-
Description
-
OPEN RECRUITMENT Executive Service (This position serves at the pleasure of the Appointing Authority) If you have ever taken a flight from BWI Thurgood Marshall Airport; renewed your Maryland driver's license; traveled to an Orioles game on the Light Rail; embarked on a cruise from the Port of Baltimore; received roadside assistance from CHART Emergency Patrol; reduced your commute time by using one of Maryland's toll roads then you have experienced some of the superb services provided by the Maryland Department of Transportation (MDOT). MDOT has various careers for people of all experiences, backgrounds, and abilities who come together to contribute to one mission-connecting our customers to life's opportunities. Join us in serving our Maryland residents, visitors, and businesses! The Maryland Department of Transportation, The Secretary's Office (MDOT TSO), is seeking a (DCIO) Chief Risk & Information Security Compliance Officer (CRISCO) (DOT Executive VIII) to serve as the enterprise executive responsible for cybersecurity, risk management, regulatory compliance, and information governance across all MDOT modes. This role is critical to ensuring that MDOT's technology environment remains secure, compliant, resilient, and aligned with the Department's mission and public service obligations. The CRISCO functions as a principal advisor to the Chief Information Officer and operates at the executive level as a peer to senior IT leadership. This position provides enterprise-wide authority to establish risk tolerance, enforce compliance standards, and oversee cybersecurity outcomes across MDOT's federated operating model. The CRISCO leads the integration of cybersecurity, enterprise risk management, audit, and compliance into a unified framework that supports modernization, protects critical infrastructure, and maintains public trust. The incumbent provides executive leadership over MDOT's cybersecurity program, including direct oversight of the Deputy Chief Information Security Officer and associated teams responsible for security operations, engineering, and incident response. This position ensures that cybersecurity capabilities are aligned with enterprise risk tolerance, regulatory requirements, and operational priorities. In this dynamic role, you will:
- Establish and enforce enterprise-wide cybersecurity, risk management, and compliance strategy across all MDOT systems, data, and infrastructure. Defines risk tolerance and mandates corrective action across modes.
- Provide executive leadership and full accountability for MDOT's enterprise cybersecurity program, including oversight of security operations, engineering, architecture, and incident response functions.
- Direct and enforce compliance with State and Federal regulations, policies, and standards. Leads enterprise audit strategy, including audit readiness, response, and remediation enforcement.
- Design and implement an enterprise risk management framework integrating cybersecurity, operational, data, and third-party risk into a unified governance model.
- Exercise governance authority across MDOT's federated IT environment to ensure consistent adherence to enterprise standards and eliminate fragmented or duplicative implementations.
- Serve as executive authority during major cybersecurity or data incidents, ensuring coordinated response across MDOT modes and external agencies, and enforcing post-incident corrective actions.
The current vacancy exists at MDOT TSO in the Office of Transportation Technology Services (OTTS), which is located in Hanover, MD. (Anne Arundel County). This position may require travel between MDOT facilities and coordination with State and Federal agencies, and may also require after-hours availability during cybersecurity incidents, emergency operations, major outages, or critical operational events. This position may allow a hybrid work schedule, including telework and on-site work hours. MDOT offers a generous and competitive benefits package. You can learn about our amazing benefits here: MDOT Benefits
-
Qualifications
-
PREFERRED QUALIFICATIONS: Education:A bachelor's degree from an accredited college or university in Information Technology, Cybersecurity, Risk Management, Business Administration, Public Policy, or a closely related field. Experience: Ten (10) years of progressive experience in enterprise risk management, cybersecurity, compliance, or governance within large, complex organizations. Five (5) years must include executive or senior management roles with responsibility for enterprise-level decision making, policy development, and organizational oversight. *Experience in government or regulated industries preferred. The ideal candidate will possess:
- Master's degree in Information Systems, Business Administration, Public Policy, or related field.
- Experience leading enterprise risk management, compliance, or governance programs at scale.
- Experience overseeing cybersecurity functions while operating at a strategic, policy, and executive level
- Strong understanding of regulatory frameworks, audit processes, and compliance enforcement.
- Experience working in public sector, transportation, or other critical infrastructure environments.
- Ability to operate independently with executive presence and sound judgment in high-impact decision making environments.
Consideration for employment may be based solely on the contents of your application; therefore, it is essential that you provide complete and accurate information. Please include all relevant experience on your application. This includes, but is not limited to, full or part-time, volunteer, military, acting capacity, or any other experience that is relevant to the position you are applying for. If you have held more than one position at the same employer, please list each position that you held and the length of time that you held each position. Note: U.S. Armed Forces military service experience as defined under the Minimum Qualifications may be substituted for the required education and experience on a year-for-year basis.
-
Licenses & Certifications
-
None.
-
Additional Information
-
TO APPLY: You must complete an MDOT employment application (DTS-1) online to be considered for this recruitment. RESUMES CANNOT BE SUBSTITUTED FOR THE MDOT EMPLOYMENT APPLICATION. No paper applications will be accepted. The application must be complete at the time of submission and must clearly describe the required work experience. Dates (month and year) must be stated. Vague descriptions of experience will not be considered. Please include all relevant experience on your application. Description of duties that state, "see resume" will negatively impact consideration for this position. Applicants will not be contacted for additional information. Only applicants considered for this position will be contacted. Selected candidates may be subject to background and reference checks. You may apply online at: https://www.governmentjobs.com/careers/mdotmd. Applications must be submitted online by 11:59 pm on 5/27/2026. Appropriate auxiliary aids and services for qualified individuals with disabilities will be provided upon request. Please notify in advance. MD Relay Service Number (711). Bilingual applicants are encouraged to apply. The Maryland Department of Transportation is not sponsoring new employees in application of the H- 1B Visa or providing an extension of an existing H-1B at this time due to budgetary constraints. All applicants must be legally authorized to work in the United States under the Immigration Reform and Control Act of 1986. Federal regulations prohibit H-1B Visa candidates from paying sponsorship fees; all sponsorship fees must be assumed by the potential employer. Applicants who have education obtained outside of the U.S. will be required to provide proof of the equivalent U.S. education as determined by a foreign credential evaluation service, such as the National Association of Credential Evaluation Services (http://www.naces.org) or World Education Services: International Credential Evaluation (https://www.wes.org/). The incumbent in this position will not be a member of a covered bargaining unit. WE ARE AN EQUAL OPPORTUNITY EMPLOYER. MDOT does not discriminate based on age, ancestry, color, creed, gender identity or expression, genetic information, marital status, mental or physical disability, national origin, race, religious affiliation, belief or opinion, sex, or sexual orientation. Issued Date: 5/13/2026 The purpose of the supplemental questions listed below is to evaluate your experience and education further to determine your eligibility for this job classification. Answer each question accurately and thoroughly. The experience you indicate in your responses to the supplemental questions must also be described in detail in the Work History section of this application. If you cite experience in your response that is not included in the Work History section of this application, your application may be considered incomplete, and you may not receive further consideration for this position. Questions with text answers require you to include the name of the employer/organization and dates of the specific experience.
|