IT Security Administrator

Owensboro Municipal Utilities

• $80K — $95K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Technical degree in Computer Engineering or related field; Master's degree preferred.
  • 6 years of related experience in information security administration, with 2 years in management roles.
  • Certifications required: CompTIA Security+, CEH, CySA+, CFR.
  • Strong analytical skills with the ability to solve complex security problems.
  • Excellent communication skills for technical support and consultation.

Responsibilities

  • Manage detailed investigations into security issues.
  • Conduct routine vulnerability scans and remediate vulnerabilities promptly.
  • Analyze system logs regularly for anomalies and isolate malicious activity.
  • Install, configure, and maintain network services and devices.
  • Oversee building access security and telecommunication systems.
  • Stay updated on emerging threats to the organization's information assets.
  • Develop long-term strategies for security initiatives like penetration testing and PCI compliance.

Benefits

  • Flexible work environment with autonomy in task management.
  • Opportunities for advanced security training annually.
  • Exposure to a variety of security technologies and practices.
  • Possibility of impacting organizational security architecture.
Full Job Description
Job Code: 196
Exempt: Yes
Civil Service: No
Random Drug Screen: No
Residency Requirement: No
Department: Information Technology
Reports To: IT Systems Supervisor
Location: Main Office

GENERAL DESCRIPTION OF POSITION
The intent of this description is to provide a representative summary of the major duties and responsibilities performed by employees on this job. Employees may be required or assigned other related activities, projects, or tasks other than those specifically presented in this description. The requirements are representative of the knowledge, skill and/or ability needed. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Under the general direction of the IT Manager, the IT Security Administrator is responsible for the management of the organization's information security policies, security procedures, and security processes. This includes hardware, firmware, and software. Ensures that security architecture, plans, controls, processes, standards, policies, and procedures align with OMU needs and meet regulatory and industry requirements. Manages all vulnerability remediation. Develops, deploys, and maintains secure critical communication systems, and oversees network equipment, services, telephony, and mobile unit support to ensure reliable operation. Stays abreast of security-related regulatory requirements, industry standards, and best practices and implementing and managing changes as needed. Must be able to work autonomously. Must be able to effectively use interpersonal and communications skills including tact and diplomacy.

ESSENTIAL DUTIES AND RESPONSIBILITIES
  1. Manages detailed, comprehensive investigations related to security issues.
  2. Conducts routine vulnerability scans and manages timely remediation of identified vulnerabilities for corporate IT networks and systems.
  3. Analyzes system logs for anomalies on a routine basis. Collects evidence to support prosecution when necessary and isolates malicious activity to prevent further damage to OMU information.
  4. Installs, configures, and maintains network services, equipment, and devices; architects, plans, and supports network and computing infrastructure; leads and plans daily maintenance and problem resolution, including operating system patches, software upgrades, and routine hardware configuration for LAN/WAN and related systems.
  5. Oversees building access security and monitoring (including badge access and surveillance systems), as well as all communications billing, configuration, and support related to telephony and mobile units.
  6. Stays abreast of new and emerging threats that can affect OMU's information assets.
  7. Completes advanced security training at least annually.
  8. Reviews security settings for access and transmission of information, including routers, switches, firewalls, Active Directory, software settings, remote access, servers, wireless, PCs, web services, APIs, etc.
  9. Develops long-term strategies for conducting penetration testing, vulnerability scanning, remote-access security, PCI compliance, phishing exercises, security training, and other security-related activities.
  10. Performs day-to-day security functions related to security reviews and processes.
  11. Evaluates, recommends, and implements security solutions that are effective and affordable.
  12. Manages contractors, when needed, who have highly specialized skills in security systems.
  13. Ensures compliance with regulatory security and data protection measures (including those measures required for compliance with PCI, HIPAA, House Bill 5 PII, etc.).
  14. Provides technical support, advice, and consultation to customers with issues relating to information security.
  15. Provides 24/7 support of critical systems in area of responsibility.
  16. Maintains confidentiality of work-related information and materials.
  17. Perform any other related duties as required or assigned.

QUALIFICATIONS
To perform this job successfully, an individual must be able to perform each essential duty mentioned satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required.

EDUCATION AND EXPERIENCE
Technical degree required in such disciplines as Computer Engineering, CPA, etc., plus 6 years related experience and/or training, and 2 years related management experience, or equivalent combination of education and experience.

COMMUNICATION SKILLS
Ability to read, analyze, and understand common scientific and technical journals, financial reports, and legal documents; ability to respond to complex or difficult inquiries or complaints from customers, regulatory agencies, or members of the business community.

MATHEMATICAL SKILLS
Ability to apply advanced mathematical concepts such as exponents, logarithms, quadratic equations, and permutations. Ability to apply mathematical operations to such tasks as frequency distribution, determination of test reliability and validity, analysis of variance, correlation techniques, sampling theory, and factor analysis.

CRITICAL THINKING SKILLS
Ability to apply principles of logical or scientific thinking to a wide range of intellectual and practical problems. Ability to deal with nonverbal, logical or scientific symbolism such as formulas, scientific equations, and graphs. Ability to deal with a variety of abstract and concrete variables.

REQUIRED CERTIFICATES, LICENSES, REGISTRATIONS
Valid Driver's License

PREFERRED CERTIFICATES, LICENSES, REGISTRATIONS
Not indicated.

SOFTWARE SKILLS REQUIRED
Mastery: Database
Advanced: Presentation/PowerPoint, Programming Languages, Spreadsheet
Intermediate: Contact Management, Word Processing/Typing
Basic: 10-Key, Alphanumeric Data Entry

INITIATIVE AND INGENUITY
SUPERVISION RECEIVED
Under direction where a definite objective is set up and the employee plans and arranges own work, referring only unusual cases to supervisor.

PLANNING
Considerable responsibility with regard to general assignments in planning time, method, manner, and/or sequence of performance of own work, in addition, the organization and delegation of work operations for a group of employees engaged in widely diversified activities.

DECISION MAKING
Performs work operations which permit frequent opportunity for decision-making of major importance which would have considerable effect on the final attainment of multiple major activities and the organization's projects of a large organization component and organization's clientele.

MENTAL DEMAND
Intense mental demand. Operations requiring sustained directed thinking to analyze, solve, or plan highly variable, administrative, professional, or technical tasks involving complex problems or mechanisms.

ANALYTICAL ABILITY / PROBLEM SOLVING
Moderately directed. Activities covered by wide-ranging policies and courses of action, and generally directed as to execution and review. High order of analytical, interpretative, and/or constructive thinking in varied situations.

RESPONSIBILITY FOR WORK OF OTHERS
Responsibility for work of others: Not indicated.

RESPONSIBILITY FOR FUNDS, PROPERTY and EQUIPMENT
Occasionally responsible for organization's property where carelessness, error, or misappropriation would result in moderate damage or moderate monetary loss to the organization. The total value for the above would range from $150,000 to $1,000,000.

ACCURACY
Probable errors would normally not be detected in succeeding operations and may have serious effects in relationships with patrons and/or with the operations of other segments of the organization. Frequent possibilities of error would exist at all times, since the above-mentioned areas are inherent in the job.

ACCOUNTABILITY

FREEDOM TO ACT
Directed. Freedom to complete duties as defined by wide-ranging policies and precedents with mid- to upper-level managerial oversight.

ANNUAL MONETARY IMPACT
The amount of annual dollars generated based on the job's essential duties / responsibilities. Examples would include direct dollar generation, departmental budget, proper handling of organization funds, expense control, savings from new techniques or reduction in manpower.

Small. Job creates a monetary impact for the organization from $100,000 to $1mm.

IMPACT ON END RESULTS
Major impact. Job has a considerable impact on the organization's end results. A high level of accountability to generate, manage, and/or control funds within a department and/or total organization.

PUBLIC CONTACT
Occasional routine contacts with persons outside the organization. This would include contacts with suppliers, mail service, etc.

EMPLOYEE CONTACT
Contacts of considerable importance within the department or office, such as those required in coordination of effort, or frequent contacts with other departments or offices, generally in normal course of performing duties. Requires tact in discussing problems and presenting data and making recommendations, but responsibility for action and decision reverts to others.

USE OF MACHINES, EQUIPMENT AND/OR COMPUTERS
Highest level of network engineering, subject matter experts and telecom engineering and/or comprehensive information systems management executive for information systems or information technology operations.

WORKING CONDITIONS
Normal working conditions as found within an office setting, wherein there is controlled temperature and a low noise level, plus a minimum of distractions.

ENVIRONMENTAL CONDITIONS
The following work environment characteristics described here are representative of those an employee encounters while performing essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

The noise level in the work environment is usually quiet.

PHYSICAL ACTIVITIES
The following physical activities described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions and expectations.

High diversity, low physical. Work activities which allow for considerable amount of diversity as an incumbent performs a variety of tasks. Such tasks might be performed from a given work area, or the individual may move about physically in performing a variety of duties.

While performing the functions of this job, the employee is regularly required to stand, walk, sit, use hands to finger, handle, or feel, reach with hands and arms; frequently required to talk or hear; and occasionally required to climb or balance, stoop, kneel, crouch, or crawl. The employee must occasionally lift and/or move more than 100 pounds; frequently lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision; distance vision; color vision; peripheral vision; depth perception; and ability to adjust focus.

ADDITIONAL INFORMATION
Knowledge and Abilities

Bachelor's degree in Technology related studies, Master's degree preferred in a technical related field. Relevant work experience will be considered in lieu of advanced background.

Certifications required include:
• CompTIA Security+ or SANS GIAC Security Essentials
• Certified Ethical Hacker (CEH), CompTIA Cybersecurity Analyst (CySA+) or Cisco CCNA Cyber Ops
• CyberSec First Responder (CFR)

Preferred certifications include:
• Certified Information Systems Security Professional (CISSP)
• Certified Information Security Manager (CISM)

Experience
Minimum of six years of work experience and/or training in information security administration. Minimum of two years related management experience. Advanced security remediation skills, regulatory/industry knowledge, log aggregation and investigation, and vendor management skills are required.

Similar Jobs

More Jobs at Owensboro Municipal Utilities

More Information Technology Jobs

Find similar IT Security Administrator jobs: