- Company Name
- United States Courts
- Job Title
- IT Security Officer: Risk, Policy & Incident Lead
- Job Description
-
Job Title: IT Security Officer – Risk, Policy & Incident Lead
Role Summary:
Responsible for maintaining and enhancing the operational security posture of the court’s IT environment. Manages security policy implementation, conducts risk assessments, oversees vulnerability management, monitors compliance, coordinates incident responses, and drives security awareness initiatives. Works collaboratively with the Administrative Office IT Security Office and other ITO management to align policies, manage risks, and ensure national security standards are met.
Expectations:
- Lead and execute strategic security initiatives that protect court information assets.
- Serve as the primary IT security advisor for court leadership and external stakeholders.
- Ensure timely and effective incident response and reporting.
- Maintain compliance with federal security regulations and national policies.
- Promote a culture of security awareness among all staff.
Key Responsibilities:
- Develop, document, and enforce IT security policies, standards, and procedures.
- Perform risk assessments and vulnerability analyses; recommend mitigations.
- Manage vulnerability scanning, patch management, and remediation workflows.
- Monitor compliance with security frameworks (e.g., NIST, ISO 27001, federal guidelines).
- Coordinate incident detection, containment, investigation, and reporting; lead incident response teams.
- Provide security awareness training and communications to court personnel.
- Collaborate with ITO managers for policy updates, security strategy, and resource allocation.
- Liaise with the Administrative Office IT Security Office on national policy implementation and shared initiatives.
- Present security posture, metrics, and recommendations to executive leadership.
Required Skills:
- Strong knowledge of IT security frameworks (NIST, ISO 27001, FedRAMP, etc.).
- Experience with risk assessment, vulnerability management, and incident response.
- Ability to develop and enforce security policies and procedures.
- Proficiency in security monitoring, threat detection, and incident investigation tools.
- Excellent communication, presentation, and stakeholder management skills.
- Analytical and problem‑solving abilities, with attention to detail.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent professional experience).
- Relevant security certifications such as CISSP, CISM, or equivalent.
Washington dc, United states
On site
Senior
27-01-2026