INTERVIEW= Onsite / Virtual
JOB TYPE= Onsite
Scope of Work/Job Characteristics
The Advanced Information Security Analyst will serve as the principal line of communication for the project team. The duties and responsibilities of this position are as follows:
" Assist with planning, implementing, and tuning the Department's Managed Security Services Provider, Security Information and Events Management (SIEM), and vulnerability management;
" Support NextGen Firewall security tools and maintain the site block list;
" Support and maintain endpoint detection, response, and antivirus software functionality on servers and client systems;
" Monitor Intrusion Detection/Prevention Systems (IDS/IPS) for information security threats and advise or participate in response actions;
" Act as a member of the Computer Security Incident Response Team (CSIRT);
" Support the administration of secure messaging and second-factor authentication capabilities;
" Develop and maintain technical specifications, standards, procedures, and systems documentation;
" Analyze, troubleshoot, and resolve antivirus software issues with minimal impact on users;
" Work independently or as a team member on multiple IT security projects and occasionally as a project leader;
" Work on large, complex security issues or projects that require increased skill in multiple IT functional areas, and may mentor junior staf;
" Research and recommend appropriate technical solutions to meet functional requirements; and
" Provide recommendations for possible process improvements within the Department's information security team.
Required Qualifications
A bachelor's degree from an accredited college or university in Computer Science, Information Systems, or other related fields is required. Relevant experience may be substituted for education on a year-for-year basis when applicable.
The Department requires the following experience, skills, and knowledge for this position:
" A minimum of five (5) years or more of server or network administration experience;
" A minimum of three (3) years or more of information security administration experience in an enterprise environment with 1,000 or more users;
" Knowledge of security issues, techniques, and implications across all existing computer platforms;
" A minimum of three (3) years or more of SIEM experience;
" A minimum of three (3) years or more of vulnerability management experience; and
" Experience maintaining and supporting third-party antivirus applications.
NOTE: In addition to the above list, the selected Candidate must successfully complete a Level II Background Check and Criminal Justice Information Services (CJIS) security awareness training.
4.2. Preferred Qualifications
The Department prefers the Candidate to have the following experience, skills, and/or knowledge for this position:
" A minimum of three (3) years or more of experience administering Splunk or similar SIEM;
" A minimum of one (1) year or more of experience using Microsoft Defender products;
" A minimum of one (1) year or more of experience working with IDS/IPS systems;
" A minimum of one (1) year or more of experience using Office 365 Data Loss Prevention (DLP);
" Preparing status reports and providing management briefings;
" Knowledge of IT standards in a criminal justice environment; and
" Responding to security threats in a criminal justice environment.