needs of our citizens and strengthen the Commonwealth’s economy. When Virginia’s General Assembly established the Virginia Community College System in 1966, the need for a comprehensive system was well known. Over the two decades after the end of World War II, leaders in government, business, professional sectors, and academia had called for a new approach to providing educational opportunity. A key concern was Virginia's ability to develop a skilled and knowledgeable workforce to expand the state's economy. Today our community colleges give every Virginian the opportunity to gain a quality education. With 23 colleges on 40 campuses located throughout the state, Virginia's Community Colleges are committed to serving Virginia families, helping them acquire the knowledge and skills to seize the opportunities of today and tomorrow.

The Information Security Officer provides guidance and oversight for information security activities necessary to secure and protect information resources and technology infrastructure at one or more VCCS organizations (college/agency) from external and internal threats while supporting the overall VCCS Information Security Program.

The position serves as the Information Security Officer for one or more VCCS organizations and assists the college/agency administration in the planning, implementation, management and administration of their information security program.

The position will develop and advise college staff on security measures to safeguard information against accidental or unauthorized modification, destruction, or disclosure; address issues and matters specific to information security and their impact on telecommunications and computing areas such as voice, data, and video; desktops and servers; and general computing applications and services; provide analyses and reports to college management on the development and implementation of security controls necessary to address information security risks; confer with college/agency management, technical staff, system/data owners, auditors, security officers, and other personnel to plan and implement the college/agency information security program as outlined in the VCCS Memorandum of Understanding for Information Security Shared Services (ISSS).
Minimum Qualifications:


Required:
Ability to meet the requirements to obtain and maintain the VCCS ISO certification as outlined below:A. Graduation from an accredited Cybersecurity Degree program; orB. Has obtained and maintained any advanced information security certification listed below:• ISACA Certified Information Systems Auditor (CISA)• ISACA Certified Information Systems Manager (CISM)• ISACA Certified in Risk and Information Systems Control (CRISC)• ISC2 Certified Information Systems Security Professional (CISSP)• ISC2 Governance, Risk and Compliance Certification (CGRC)• GIAC Security Leadership (GSLC)• GIAC Information Security Professional Certification (GISP); orC. Previously met all requirements for the Commonwealth Certified Information Security Officer position with another Commonwealth of Virginia agency; orD. Served in the role of Information Security Officer for a minimum of five years.

KSA's:
Comprehensive knowledge:
• Information security program development and management to include: risk identification and mitigation, security architecture, and compliance.
• Current trends and advancements in IT systems and enterprise wide security
• Implementation experience with commonly accepted industry standards and best practices, including ISO 27000, NIST publications, ISF Best Practices, etc.
• Some experience with current legal and regulatory requirements around information security and privacy, including PCI, SOX, HIPAA, GLBA, etc
• Demonstrated knowledge of IT Security and IT Audit concepts and techniques
• Comprehensive knowledge of VCCS and Virginia’s security standards
Considerable knowledge:
• Significant understanding and management capability related to the effective planning, implementation and maintenance of a highly technical and complex information technology infrastructure.
• Current trends and advancements in the security industry.
• Creating documentation (White papers, models, guidelines, user guides, procedures, test plans, implementation plans, etc.).
• Security and networking hardware and software evaluation.
Working knowledge:
• Internet, Intranet, Extranet, and Remote Access network design Standards and protocols.
• Directory Services Security automation
• Web services Implementation and SSL security
• ERP Applications (preferably Oracle/PeopleSoft).
Considerable skill:
• In all the items listed under comprehensive and considerable knowledge.
Working skill:
• In all the items listed under working knowledge.
Ability:
• To learn new things and to apply them when and where appropriate.
• Outstanding oral/written communication.
• Detail-oriented.
• To work on multiple tasks simultaneously.
• To apply general work experience to a task.
• To work independently or as part of a team.
• To work in stressful situations.
• To use logic to resolve complex problems.
• To communicate and work well with everyone from the highest levels of technical Management to staff level.
• Ability to understand a technical environment, and plan accordingly.
• To find creative solutions to problems.
• To analyze user needs and solve problems.
• To be a self-starter and work independently.
• To use logic to resolve complex problems.
• Coordinate work of a team.
• To coordinate multiple projects and priorities.


Additional Considerations:

CISSP, CISM, or other security certification/accreditation desirable.

Related Jobs

View all jobs

Information Security Officer

Information Security Officer

Information Security Officer (Bristol or Sheffield)

Information Security Officer (Bristol or Sheffield)

Information Security & Compliance Officer

Chief Information Security Officer

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

10 Cyber Security Recruitment Agencies in the UK You Should Know (2025 Job‑Seeker Guide)

UK cyber security hiring remains resilient in 2025, driven by nation-state threats, cloud security investments, and NCSC regulatory pressures. Lightcast reports +42 % YoY growth in UK roles mentioning “SOC”, “cyber risk”, “offensive security” or “GRC”. Yet despite 30,000 active cyber professionals, monthly live vacancies remain in the 2,500–2,900 range. The result: strong demand across public and private sector. We reviewed 50 + consultancies and included only those that: Are registered in the UK (Companies House) Operate a dedicated Cyber Security / InfoSec / Risk & Compliance desk Posted at least 5 UK cyber security roles between March and June 2025 This guide includes 2025 salary ranges, key skills, interview prep tips, and a verified recruiter directory.

Cyber Security Jobs Skills Radar 2026: Emerging Frameworks, Tools & Certifications to Learn Now

Cyber threats are evolving—and so must the people defending against them. As ransomware, AI-enhanced phishing, and supply chain attacks grow more advanced, UK employers are urgently hiring cyber security professionals with the right mix of strategic and hands-on skills. Welcome to the Cyber Security Jobs Skills Radar 2026, your go-to guide for the most in-demand tools, frameworks, certifications, and technologies shaping the UK's cyber workforce. Whether you're a SOC analyst, penetration tester, or cloud security architect, this annual radar is designed to help you stay ahead of the market.

How to Find Hidden Cyber Security Jobs in the UK Using Professional Bodies like BCS, CIISec & More

The demand for skilled cyber security professionals in the UK has never been higher. With threats increasing in sophistication and frequency, organisations are urgently hiring ethical hackers, threat analysts, GRC specialists, and security architects. But many of the most valuable roles—particularly in government, defence, and critical infrastructure—are never publicly advertised. Instead, these jobs are shared behind the scenes through trusted networks, private communities, and professional bodies. In this article, we explore how to uncover hidden cyber security jobs in the UK using organisations like the BCS (The Chartered Institute for IT), CIISec (The Chartered Institute of Information Security), ISACA, and ISC² UK Chapter. We’ll show you how to use membership directories, special interest groups, CPD events and informal networks to gain early access to roles most people never see.