IT Security Analyst (CYFD/ITD #10118952)
Role details
Job location
Tech stack
Job description
This position exists to support CYFD's implementation and ongoing compliance with SB42 by ensuring the security, protection, retention, and governance of electronic records and information systems. The position provides cybersecurity, risk management, compliance, and audit support to help safeguard sensitive agency data and ensure compliance with state and federal requirements. How does it get done?
20% -Lead SB42 cybersecurity compliance activities, including monitoring compliance with electronic records retention, security, governance, and data protection requirements.
15% -Conduct cybersecurity risk assessments, security reviews, compliance evaluations, and third party/vendor security assessments for enterprise systems, cloud services, AI technologies, and applications.
15% -Develop, implement, and maintain cybersecurity policies, standards, procedures, governance documentation, and security controls to support SB42 and regulatory compliance.
15% -Administer, monitor, and optimize enterprise security technologies, including next generation firewalls, web filtering, intrusion prevention systems (IPS), VPNs, and network security controls to protect CYFD systems and data.
10%- Support security operations by monitoring security events, investigating alerts, coordinating incident response activities, vulnerability management, and remediation efforts.
10% -Coordinate audit readiness activities, compliance reporting, evidence collection, corrective action plans, and collaboration with DoIT, Legal, Privacy, Procurement, and internal CYFD stakeholders.
10% -Support identity and access management, security architecture reviews, secure configuration standards, and implementation of technical security controls across the enterprise.
5% -Promote cybersecurity awareness, governance initiatives, security metrics, and continuous improvement efforts to strengthen CYFD's overall security posture. Minimum Qualification
Requirements
Bachelor's degree in Computer Science, Management Information Systems (MIS), Information Technology, Engineering, or similar technical degree and two (2) years of experience in IT security or compliance validation (e.g., HIPAA, PCI). Any combination of education from an accredited college or university in a related field and/or direct experience in this occupation totaling six (6) years may substitute for the required education and experience. A certificate in IT security/forensics (e.g., CISSP, CEH, CCFP, CCSP, HCISPP, SSCP) or regulated compliance (e.g., PCIP, ASV, ISA, QSA) can be used to substitute one (1) year of experience. Employment Requirements
Must possess and maintain a valid Driver's License. Pre-employment background investigation is required and is conditional pending results. Working Conditions
Work is performed in an office setting with exposure to Visual/Video Display Terminal (VDT) and extensive phone and personal computer usage. Direct client interaction and some travel may be required. Supplemental Information