More jobs:
Job Description & How to Apply Below
Utilizing a risk-based approach to manage information security related aspects of HRT’s operations. Assuring compliance with information security, privacy, and industry standards and regulations. Designing, establishing, and maintaining reasonable organizational cyber security and information privacy postures. Implementing the NIST Cybersecurity Framework within the organization to improve cyber resilience. In coordination with key stakeholders, this position communicates, prepares for, and responds to geopolitical, international, and national cyber threats from an Agency perspective.
This role is responsible for ensuring HRT’s systems are secure, are compliant as per established regulatory frameworks, and audited as per established cadence.
Essential Job Functions:
(Duties listed are not intended to be all inclusive nor to limit duties that might reasonably be assigned.) Works with CIO/CTO to define, implement and maintain corporate information and operations technology security policies, procedures, and guidelines based on industry best practices that are compliant with federal and state regulations. Maintaining awareness of new cyber threats, vulnerabilities, and technologies to keep the organization secure.
Conducting risk assessments to identify potential security threats and vulnerabilities. Monitoring network activity to identify signs of intrusion or compromise. Providing technical support for computer networks, including firewalls, operating systems and applications, patch management, and data security best practices. Manage HRT’s security tool suite in including endpoint protection, vulnerability assessment, log aggregation and analysis. Training staff on information security best practices to ensure compliance with company policies.
Conducting audits to ensure security protocols are being followed by staff. Providing training in information security best practices to employees. Working knowledge with industry standards such as HIPAA, ITIL, NIST, SANS, COBIT, OWASP, and ISO. Own the entire IT audit process for SOC & PCI reporting across the enterprise. Responsible for leading vulnerability audits, forensic investigations, and mitigation procedures. Responds immediately to security-related incidents, leads response team, and provides post-event analysis.
Evaluate new cybersecurity threat and IT trends and develop effective security controls. Evaluate potential security breaches, coordinate response, and recommend corrective actions. Monitor compliance with security policies and procedures. Investigate security breaches and incidents. Coordinate incident response activities. Train and educate employees on security awareness. Manage security vendors and service providers. Take proactive role is procurement process from the cyber security perspective.
Manage department budget, take part in annual capital expenditures planning exercises. Manage records created and received in compliance with the Hampton Roads Transit Records Management Policies and Procedures. Performs all other related duties as assigned.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×