GENERAL STATEMENT OF RESPONSIBILITY: Responsible for the full execution of CRL's Information Security Management (ISMS) with continual monitoring of the performance of the program and related activities, taking appropriate steps to improve effectiveness and keep in compliance with regulations.
ESSENTIAL FUNCTIONS: - Direct all aspects of corporate security and access control.
- Implement policies and procedures to limit access to IT facilities and equipment.
- Develop and implement security guidelines, standards, procedures, and training for multiple platforms and diverse system environments.
- Establish and maintain monitoring for security events; investigating, analyzing, and coordinating security event responses; and recommending appropriate corrective actions.
- Support the development and management of CRL's Data Center Recovery Plan and the security elements of CRL's business continuity plan, including data backup and disaster recovery.
- Maintain alignment with CRL Privacy Officer to ensure correlation of Security and Privacy activities.
- Identify and assess security risks and exposures on new and existing infrastructure.
- Develop and maintain security best-practices, policies, and controls, and monitoring and recommending appropriate corrective action to ensure their compliance.
- Monitor corporate compliance with policies and procedures related to physical access to all corporate facilities and equipment, including all those related to IS, such as computer rooms and systems, network rooms and equipment, telephone facilities, etc.
- Implement policies and procedures to ensure the security and efficacy of CRL's corporate email system.
- Implement policies and procedures to ensure proper and appropriate access to and from the Internet and CRL's internal networks.
- Conduct active penetration tests; discovering vulnerabilities in information systems, recommending corrective action, and monitoring and escalating to ensure appropriate fixes are implemented.
- Provide technical consulting in the development and implementation of cybersecurity strategies for both SBU and IS initiatives.
- Perform security risk assessments of the different business units, relevant external suppliers and the corporate systems and infrastructure and reviewing network architecture, server administration, and product development.
- Evaluate and recommend solutions, best practices, and standards for enterprise security infrastructure including authentication and authorization services, intrusion detection, firewalls, and virus management.
- Support IT Business Directors by assisting, from a security and access control position, in applicable audits and client visits.
- Secure communication channels and guard against and responding to network attacks.
- Conduct regular audits of software development and other IT processes to ensure appropriate quality is delivered in these processes.
- Identify, capture and trend metrics to track the performance of the IT department related to completion of tasks on time, code defects and adherence to information security procedures.
- Act as a key stakeholder in the quality management system team.
- Set strategic performance improvement goals for the IT department related to its various service centers.
- Assist the IT department is executing on process improvement initiatives.
- Maintain professional and technical knowledge by attending educational training forums/workshops; reviewing professional publications; establishing personal networks, participating in professional societies.
- Continually develop management skills through available training resources, including offsite professional training.
- Be proactive in bringing ideas to management's attention to improve recruiting, productivity, service, quality, policies and procedures, cost savings, and utilization of company resources.
- Ensure concerns are raised to the appropriate level of management.
- Maintain and protect the confidentiality of all CRL, CRL subsidiaries, legal entities and client information.
- Be able to comply with all applicable federal, state, and local safety and health regulations that would apply to this job.
- Other duties as assigned.
JOB QUALIFICATIONS:EDUCATION: Bachelor's degree in related discipline and/or work experience.
EXPERIENCE:- 5 years IS systems administration experience with some focus in IS security.
- 2 years programming experience.
- Qualifications to acquire CISSP (ISC2), GISP (GIAC), GSLC (GIAC) or CSQE (ASQ) certification within 12 months of hire required.
SKILLS & ABILITIES:- Ability to prepare clear written communication; to prepare and lead professional presentations, and to communicate clearly on the phone and through email and chat with remote parties regarding all aspects of information security and access control.
- Demonstrated successful execution of large-scale IS/IT projects in complex environments.
- Strong skills in assessing client needs and delivering on such requirements.
- Strong understanding of web technologies and demonstrated experience with business process analysis and implementation.
- Excellent analytical, troubleshooting and problem-solving skills.
- Strong ability to elicit, articulate, and document information in a well-organized manner.
- Excellent communication, interpersonal, and team building skills and ability to form trusted relationships at all levels.
- Keen understanding of QA principles and their application to software development and other IS/IT functions.
- Capacity to think strategically and develop plans to bring strategic vision to practical results.
- Ability to solve complex problems and issues using sound business judgment.
- Proven ability to handle multiple priorities concurrently and be proficient using MS Office, Visio, SQL, and Oracle.
- Ability to work effectively in a team environment and to influence others successfully.
- Ability to be at work and on time
- Ability and judgment to interact and communicate appropriately with other employees, clients and managemen
PHYSICAL REQUIREMENTS: Must be able to operate a keyboard and mouse.
EQUIPMENT: Personal computers, midrange systems, communications equipment (telephones, faxes).
OTHER: Flexible work schedule and some travel required.
The employer shall, in its discretion, modify or adjust this position to meet the company's changing needs.
This job description is not a contract and may be adjusted as deemed appropriate in the employer's sole discretion.
To perform this job successfully, an individual must be able to perform each essential job duty satisfactorily. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform essential job functions.
- denotes essential job function
Pay Range: $110,000 - $245,000
Starting Pay Range: $110,000 - $130,000
Benefits for Full Time Employees:- Medical, Dental, Vision
- Life/AD&D
- Supplemental Life/AD&D
- Section 125 FSA Plan
- 401(k)
- Short and Long-Term Disability
- Paid Time Off
- Holidays
- Tuition Reimbursement