FY27: IT Systems Engineer, Information Security and Compliance, Dept Infrastructure/Operations, 8 hrs/12 mos, Ad closes 7/31/26

Montgomery County Public Schools
Rockville, MD, United States
20 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$93,891.0 - $137,093.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Proxy Servers Software as a Service Software Documentation CompTIA Security+ Cyber Security Data as a Services Disaster Recovery Domain Name System (DNS) Infrastructure as a Service (IaaS) Information Security Management Network Security
+8 more
Platform as a Service (PAAS) Software Vulnerability Management Computer Networking Systems Large Language Models Control Structures Firewalls (Computer Science) Information Technology Vulnerability Analysis

Job description

Under direction of the Director of the Department of Cybersecurity and Technology Infrastructure, coordinates, designs, and maintains system-wide information security and compliance initiatives; safeguards enterprise systems and data by defining access privileges, control structures, and resources, as determined by best practices, industry standards, and stakeholder needs; identifies and mitigates system vulnerabilities, violations, and inefficiencies through routine audits; provides status updates on system performance through multiple means; acts on privacy breaches and malware threats. Executes and supports Risk Management Framework (RMF) activities and ensures compliance with Maryland Department of IT processes and documentation standards. Supports enterprise architecture governance by maintaining architecture artifacts, system documentation, and technical configuration diagrams. Lead engineer on network Disaster Recovery solutions, reviewing vendor security reports, and cybersecurity

Requirements

strategies. Effectively communicates with staff and stakeholders, including senior leadership. Physical Demands: Position is required to work at computer workstations for sustained periods of time. Special Requirements: Ability to work extended hours, especially during peak periods and when urgent work requirements exist.

Knowledge Skills Abilities: Thorough knowledge and experience with risk management processes, cybersecurity and privacy policies and procedures, vulnerability and threat management, vulnerability assessment tools and techniques, network security principles and practices. Ability to identify and mitigate network vulnerabilities, as well as communicate best practices to avoid security flaws. Thorough knowledge of disaster recovery and business continuity best practices for critical systems required. Ability to construct high level and detail level network security and disaster recovery diagrams to be shared with management, other departments, and coworkers. Ability to manage multiple complex projects and tasks while paying close attention to details. Thorough knowledge of risk management framework and system risk assessments to prepare school system for state and county audits by documenting the environment and providing guidance to system stakeholders. Strong analytical and problem-solving skills. Skilled in decision making with a track record of exercising good judgment. Must be detail-oriented, highly organized, and an effective communicator. Excellent oral and written communication and human relations skills.

Education Training Experience: Bachelor of Science or Bachelor of Arts degree in Computer Science, Information Technology systems, or related field from an accredited university required. Master?s degree preferred. Five years or more documented professional experience in technology. Proven experience in information system security operation, information system security assessment, system documentation, risk mitigation, vulnerability management, networking systems and/or network security (i.e., DNS, firewalls, proxies), agentless security, and XaaS (e.g., SaaS, IaaS, PaaS, DaaS, FaaS). Experience implementing industry standard information security frameworks, policies and procedures. Experience supporting GRC capabilities such as policy management, security awareness training, third-party risk management, and metrics and reporting. Experience in deploying various solutions to scale GRC processes including but not limited to security questionnaires, risk assessment, evidence collection, and control testing. Experience designing, reviewing, deploying, and auditing AI-powered solutions (including agents) and apply LLMs/NLP to analyze policies, audit findings, and regulatory requirements preferred. Certificate License: Professional certification in one or more of the following: CISSP, CompTIA Security+, CISA preferred.

Benefits & conditions

Job Specific Information: SEIU GRADE 27 The wage range for this position is between $45.14 and $65.91per hour, based on years of service. For information about benefits, please follow the link below. https://drive.google.com/file/d/1nCKtJEqy4w4SLTzmvmVXgE8hPfOBolkb/view

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:14 min

Understanding the basic mechanics of automated web scraping

Vidas Bacevičius Vidas Bacevičius · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter · World Congress 2022

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

2:12 min

Generating a reverse proxy server from proto definitions

Rajiv Ranjan Singh Rajiv Ranjan Singh · Europe 2026 Virtual

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt · LIVE

Videos

See all

Related articles

See all