Full Job Description
Summary Description: Under direction of the Director of the Department of Cybersecurity and Technology Infrastructure, coordinates, designs, and maintains system-wide information security and compliance initiatives; safeguards enterprise systems and data by defining access privileges, control structures, and resources, as determined by best practices, industry standards, and stakeholder needs; identifies and mitigates system vulnerabilities, violations, and inefficiencies through routine audits; provides status updates on system performance through multiple means; acts on privacy breaches and malware threats. Executes and supports Risk Management Framework (RMF) activities and ensures compliance with Maryland Department of IT processes and documentation standards. Supports enterprise architecture governance by maintaining architecture artifacts, system documentation, and technical configuration diagrams. Lead engineer on network Disaster Recovery solutions, reviewing vendor security reports, and cybersecurity strategies. Effectively communicates with staff and stakeholders, including senior leadership. Physical Demands: Position is required to work at computer workstations for sustained periods of time. Special Requirements: Ability to work extended hours, especially during peak periods and when urgent work requirements exist.
Knowledge Skills Abilities: Thorough knowledge and experience with risk management processes, cybersecurity and privacy policies and procedures, vulnerability and threat management, vulnerability assessment tools and techniques, network security principles and practices. Ability to identify and mitigate network vulnerabilities, as well as communicate best practices to avoid security flaws. Thorough knowledge of disaster recovery and business continuity best practices for critical systems required. Ability to construct high level and detail level network security and disaster recovery diagrams to be shared with management, other departments, and coworkers. Ability to manage multiple complex projects and tasks while paying close attention to details. Thorough knowledge of risk management framework and system risk assessments to prepare school system for state and county audits by documenting the environment and providing guidance to system stakeholders. Strong analytical and problem-solving skills. Skilled in decision making with a track record of exercising good judgment. Must be detail-oriented, highly organized, and an effective communicator. Excellent oral and written communication and human relations skills. Education Training Experience: Bachelor of Science or Bachelor of Arts degree in Computer Science, Information Technology systems, or related field from an accredited university required. Master?s degree preferred. Five years or more documented professional experience in technology. Proven experience in information system security operation, information system security assessment, system documentation, risk mitigation, vulnerability management, networking systems and/or network security (i.e., DNS, firewalls, proxies), agentless security, and XaaS (e.g., SaaS, IaaS, PaaS, DaaS, FaaS). Experience implementing industry standard information security frameworks, policies and procedures. Experience supporting GRC capabilities such as policy management, security awareness training, third-party risk management, and metrics and reporting. Experience in deploying various solutions to scale GRC processes including but not limited to security questionnaires, risk assessment, evidence collection, and control testing. Experience designing, reviewing, deploying, and auditing AI-powered solutions (including agents) and apply LLMs/NLP to analyze policies, audit findings, and regulatory requirements preferred. Certificate License: Professional certification in one or more of the following: CISSP, CompTIA Security+, CISA preferred.