Responsibilities
- Perform a detailed security assessment and establish the current baseline.
- Create an information security improvement plan and implement the plan by closely collaborating with other internal IT teams.
- Create and maintain information security score card.
- Establish Information Security and Risk Management programs.
- Developing, implementing and maintaining DES information security enterprise standards, processes, procedures, regulations, and guidelines based on federal and state laws and mandates (e.g. NIST 800-53, IRS Publication 1075, FedRAMP, etc.).
- Conducts system configuration and operations audits of discrete applications, network, and computing resources to identify potential vulnerabilities (e.g. Port Scans, Intrusion Detection and Prevention, Network Scans and Perimeter Security).
- Provides leadership and guidance in information security and enterprise risks to business owners and agency staff.
Requirements
- Demonstrated work experience developing and implementing Information Security and Enterprise Risk management programs.
- Experience developing, implementing and maintaining information security standards, processes, procedures, regulations, & guidelines
- Experience developing and implementing security improvement plans with effective results that are tracked and reported
- Experience configuring, implementing and managing all the various information security solutions
- Knowledge of the latest cyber security frameworks, principles, application threats/vulnerabilities, and secure coding practices
- Knowledge of cloud security best practices in the areas of Services, Infrastructure (IaaS), Platform (PaaS), and/or Software (SaaS).
Nice to Have
- Experience in the areas of NIST Risk Management Framework, IRS Publication 1075, FedRamp, Cloud Hosting, and FIPS
- Experience in the areas of Siem and Identity Management (IDM) solution implementations
- Ability to work with IT staff to transition knowledge as requested