WHAT WILL YOU BRING:
Required Education
Bachelors degree from an accredited college or university in Cybersecurity Information Technology or a closely related field.
High school diploma or equivalent and additional full-time experience in cybersecurity information security systems analysis programming computer operations IT business analysis or related experience may be substituted on an equivalent year-for-year basis.
Required Experience
Must have the ability to maintain the security and integrity of communication infrastructure systems and cybersecurity systems as defined in Section 117.001(2) of the Texas Business and Commerce Code and:
Four (4) years of full-time directly related progressively responsible experience in cybersecurity information security systems analysis programming computer operations IT business analysis or related experience.
One (1) year of full-time directly related progressively responsible experience developing and training employees on security/privacy policies data handling practices and procedures and legal obligations or related experience.
One (1) year of full-time directly related progressively responsible experience conducting IT audits and needs analysis to improve business process solutions. As well as developing and writing IT policies procedures and audit responses or related experience.
Experience may be concurrent.
A masters degree or doctoral degree in a closely related field may be substituted on an equivalent year-for-year basis.
Required Registration Certification or Licensure
Certification as a Certified Information Systems Security Professional (CISSP) or other security related certifications.
Preferred Qualifications
Experience with risk management frameworks as it pertains to the National Institute of Standards and Technology.
Experience with various security monitoring tools network and web assessment tools and automation techniques.
Basic development or scripting experience and skills. (.Net Python and Java are preferred.)
Experience with identifying security issues through code review.
GIAC 500 series or higher certifications OSCP or other security related certifications.
Knowledge Skills and Abilities
Knowledge of:
Computer systems and technology limitations capabilities and security infrastructures.
Information security systems controls methodologies practices and regulations including data encryption and information protection.
National and international laws regulations policies along with ethics as they relate to cybersecurity/privacy.
Organizations risk tolerance and/or risk management approach.
Applicable state and federal laws statutes Presidential Directives executive branch guidelines related to information security or cyber security.
Common security flaws and ways to address them (e.g. OWASP Top 10 CIS Top 18).
Current and emerging cyber technologies.
Agile methodology.
Common code repository and continuous delivery tools.
Skills in:
Analyzing complex technical problems and developing workable solutions
Managing multiple conflicting tasks/deadlines.
Effective verbal and written communication of complex technical information.
Ability to:
Effectively assess areas of risk associated with information security.
Determine the validity of technology trend data.
Develop policy plans and strategies in compliance with laws regulations policies and standards in support of organizational information security assurance.
Establish and maintain harmonious working relationships with co-workers agency staff and external contacts.
Work effectively in a professional team environment.