Key Responsibilities:
Participates in the design implementation and support of security infrastructure for the Department.
Identifies network and information security risks across the enterprise design engineer implement security solutions to address the risks at an enterprise level.
Works closely with the IT Division and outside vendors to effectively design plan deploy secure and update network projects in the environment.
Effective collaboration with the Office of Information Security OIS and other ITD groups is maintained.
Strategic Plan items pertinent to the Network Security Operations group are completed.
System policies and procedures are created documented and maintained.
Perform network scans and penetration testing. Monitors log analysis and management tools for threats.
Evaluate vulnerability scan results and notify business application and infrastructure teams of vulnerabilities in need of remediation.
Evaluate and participate in agency Azure cloud solution review of network security and general project involvement.
Ensure all daily functions that are required to maintain security applicable systems and applications are documented.
Work with the agencys ISO team and the IT Auditors to review security audit findings and vulnerability scans results. Identify recommended correction activities and course of action once determined communicate with the various stakeholders.
Device configurations are based on best practices.
Relevant documentation is kept up to date.
Coordinating the handling and resolution of incidents related to security.
Required Skills & Experience (7 years each)
| Skills | Years of experience | Rate |
| Strong knowledge and hands-on experience with information systems security and security policies.
|
| /10 |
| Experience with web security gateways network access control endpoint security and perimeter security technologies.
|
| /10 |
| Hands-on experience with firewalls anti-virus anti-malware anti-phishing and authentication systems.
|
| /10 |
| Knowledge and experience with intrusion detection/prevention systems (IDS/IPS) log analysis/management and web content filtering.
|
| /10 |
| Solid understanding of network protocols and authentication/security protocols across all OSI layers (especially TCP/IP).
|
| /10 |
| Ability to identify and mitigate security risks across the enterprise including daily security operations.
|
| /10 |
| Proven experience in administering and ensuring confidentiality integrity and availability of IT systems and information assets.
|
| /10 |
| Strong experience in detecting responding to and remediating security incidents.
|
| /10 |
| Hands-on experience with System Security Plans (SSP) and Risk Assessments (RA) in cybersecurity.
|
| /10 |
| Experience conducting threat analysis vulnerability assessments risk assessments and managing security breach incidents.
|
| /10 |
| Strong knowledge of web technologies and penetration testing tools. |
| /10 |