You are viewing a preview of this job. Log in or register to view more details about this job.

Sr. Information Security Analyst

THIS POSITION IS OPEN UNTIL FILLED
The first review of applications will take place: 
Monday, April 27, 2020 at 5:00 pm PDT

Are you motivated to be a part of an organization with extensive opportunities to learn, grow, and make a difference in a community that cares about you? Do you appreciate emotional intelligence and speak ITIL? Are you forward looking with process improvement in mind? As a true techie, do you love the thrill of new and interesting challenges and working with people who share a love of working with technology to solve problems? Is it important for you to have fun at work? Have you imagined yourself living in the richness of the Pacific Northwest?
 
If you answered yes to these questions this position and team might be right for you! The City of Eugene Information Services Division (ISD) builds and maintains the City of Eugene's technologies to meet the evolving needs of the community. We are a team committed to innovation and excellence built on a solid foundation of providing excellent customer service.
 
The scope of operations include:
  • Award-winning technology and services
  • Customers who are appreciative, collaborative, and engaging
  • An abundance of professional development and training opportunities
  • 51 City facilities throughout the community connected by a high-speed fiber optic network
  • A VMWare based virtualization environment running over 200 Windows servers
  • Cloud based infrastructure in the Microsoft Azure Government Tenant
  • More than 200 business software systems
  • More than 2 million visits to the City website annually
  • State of the art security and network intrusion systems, including Rapid 7 IDS/SIEM, and checkpoint Firewalls
 
As part of our dynamic information services team, you will play an integral role in our nationally and internationally recognized city organization, which delivers quality services to the unique City of Eugene. 
 
The City of Eugene is seeking a qualified Senior Information Security Analyst to continuously improve the city's security posture, as well as respond to emergent threats. This key position is responsible for securing our IT environment and providing expert advice on security best practices. The successful candidate will have an exemplary technical background in a variety of security tools and technologies, as well as a mastery of relevant security and regulatory frameworks. The successful candidate will have a passion for managing security along with a desire to relentlessly champion best practices.
 
This is a technical position, responsible for the data protection solutions that support the mission of the city. This position is responsible for protecting the confidentiality, integrity, and availability of information assets owned or entrusted to the City of Eugene. This position also requires superior communication and people skills like empathy, tact, flexibility and collaboration.

The Senior Security Analyst will have a proven track record in evaluating, assessing and recommending new products and technologies, as well as designing and implementing them in an enterprise technology environment. In addition, the Senior Security Analyst will evaluate, assess and perform risk analysis on existing vulnerabilities and provide actionable advice to key decision makers.
 
The Senior Security Analyst will work with members of the ISD team to investigate, perform forensics, compile relevant technical/background information, and perform post-mortem analysis of security incidents. This position will also be responsible for overseeing and conducting routine security audits, including CJIS, HIPAA and PCI audits.
 
The Senior Security Analyst will assist with education and outreach by providing advice to departments on current best practices related to security, developing security documentation, and teaching workshops on security related topics. They must stay abreast of evolving city needs, technology capabilities, and threat intelligence from a variety of sources to ensure our systems are secured.
 
The successful candidate for this position must demonstrate an extensive working knowledge of security and firewall appliances, Intrusion Detection Systems (IDS), Security Information Event Management Systems (SIEM), Windows server and client technologies, and networking best practices. Strong project management skills are essential.
 
The Senior Security Analyst will draw on their experience and strong ability to learn diverse technologies to maintain a heterogeneous technical environment, while providing expert advice as it pertains to a suite of regulatory best practices including CJIS, HIPAA, and PCI.

Work Schedule: Monday - Friday 8:00 AM - 5:00 PM with rotating on-call duties and occasional after hours per business need
 
Annual Salary:
Systems Programmer 2: $76,128.00 - $100,505.60

We are recruiting for a Senior Information Security Analyst. However, underfilling the position at a Systems Programmer 1: $69,971.20 - $90,521.60 may be considered.

MUST PASS A CRIMINAL RECORDS CHECK
Online applications only

Limited duration employees are required to have supervisor approval before applying to another City of Eugene position.
 Examples of Duties Performed - Duties may include but are not limited to the following:
In addition to the full scope of duties of the Systems Programmer 1 or Systems Programmer 2, duties may include, but are not limited to the following:
 
  • Manages and/or participates in technology projects using project management best practices.
  • Analyzes, diagnoses, and resolves complex hardware, communications, network, and operating systems problems/issues relating to the City's network.
  • Develop and implement IT security standards, policies, and best practices
  • Develop, implement and maintain internal procedures for incident response and data security
  • Lead routine procedures to identify security vulnerabilities and provide technical advice and support for vulnerability remediation
  • Create and maintain comprehensive documentation for all implemented security systems and networks at a standard in line with current regulatory best practices
  • Monitor and maintain centralized logging server aggregating tools such as Rapid 7, and respond to output of logs accordingly
  • Be responsible for critical auditing functions including CJIS, HIPAA, and PCI
  • Develop, implement and maintain Business Continuity planning and Disaster Recovery for IT systems
  • Work with HR to develop and implement security training for City employees
  • Be responsible for selecting, deploying and maintaining all security related tools, including new tools and enhancements to existing tools
  • Facilitate periodic risk assessments, penetration tests, and vulnerability assessments. Make security enhancement recommendations as a result of this testing.
  • Research, evaluate and recommend information security related enhancements as a result of current security best practices
  • Maintains and implements network and security policies consistent with industry best practices, FBI Criminal Justice Information Systems (CJIS) security policies, HIPPA and other regulatory standards.
  • Reviews output from SIEM and IDS tools to assess and respond to potential security incidents
  • Manages on premises and cloud-based infrastructure

  Qualifications:
Knowledge of:
  • Principles of network, system, and service design
  • Best practices related to IT service delivery, including ITIL
  • Principles of project management in a highly complex IT environment, such as AGILE and/or PMI
  • Working knowledge of laws, regulations, and standards affecting information technology security in a government environment including, but not limited to: PCI-DSS, HIPAA, and CJIS
  • Demonstrated expertise in three or more of the following IT security domains: data security, digital forensics, incident response and analysis, IT systems and operations, network security, Systems and application security, or vulnerability management
  • Current best practices of network and data center security.
  • Extensive knowledge of SIEM and IDS tools, including log and monitoring management systems, security event monitoring, network-based and host-based intrusion detection systems, firewall technologies, malware detection, and encryption standards 
  • Local and wide-area network hardware and software and related transmission and interface protocols.
  • Windows Server, IIS, SCCM and other Microsoft technologies.
  • Malware, anti-virus and endpoint management tools
  • Excellent understanding of Cisco based networking environments, and underlying network protocols, including TCP/IP and encryption
  • Excellent understanding of security/firewall appliances, including Checkpoint
  • Excellent understanding of Microsoft Office 365 and cloud technologies, with a particular emphasis on securing cloud hosted resources
  • General understanding and knowledge of VMware and other virtual platforms.
Ability to:
  • Acquire expert-level technical expertise in CJIS, PCI, HIPAA and other security standards, and be able to lead routine security audits that comply with these frameworks.
  • Develop and implement process and procedure improvements, especially as it pertains to security best practices.
  • Adapt in a rapidly changing technical environment.
  • Perform vulnerability scans in an windows-based enterprise environment.
  • Communicate effectively to technical and non-technical staff.
  • Create and conduct security training for a diverse audience.
  • Perform data forensics and post-incident analysis.
  • Demonstrate familiarity working with SIEM and IDS products.
  • Learn a variety of diverse network, server, software, workstation and interface technologies deployed in a complex and critical environment.
  • Communicate clearly and concisely, both orally and in writing; make presentations as needed.
  • Understand complex technical issues and apply technical knowledge in development of solutions.
  • Apply logic, knowledge, and experience in recognizing patterns and trends to solve problems.
  • Manage vendor and service contracts as needed.
  • Be available for flexible shifts, including rotating after-hours on-call.

MINIMUM QUALIFICATIONS
Any equivalent combination of education and experience which provides the applicant with the knowledge, skills and abilities required to perform the job. A typical way to obtain the knowledge and abilities would be:
 
Experience:
Six or more years of increasingly responsible experience in a secure enterprise Windows environment including project management, analysis, procurement, installation and maintenance of hardware, servers, software and telecommunications equipment.

We are recruiting for a Senior Information Security Analyst. However, underfilling the position at a Systems Programmer 1: $69,971.20 - $90,521.60 may be considered.
 
Education:
Bachelor's degree from an accredited college or university with major course work in Computer Science, Telecommunications, or a closely related field.
 
Certification in or progress towards at least one designation an information security risk, or compliance related discipline (E.g. CISSP, SSCP, CSA+, CASP, GESC, GCIA, CEH)
  
License or Certificate:
Valid Oregon driver's license, or ability to obtain by date of hire; must pass driving records check and, if hired, maintain a driving record that meets the City's standard. Oregon law requires that an out-of-state license holder must obtain a valid Oregon license (with appropriate endorsements) within 30 days of becoming domiciled in the state (ORS 803.355).

  Supplemental Information:
Retirement Program
Upon eligibility, the City will contribute an employee contribution of 6%, as well as the employer contribution, to a retirement program administered by the Oregon Public Employees' Retirement System (PERS). In addition, the City will pay a 3% contribution to a deferred compensation program if the employee contributes at least 1%.

Selection Process
Applicants are screened based upon their relevant knowledge, abilities, skills, experience, and training. The selection process varies according to the position and can include such things as screening of supplemental questionnaires, written or skill tests, ability or fitness tests, interviews, and assessment processes. In addition, background investigations and records checks may be required. Some positions also require applicants to have a psychological evaluation and/or physical examination and a drug test prior to employment.
 
DUE TO THE VOLUME OF APPLICATIONS RECEIVED BY THE CITY, GENERALLY, ONLY APPLICANTS SELECTED FOR FURTHER CONSIDERATION (TESTING, INTERVIEWS) WILL BE CONTACTED.
 
Current information about the status of a job posting is available by going to www.eugene-or.gov/jobs and selecting "Job Posting Status."

The City of Eugene complies with the Americans with Disabilities Act of 1990. Any applicant with a qualified disability under the Americans with Disabilities Act may request accommodation by contacting an employment coordinator at (541) 682-5061.

In compliance with the Immigration Reform and Control Act of 1986, the City of Eugene will request all eligible candidates who accept employment with the City to provide documentation to prove they are eligible for employment in the United States.

The City of Eugene is committed to a work environment which values the cultural, educational, and life experiences of each employee. We believe that a diverse workforce enables us to deliver culturally competent service to all members of our community. As part of our commitment to diversity, the City continues to be an affirmative action/equal opportunity employer. Women, people with disabilities, and persons of color are strongly encouraged to apply.