Position Description |
An Information Security Specialist interprets information security policies, standards and other requirements as they relate to internal information system and coordinates the implementation of these and other information security requirements. The Information Security Specialist redesigns and reengineers internal information handling processes so that information is appropriately protected from a wide variety of problems including unauthorized disclosure, unauthorized use, inappropriate modification, premature deletion, and unavailability. The Information Security Specialist will provide highly specialized experience in one or more information, computer, or network security disciplines (e.g. penetration testing, accreditation, or risk assessment and mitigation); develop system security plans, certification and accreditation reviews; analyze and establish processes for comprehensive systems and data protection; assess and mitigate system security threats and risks; perform security audits, evaluation, risk assessments and make a strategic recommendations; and manages, supports, installs and maintains security tools and systems, and tracks security patches and incidents. |
|
Skills Required |
The Information Security Specialist will possess knowledge and experience in standard methodologies used in certification and accreditation processes; extensive experience following NIST guidelines in risk assessment and management; conducting vulnerability analysis; developing mitigation plans; and performing penetration testing, password protection testing and application security testing. |
|
Skills Preferred |
– Excellent customer service, interpersonal, verbal, and written communication skills. – Working knowledge managing Pulse Secure Access, or similar, environment including, but not limited to, the configuration of all resource profiles and policies, user realms and roles, sign-in pages and policies, access policy, and delegated administration privileges. – Working knowledge managing and supporting Zscaler Private Access multi-tenancy, or similar, environment that supports 2000 or more users. – Working knowledge and experience managing and supporting Zscaler Internet Access technology in high availability environments supporting more than 2000 users. |
|
Experience Required |
This classification must have a minimum of five (5) years of experience applying security policies, standards, testing, modification and implementation. At least three (3) years of that experience must be in information security analysis. |
|
Experience Preferred |
– Two (2) years of experience within the last three (3) years designing, implementing, upgrading, and troubleshooting VPN technologies including Zscaler Private Access AND Pulse Secure SSL VPN, or similar, in multi-tenancy and high availability environments. – Two (2) years of experience within the last three (3) years designing, implementing, upgrading, and troubleshooting Zscaler Internet Access in the enterprise environment that supports 2000 or more users. – Three (3) years of experience within the last five (5) years as an Information Security Specialist, or similar, supporting an enterprise network environment with at least 50 servers, 2,000 or more users and multiple firewalls, switches, and routers. |
|
Education Required |
This classification requires the possession of a bachelor’s degree in an IT-related or Engineering field. Additional qualifying experience may be substituted for the required education on a year-for-year basis. |
|
Education Preferred |
Security trainings and certifications such as ZCCA-IA, ZCCP-IA, ZCCA-PA, ZCCP-PA, Certified in Cybersecurity (CC) or CISSP. |