Information Technology Enterprise Expert - Information Security Architect
Des Moines, Polk County, Iowa, 50319, USA
Listed on 2026-01-14
-
IT/Tech
Cybersecurity, IT Consultant
Only applicants who meet the Minimum Qualification Requirements and meet all selective requirements (listed below) will be placed on the eligible list.
The Department of Management (DOM), Division of Information Technology (DoIT), is seeking an Information Security Architect to design, implement, and govern the State of Iowa’s enterprise security architecture. This position is critical to safeguarding state systems and data by embedding security into technology solutions, aligning with national standards, and advancing the Iowa Cyber Strategy and Cyber
GUARD framework.
- Develop, implement, and continuously improve the State’s enterprise security architecture framework.
- Define and enforce standards that integrate security controls across systems, platforms, and services.
- Establish scalable technical, administrative, and physical controls to maintain a consistent security posture statewide.
- Serve as the authority for identifying and documenting compensating controls when baseline measures are not feasible.
- Ensure alignment with NIST SP 800-53, Risk Management Framework (RMF), and the Iowa Cyber Strategy.
- Translate compliance and policy requirements into measurable, enforceable security controls.
- Conduct threat modeling using frameworks such as MITRE ATT&CK and the cyber kill chain to inform architecture decisions.
- Enhance visibility and reporting of controls to support audits, assessments, and incident response.
- Collaborate with leadership, agency partners, and technical teams to embed secure design principles.
- Lead enterprise-wide initiatives, including project charters, cost-benefit analyses, and vendor oversight.
- Analyze statewide security trends and report on performance, risk posture, and architecture effectiveness.
- Represent the Chief Information Security Officer (CISO) in interagency committees and strategic planning efforts.
- Promote adoption of Cyber
GUARD standards and secure architecture practices across agencies. - Evaluate emerging technologies and evolving threats to strengthen enterprise security architecture.
- Proven expertise in security architecture and enterprise-level design.
- Experience with NIST and RMF frameworks for secure system implementation.
- Knowledge of threat modeling using MITRE ATT&CK and cyber kill chain methodologies.
- Strong collaboration skills to work across agencies and technical teams.
- Ability to translate policy into actionable controls for compliance and audit readiness.
- Forward-thinking approach to address emerging threats and technologies.
- Preferred certifications: CISSP, CISA, GSEC, or equivalent.
- Flexible work environment
- Iowa Public Employees' Retirement System (IPERS)
- Health, dental, and vision insurance
- Generous vacation, sick leave, and paid holidays
- Life and disability insurance
- Retirement savings options (RIC)
- Flexible Spending Accounts
At the Iowa Department of Management (DOM), we help government agencies across the state perform at their best by managing financial resources, technology, and information. Our mission is rooted in service—we provide efficient, innovative, and strategic solutions that empower agencies to fulfill their goals.
We’re guided by four core values:
- Integrity– We act with honesty and accountability.
- Teamwork– We collaborate to achieve shared success.
- Service– We are committed to excellence in public service.
- Partnership– We build strong relationships to drive results.
This position requires onsite work in Des Moines, IA each week. Employees meeting all expectations of their work responsibilities may request remote work and develop a hybrid/remote schedule collaboratively with their manager.
Please note, candidates for this position must reside in the state of Iowa at the time of starting the role.
Background Check Requirements- After a conditional offer of employment has been made, and as the final step in the hiring process, candidates for this position will be subject to a background investigation, which may include but may not be limited to a verification of a candidate’s education, previous employment/work history, contact of personal references, motor vehicle records,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).