What are the responsibilities and job description for the Cyber Security Officer position at Charlotte-Mecklenburg Schools?
JOB GOAL
Responsible for determining vulnerabilities in software, hardware, networks, data centers, design strategies and defensive systems to protect against attacks and threats in overall district IT systems while continuing to evolve technology as new security concerns continue to develop.
Essential Duties & Responsibilities
- Offers customized risk ratings for vulnerabilities based on district policies and maintains information technology (IT) security control documentation by conducting counteractive protocols and reporting incidents.
- Performs research, testing, evaluation, and deployment of security technology and procedures.
- Runs diagnostics on any changes to data to verify any undetected breaches.
- Develops custom systems for specialized security features and procedures for software systems, networks, data centers, and hardware.
- Develops and implement information security standards, guidelines, and procedures.
- Establishes workflows, determines department priorities, and creates support systems to ensure efficient operations.
- Provides leadership and guidance for both internal and external technical resources, including coaching and feedback and coordinating activities and assignments, to ensure delivery of high-quality services to district stakeholders.
- Conducts threat and risk analysis and analyzes the business impact of new and existing systems and technologies to eliminate risk, performance, and capacity issues.
- Implements vulnerability assessments and configures audits of operating systems, web servers, and databases and detects patterns, insecure features, and malicious activities in the infrastructure.
- Ensures execution and delivery of information technology (IT) portfolio project initiatives as the executive leader in charge of all enterprise projects.
- Partners with stakeholders to identify, develop, implement, and assess emerging technology strategies.
- Reports trends affecting daily operations and provides feedback to IT operations, senior leadership, and other team members.
- Develops and maintains in-depth knowledge of the inner workings of districts' enterprise operational systems, stays up to date with new intrusion methods, and develops protection plans.
- Effectively collaborates with cross-functional areas for ticket resolution, monitors the response-time of team services, and in the procurement of IT hardware and software.
- Coordinates with other departments regarding disaster and contingency emergency management planning and preparedness.
- Participates in professional development to remain current with emerging technologies and educational research.
- Performs other related duties as assigned.
SUPERVISORY RESPONSIBILITY
Direct supervision of assigned personnel. Responsibilities include planning, assigning, and directing work: addressing complaints and resolving problems; training employees; evaluating performance; and interviewing, testing, hiring, and assignment of personnel.
MINIMUM REQUIREMENTS
Knowledge, Skills & abilities
- Thorough knowledge of physical and core technologies
- Thorough knowledge of enterprise-scale cloud and/or hybrid infrastructures, architecture designs, migrations, and/or technology management
- Skilled in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes
- Knowledge of risk management processes
- Knowledge of laws, regulations, policies, principles, and ethics as they relate to cybersecurity and privacy
- Knowledge of cyber threats and vulnerabilities
- Knowledge of specific operational impacts of cybersecurity lapses
- Knowledge of encryption algorithms
- Knowledge of business continuity and disaster recovery continuity of operations plans
- Knowledge of incident response and handling methodologies
- Knowledge of system life cycle management principles, including software security and usability
- Knowledge of information security program management and project management principles and techniques
- Knowledge of implementing enterprise key escrow systems to support data-at-rest encryption
- In-depth knowledge of vulnerabilities, management systems, and common security applications.
- Strong problem solving and critical thinking skills
- Ability to communicate effectively with a variety of audiences, orally and in writing, including electronic media
- Excellent time management skills and ability to organize, prioritize, manage and carry out duties efficiently and within established timeframes
- Ability to establish and maintain collaborative working relationships with all stakeholders
- Must be able to work flexible hours, including during non-business hours as required by the flow of operations.
Education, Training & Experience
- Bachelor's degree from an accredited institution
- 10 years of related experience
- At least 8 years directly responsible for various components of enterprise IT security/network infrastructure
OR
- Any equivalent combination of education and experience which provides the required knowledge, skills, and abilities to perform the essential duties and responsibilities of the position
Certificates, Licenses & Registrations
- Certified Information Systems Security Professional (CISSP), preferred
- Certified Information Systems Auditor (CISA), preferred
Preferred qualifications
- Hands-on experience with supporting large-scale IT initiatives within a public-school educational environment
- Experience applying techniques for detecting host and network-based intrusions using intrusion detection technologies
- Experience integrating information security requirements into the acquisition process; using applicable baseline security controls as one of the sources for security requirements; ensuring a robust software quality control process; and establishing multiple sources (e.g., delivery routes, for critical system elements).
- Experience identifying critical infrastructure systems with information communication technology that were designed without system security considerations.
Salary : $94,661 - $0