Jobs · Pennsylvania

Operational Technology Security Engineer

CyberJobs.Com · Harrisburg, PA · 2 days ago
$153k/yrFull-time

PHEAA is a nonprofit student aid organization dedicated to providing affordable access to higher education. Join us to give back!

Job Purpose And Summary

This role is responsible for planning, developing, and operating reliable information security and privacy programs that support the integrity and availability of digital information, safeguard the Agency’s digital assets, and implement effective and appropriately scaled security and privacy policies, practices, and technologies.

Develop relationships with all levels of the organization to implement appropriate security and privacy standards and procedures. This position is responsible for monitoring compliance with the legislated requirements that impact information security and privacy for PHEAA in its roles as an independent state agency and a commercial enterprise.

Primary Duties And Responsibilities

  • Security Leadership:

    • Build an enterprise-wide cybersecurity culture that improves security awareness and instills a risk-aware culture in the Agency.
    • Develop, manage, and set the vision, goals, and priorities for information security at PHEAA.
    • Advise and report to Agency executive leadership and Board as may be required or requested on current Agency cybersecurity strategy and cybersecurity risk.
    • Lead initiatives related to Information Security strategic planning.
    • Provide strategic oversight for the security execution of enterprise projects, initiatives, and organizational changes, ensuring effective leadership and alignment across security managers, team leads, and staff.
    • Drive and oversee execution of security projects and initiatives, empowering security managers, team leads, and staff.
    • Set and manage the budget for the Enterprise Security Office.

  • Information Security and Privacy Management:

    • Consult with business and Information Technology stakeholders to understand their business and technical plans and formulate an Information Security plan that allows the Agency to achieve its goals.
    • Define Information Security metrics and report them regularly as required by Agency processes.
    • Stay current on emerging technology, trends, legislation, and threats that impact the Agency’s information security posture.
    • Lead the development and maintenance of the Agency’s strategic cyber-security roadmap.
    • Oversee the development, implementation, and management of security strategy processes, along with related architecture and engineering standards.
    • Aid in the review of applications and technology environments during the development and acquisitions process.
    • Translate and interpret technical risks for a broad range of audiences including the Board and Executive Leadership.
    • Define and drive compliance with the Agency’s enterprise security and privacy policies and standards, and ensure the related controls are in place and operating effectively.

  • Security Risk Management:

    • Identify protection goals, objectives, and metrics consistent with Agency goals and regulatory requirements.
    • Collaborate with stakeholders to gain alignment on the determination of acceptable levels of risk.
    • Prioritize security initiatives and spending aligned with overall Agency risk management and financial goals.
    • Identify requirements and oversee development of Agency cyber-security training.

  • Staff Management:

    • Responsible for leading the Enterprise Security Office team in fulfilling the mission of the Agency’s information security goals.
    • Develop and enhance employee competence and effectiveness by providing on-going guidance, mentoring, feedback, and motivation to staff.
    • Create a culture that fully engages employees and empowers others to suggest and make decisions for continuous improvement.
    • Responsible for assisting recruiting with attracting key talent.
    • Responsible for employee lifecycle including hiring, providing periodic feedback on performance including writing and delivering annual performance evaluations, promotions, and terminations.
    • Ensure that ESO has the appropriate tools and resources necessary to accomplish their assigned tasks.
    • Identify skill development needs and develop training programs.

  • Incident Response:

    • Provide strategic vision and tactical execution for cybersecurity incident prevention, detection, and response.
    • Oversee incident response planning as well as the investigation of security breaches and assist with disciplinary and legal matters associated with such breaches as necessary.
    • Set the strategy for the continuous monitoring and protection information systems including oversight of the Agency’s Security Operations Center.
    • Evaluate suspected security breaches and recommend corrective actions (including incidents involving outside vendors).
    • Advises Executive Leadership during incidents as part of the Agency’s Critical Incident Management team.

  • Other Duties And Responsibilities:

    • Collaborate with internal and external auditors as appropriate for independent security audits.
    • Support Information Technology goals by providing leadership and guidance as directed over Information Technology roles not traditionally part of the Enterprise Security Office as well as provide strategic architectural guidance on cross-functional solutions.

Qualifications

Required:

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field.
  • Minimum of 5 years of relevant experience in information security, preferably in a government or public sector environment.
  • Experience managing a team of security professionals.
  • Knowledge of industry-standard security protocols and best practices.
  • Ability to communicate complex technical concepts to non-technical stakeholders.

Skills

  • Strong understanding of information security principles and practices.
  • Experience with security risk assessment and management.
  • Excellent communication and interpersonal skills.
  • Ability to work independently and as part of a team.
  • Proficiency in Microsoft Office Suite.

Benefits

Flexible working arrangements, professional development opportunities, competitive salary, and comprehensive benefits package.

Pay

Grade 20, Commensurate with experience starting at $153,222.00

Schedule

Monday through Friday 8:00 AM - 5:00 PM - Hybrid 2 days a week onsite

Similar jobs