Location: 100% Remote (Eastern or Central Time Zones Preferred) Work Arrangement: Remote. Candidates residing in Maine may be required to report onsite once every two weeks. Employment Type: W2 Contract Compensation: $58-60
Overview
Epitec is seeking an experienced Agency Information Security Officer to support statewide cybersecurity initiatives, enterprise security planning, risk management, and incident response efforts. This role is ideal for a cybersecurity professional who excels at building relationships across technical and business teams while helping organizations strengthen security programs and align with industry best practices.
In this role, you will serve as a trusted security advisor, partnering with leadership, operational stakeholders, and technical teams to advance cybersecurity priorities, improve operational resilience, and support enterprise security initiatives.
Key Responsibilities
Lead cybersecurity coordination efforts across multiple stakeholders and cross-functional teams.
Support security program planning, governance initiatives, and enterprise security operations.
Collaborate with agency leaders, technical teams, and business stakeholders to identify and manage cybersecurity risks.
Assist with incident response coordination, escalation management, communication planning, and operational recovery efforts.
Develop, maintain, and review security plans, procedures, workflows, and program documentation.
Evaluate technical and business environments to identify security gaps and improvement opportunities.
Facilitate collaboration among internal teams, vendors, contractors, and external partners to align cybersecurity objectives.
Support continuous improvement initiatives related to security processes, operational readiness, and program effectiveness.
Promote alignment with NIST guidance and established cybersecurity best practices.
Required Qualifications
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field. Equivalent combinations of education, certifications, training, and experience will be considered.
Minimum of 5 years of experience in cybersecurity, information security, risk management, security governance, compliance, or related disciplines.
Experience supporting or implementing cybersecurity frameworks and standards, including NIST-based practices.
Demonstrated ability to build strong relationships and collaborate across technical, operational, and leadership teams.
Strong communication skills with the ability to explain security risks and recommendations to both technical and non-technical audiences.
Preferred Qualifications
5 to 7 years of experience in leadership-focused information security environments.
Experience with regulatory compliance and policy implementation.
Background in incident response, threat mitigation, or enterprise security operations.
Experience supporting cybersecurity governance, security planning, or risk management programs.