Job DescriptionThe IT Security Governance Officer is responsible for establishing and enforcing information security governance frameworks within a government entity. The role ensures compliance with national cybersecurity regulations, government policies, and international standards, while supporting risk management, audit readiness, and secure delivery of digital government services.
Responsibilities
- * Develop, implement, and maintain government-aligned information security policies, standards, and procedures
- Ensure compliance with national cybersecurity regulations, data protection laws, and government directives
- Align IT security governance with recognized frameworks (ISO 27001, NIST, COBIT, government cybersecurity standards)
- Conduct information security risk assessments and support risk treatment plans
- Monitor compliance with security controls across government systems and entities
- Coordinate internal and external audits, regulatory reviews, and compliance assessments
- Track security risks, exceptions, and remediation actions
- Support governance aspects of cybersecurity incidents, reporting, and post-incident reviews
- Review third-party and vendor security compliance for government contracts
- Ensure data classification, access control, and information handling policies are enforced
- Support cybersecurity awareness and mandatory government training programs
- Prepare governance reports, dashboards, and compliance submissions for senior management
- Collaborate with legal, compliance, IT, and national cybersecurity authorities
QualificationsRequired Skills and Competencies
- * Strong knowledge of government cybersecurity governance and regulatory environments
- Experience with public sector IT policies and compliance frameworks
- Risk management, audit coordination, and compliance monitoring skills
- Strong documentation, reporting, and policy-writing abilities
- Ability to communicate security risks in a non-technical, executive-friendly manner
- High integrity and attention to confidentiality requirements
Qualifications* Bachelor’s degree in information security, IT, Computer Science, or a related field
* 4–7 years of experience in information security governance, risk, or compliance (public sector preferred)
* Professional certifications preferred:
+ CISM
+ CISSP
+ ISO 27001 Lead Implementer / Auditor
+ CRISC
- Knowledge of national cybersecurity policies and government data protection laws