What are the responsibilities and job description for the Information Technology Security Officer position at City of Carson?
Job Summary :
The purpose of this classification is to ensure the security operation of the City’s data, computer systems, servers, and network connections. Employees in this classification are responsible for developing, planning, organizing, managing, implementing, maintaining, and performing cybersecurity risk analysis of systems; scrutinizing network traffic; establishing vulnerability scans; checking server and firewall logs; conducting user activity audits, and troubleshooting, as well as also analyzing and resolving security breaches and vulnerability issues in a timely and efficient manner. This position will assist with developing IT security policies. Work is performed under general direction of the Director of Information and Technology with considerable latitude for the use of initiative and independent judgment.
Essential Duties and Responsibilities :
- Plans, organizes, manages, and participates in the development, implementation, and monitoring of the City’s information security programs, information technology risk management programs, and information security policies; supervises and reviews the work of professionals and serves as a subject matter expert in information security.
- Develops and executes a cyber security strategy that is aligned with internal stakeholders, organizational priorities, facilitates city operations, and meets industry standards.
- Directs and participates in the identification of security risks, development and implementation of security management practices, and the measurement and monitoring of security protection measures.
- Ensures compliance with regulatory requirements such as Criminal Justice Information Services (CJIS), Payment Card Industry Data Security Standards (PCI), Health Insurance Portability and Accountability Act (HIPAA), California Privacy Protection Agency, and federal, state, and local laws.
- Monitors agency infrastructure, devices, and information systems for security integrity; provides planning and guidance to information technology staff on vulnerability management and security incident response procedures.
- Oversees portfolio of cyber risk and security applications and procedures, implements new security processes and related technologies to ensure a continuous improvement of the City’s cyber security posture.
- Oversees assigned staff in performing their responsibilities and provides guidance as necessary.
- Analyzes information, situations, problems, policies, and procedures to identify, recommend, and implement solutions systemically.
- Formulates, recommends, and executes enterprise-wide policies and procedures for detecting, deterring, and mitigating information security threats.
- Serves as a subject matter expert and internal consultant on data security implications for proposed information technology projects and programs and makes recommendations to align new technologies to security standards.
- Prepares oral and written reports for executive leadership, the City Manager’s Office, and City Council.
- Develops cyber security, cyber risk, and security awareness training programs for City staff; monitors training effectiveness by documenting and reporting data point trends on user awareness and vulnerability assessments.
- Builds and maintains positive relationships with City stakeholders.
- Attends City / Industry-related functions.
- Performs other duties as required.
Qualification Guidelines :
A typical way to obtain the requisite qualifications to perform the duties of this class is as follows :
Education and / or Experience :
All potential applicants are encouraged to scroll through and read the complete job description before applying.
Option A :
Bachelor's degree in Business Administration, Computer Information Systems, Information Technology or closely related field from an accredited college or university and five (5) years of paid experience performing IT security management; and at least two (2) years in an administrative or management capacity responsible for cyber security risk assessment, implementation of security management practices, monitoring of security protection measures, managing SIEM, vulnerability management, and other security tools in an enterprise environment.
Option B :
Master's degree in Computer Science or closely related field is highly desirable from an accredited college or university and four (4) years of paid experience performing IT security management; and at least two (2) years in an administrative or management capacity responsible for cyber security risk assessment, implementation of security management practices, monitoring of security protection measures, managing SIEM, vulnerability management, and other security tools in an enterprise environment.
Knowledge of :
Skills and / or Ability to :
License and / or Certificate :
Possession of a valid California Class C driver's license. Employees in this classification will be enrolled in the Department of Motor Vehicles (DMV) Government Employer Pull Notice Program which confirms possession of a valid driver's license and reflects driving record.
Possession of at least one of the following certifications is required :
Certification as a Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Global Information Assurance Certification (GIAC), Certified Ethical Hacker (CEH), Computer Hacking Forensic Investigator (CHFI), Certified Information Security Manager (CISM), Certified Risk and Information Systems Control (CRISC), or equivalent information security certification.
Physical Requirements and Working Conditions :
Employee accommodation(s) for physical or mental disabilities will be considered on a case-by-case basis. Positions in this class normally :
RECRUITMENT PROCESS
Applications will be screened and evaluated for relevant training and experience. Applications must be complete, and include any and all required documents. Only those applicants determined to be among the most qualified may be invited to participate in the recruitment process, which will consist of the following sections :
The Human Resources Department reserves the right to adjust, modify, delete and / or change the above exam types and / or weights. Supplemental questionnaires are used to evaluate applicant’s indicated abilities with the ideal candidate profile. Applicants must achieve a cut-off score of 70% or above on written, performance and oral exams to be placed on the eligibility list. Passing any / all of the examination sections does not guarantee an invitation to the selection interview. The Human Resources Department reserves the right to invite those amongst the highest scoring to the next phase of the recruitment.
Revisions to a testing component during a recruitment process can be made at the discretion of the Human Resources Department. Applicants will be notified by email if a revision is made. An eligibility list will be established in accordance with the City's Personnel Rules, Rule VI, Employment List Procedures.
OTHER INFORMATION :
The City of Carson is an Equal Opportunity Employer. Special assistance with the application and examination process is available, upon request, for persons with disabilities. Call Human Resources for assistance at (310) 952-1736.
APPOINTMENT :
Any offer of employment, or acceptance of an employment offer, is contingent upon passing live scan, background check and other tests. All new employees are required to take a loyalty oath.
The provisions of this bulletin do not constitute an expressed or implied contract. Any provisions contained herein may be modified or revoked without notice. All statements made on the job application are subject to investigation and / or verification. Inaccurate and / or false statements will be cause for disqualification, removal from the eligibility list or discharge from employment.
IMPORTANT NOTICE : THIS POSITION IS OPEN
CURRENT CITY OF CARSON EMPLOYEES :
Please do not use your City of Carson email address as part of this application. You must indicate a personal email address in order to receive communications and / or notices from Human Resources throughout the recruitment process.
J-18808-Ljbffr