Technology Engineer – Senior (1043) - Security Specialty - Citywide (C00096)
About the role
This position serves as the senior technical contributor for systems or platforms, performing a wide range of complex analytical, design, planning, implementation, enhancement, and problem resolution tasks. The incumbent works within a framework of established procedures and interprets policies, procedures, and guidelines.
Responsibilities
- Architects, designs, implements, maintains and operates information system security and privacy controls and countermeasures.
- Analyzes and recommends security and privacy controls and procedures in acquisition, development, and change management lifecycle of information systems, and monitors for compliance.
- Analyzes and recommends security and privacy controls and procedures in business processes related to use of information systems and assets, and monitors for compliance.
- Maintains information systems for security incidents, vulnerabilities and privacy risks; develops monitoring and visibility capabilities; reports on incidents, vulnerabilities and trends.
- Responds to information system security and privacy incidents, including investigation of, countermeasures to and recovery from computer-based attacks, unauthorized access and policy breaches; interacts and coordinates with third-party incident responders, including law enforcement.
- Administers authentication and access controls, including provisioning, changes and deprovisioning of user and system accounts, security/access roles and access permissions to information assets.
- Analyses trends, news and changes in threat, compliance, and privacy regulatory environment with respect to organizational risk; advises organization management and develops and executes plans for compliance and mitigation of risk; performs risk and compliance self-assessments and engages and coordinates third-party risk and compliance assessments.
- Develops and administers, or provides advice, evaluation and oversight for, information security and privacy training and awareness programs.
Requirements
The position requires a combination of education and experience. An associate degree in computer science, computer engineering, information systems, or a closely-related field is preferred, along with three (3) years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of a system or platform. Alternatively, one year of additional experience may be substituted for the required degree.
Qualifications
To qualify, applicants must possess and maintain the qualifications required by law and by the examination announcement for the examination. Failure to obtain and maintain security clearance may be basis for termination from employment with the Airport Commission. Additionally, candidates must be insurable under the Port's automobile liability insurance policy and must be able to obtain a Transportation Worker Identification Credential (TWIC) certificate as a condition of employment.
Skills
Knowledge of security operations including concepts, investigations and incident management, security engineering, communication and network security, asset security operations, identity and access management including controlling access and managing identity, mobile security including managing and securing mobile devices and software, and security assessment and testing are essential.
Benefits
N/A
Pay
N/A
Schedule
N/A