Cyber Security Specialist
Listed on 2026-09-20
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Every employee of Stockbridge Munsee Community is expected to present themselves in a professional manner to customers as well as other departments. Stockbridge Munsee Community strives to provide a positive team environment where everyone contributes.
GENERAL RESPONSIBILITIES:
The Cyber Security Specialist is responsible for protecting the Stockbridge‑Munsee Community’s information systems, data, and digital services. This role focuses on identity security, vulnerability management, incident response, and continuous security improvement across on-premises and cloud environments. The Specialist supports SMC’s mission by safeguarding sensitive tribal, governmental, health, and financial data while aligning cybersecurity practices with NIST and public‑sector best practices
STANDARD
QUALIFICATIONS:
All employees of Stockbridge Munsee Community must meet the following qualification:
1.Must submit to and pass a pre-employment drug and health screening.
2.Must be at least 18 years of age, unless otherwise stated on job description
3.Must maintain an acceptable departmental attendance record
4.Must be able to work weekends, nights and holidays
DUTIES:
1. Monitor, investigate, and respond to cybersecurity alerts from SIEM, endpoint, email, and cloud security tools.
2. Lead incident response activities, including containment, remediation, documentation, and lessons learned.
3. Coordinate with internal IT teams and trusted external partners during security incidents.
4. Support 24/7 readiness through on‑call escalation when required.
5. Support implementation and enforcement of Multi‑Factor Authentication (MFA) and password less authentication.
6. Monitor authentication activity for anomalous or suspicious behavior.
7. Support least‑privilege and role‑based access controls across SMC systems.
8. Assist with identity governance.
9. Perform vulnerability scanning and risk assessments across endpoints, servers, networks, and cloud services.
10. Prioritize findings based on risk to SMC operations, data sensitivity, and regulatory impact.
11. Track remediation efforts and report status to IT leadership.
12. Support audit responses and risk assessments.
13. Assist with deployment, configuration, and tuning of:
- Email and phishing protection
- Network and firewall security controls
14. Maintain logging and evidence required for audits and compliance reviews.
15. Support cybersecurity policies and standards aligned with:
- NIST Cybersecurity Framework
- Tribal governance requirements
- Applicable public‑sector and health/financial data regulations
16. Assist with cybersecurity awareness training and phishing resistance programs. Contribute to incident response, disaster recovery, and business continuity documentation
QUALIFICATIONS:
1. Associates degree, Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or equivalent experience in cyber security role.
2. Working knowledge of cybersecurity threats, attack vectors, and defensive controls.
3. Experience supporting Windows Environment, Active Directory, and Microsoft 365.
4. Strong analytical, documentation, and communication skills.
5. Strong organizational skills and attention to detail.
6. Ability to work both independently and collaboratively under deadlines.
7. Strong sense of confidentiality, integrity, and public trust
8. Ability to translate cyber risk into business and operational impact
9. Collaboration across IT, leadership, and external partners
10. Continuous improvement and security‑first mindset
11. This is a full‑time position requiring occasional on‑call availability for critical incidents.
12. Required Experience
- Experience with:
- SIEM and log analysis
- Endpoint security platforms
- Vulnerability management tools
- Microsoft 365 / Azure security controls
- Scripting or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).