Information Security Officer (ISO) in Richmond, VA
Richmond, VA - USA
Job Summary
What success looks like in this role:
Position Summary
The Unisys Information Security Officer (ISO) provides dedicated cybersecurity leadership in support of the client. This role is responsible for helping the client implement manage and govern information security programs that protect the information systems services and data.
The Unisys ISO works closely with the Unisys account management team and delivery teams to ensure Unisys services meet the clients security standards. The Unisys ISO is the functional lead for a team of security professionals providing technical guidance and support in the context of delivering the services. The Unisys ISO is the key contact point for the clients CISO team agency leadership and stakeholders across the Commonwealth to ensure statewide compliance with IT security standards perform risk assessments support incident response and deliver strategic security guidance.
1. Security Delivery Lead for Unisys services
- Main liaison for Unisys account management for cybersecurity and compliance matters
- Service Delivery Manager for cybersecurity services and solutions provided to the client
- Technical lead for cybersecurity professionals in a matrixed organization
- Provide updates for Unisys leadership related to cybersecurity delivery
- Serve as the escalation point for internal Unisys cybersecurity issues affecting the client.
2. Security Governance & Compliance
- Support Unisys delivery teams by meeting compliance expectations with Commonwealth of Virginia (COV) security standards (SEC 501 SEC 525 SEC 527 SEC 530).
- Develop refine and maintain agency-aligned security policies controls and documentation.
- Assist the client and assigned agencies with audits compliance reviews and remediation planning in accordance with Unisys contractual obligations.
- Ensure adoption of NIST-aligned risk management and security control frameworks.
3. Risk Management
- Conduct or assist with enterprise risk assessments data classification and security control evaluations for the client and supported agencies.
- Identify security gaps and recommend risk-based remediation strategies.
- Support the development of System Security Plans (SSPs) Business Impact Assessments (BIAs) and agency risk registers.
- Provide guidance on Continuity of Operations Plan (COOP) and Incident Response Plan development.
4. Incident Response & Threat Support
- Act as an incident response resource to the client helping coordinate cybersecurity investigations analysis and documentation.
- Collaborate with the clients SOC the Virginia Fusion Center and agency staff during active events.
- Deliver after-action reporting root cause analysis and improvement recommendations.
5. Security Architecture & Technology Support
- Assist the client in evaluating IT solutions cloud services and enterprise initiatives for security compliance.
- Review designs contracts and procurements to ensure required security controls are incorporated.
- Provide recommendations aligned with Zero Trust identity management best practices encryption logging and network security principles.
6. Training Awareness & Stakeholder Coordination
- Support cybersecurity awareness programs across the client and partner agencies.
- Act as one of the primary Unisys security liaisons connecting with leadership.
- Communicate risks emerging threats and mitigation options to technical and non-technical audiences.
- Offer security guidance to project teams application developers and business units.
7. Strategic Security Leadership
- Contribute to enterprise cybersecurity strategy and statewide security initiatives.
- Recommend modern tools frameworks and processes to enhance the Commonwealths security posture.
- Take part in governance boards working groups and cross-agency cybersecurity committees.
- Support Unisys in delivering high-quality contract-aligned services that enhance VITAs mission.
You will be successful in this role if you have:
- Bachelors degree in information security Computer Science IT or related field; equivalent experience considered.
- 10 years of cybersecurity or information assurance experience.
- Strong understanding of:
- NIST frameworks (CSF)
- Commonwealth of Virginia security standards (SEC 501 SEC 525 SEC 530)
- Zero Trust principles and modern security architecture
- Experience in risk assessments audits and implementing security controls.
- Incident response or SOC coordination experience.
- Excellent communication documentation and stakeholder-engagement skills.
- Experience with applying AI in support of delivery and to meet contractual obligations
Must Have Certifications:
- CISSP
Preferred Certifications:
- CISM
- CISA
- CRISC
- GIAC certifications (GSEC GCIH GSTRT etc.)
- Cloud security certifications (AWS / Azure)
Key Competencies
- Ability to work collaboratively across multiple agencies and stakeholder groups
- Strong analytical and risk-based decision-making skills
- Ability to communicate complex security issues clearly
- High initiative ownership and professionalism
- Commitment to delivering high-quality support to a mission-critical state client
Onsite position with the possibility to work 1-2 days per week remotely.
This role may require access to export-controlled commodities and technology. Therefore to conform to U.S. export control regulations applicant should be eligible for any required authorizations from the U.S. Government.
Unisys is proud to be an equal opportunity employer that considers all qualified applicants without regard to age caste citizenship color disability family medical history family status ethnicity gender gender expression gender identity genetic information marital status national origin parental status pregnancy race religion sex sexual orientation transgender status veteran status or any other category protected by law.
This commitment includes our efforts to provide for all those who seek to express interest in employment the opportunity to participate without barriers. If you are a US job seeker unable to review the job opportunities herein or cannot otherwise complete your expression of interest without additional assistance and would like to discuss a request for reasonable accommodation please contact our Global Recruiting organization at or alternatively Toll Free: (Prompt 4). US job seekers can find more information about Unisys EEO commitment here.
Required Experience:
Unclear Seniority
About Company
Unisys is a global information technology company that specializes in providing industry-focused solutions integrated with leading-edge security to clients in the government, financial services and commercial markets. Unisys offerings include security solutions, advanced data analytic ... View more