Information Systems Security Officer role responsible for IT security policies and incident response. Supporting NOAA's mission with expertise in federal information security and compliance standards.
Responsibilities
Develop and implement IT security policies and procedures to safeguard NOAA's information systems and data.
Support annual training for all personnel accessing sensitive information to ensure awareness and compliance with security protocols.
Provide guidance and instruction to staff regarding their individual responsibilities within the cybersecurity framework.
Implement and manage security technologies (firewalls, encryption, vulnerability scanning) to protect NOAA’s IT resources and ensure they remain secure.
Lead efforts to respond to and investigate IT security incidents, ensuring quick, effective resolution and coordination with relevant parties.
Collaborate with NOAA departments and external agencies to ensure a unified approach to IT security across the organization.
Oversee the accreditation of NOAA’s IT systems, ensuring systems meet established security standards and guidelines.
Provide continuous monitoring of NOAA’s IT infrastructure, ensuring ongoing situational awareness and early detection of security threats.
Assess vulnerabilities and security risks within NOAA’s systems, proposing and implementing risk mitigation strategies.
Participate in ongoing Security Assessments for each application, including support for achieving and maintaining an Authority to Operate (ATO), and addressing security issues identified in the POA&M and Security Assessment Report.
Implement data masking procedures to protect Personally Identifiable Information (PII).
Requirements
Proven experience in IT security roles, preferably in a federal or governmental environment.
Experience with Cloud Responsibility Model and keeping it updated.
Tracking and following Compliance Standards via NIST.
Experience using Tenable scan utility.
Experience using ArcSight and BigFix asset inventory tools.
Project Management (Self-directed management of projects).
Technical Writing.
Knowledge of security frameworks (NIST, ISO 27001, etc.) and security tools.
Familiarity with incident response processes and vulnerability management.
Experience with security accreditation and continuous monitoring.
Strong communication and collaboration skills, with the ability to work across multiple teams and agencies.
Ability to obtain and maintain a Public Trust background check.
Benefits
Comprehensive Health Benefits (Medical, Dental, and Vision) including High Deductible Health Plan where the company pays 100% of the deductible for your family.
Flexible Spending Accounts (FSA) & Health Savings Account (HSA).
Retirement Plan with 4% match and discretionary match at year end.
Paid Time Off (PTO): 15 days of PTO accrued per year; 7 holidays + 3 Floating holidays; 2 Innovation days (paid training days).
Manager at PwC contributing to digital transformation in Utilities through technology consulting and stakeholder management. Focused on creating strategies and providing technology solutions in a data - driven world.
Research Associate conducting advanced research in iOS security within a leading institute for applied cybersecurity. Emphasis on secure application development and vulnerability analysis.
Cybersecurity Engineer focused on threat monitoring and incident response for Verizon's network security. Collaborating on security architecture and vulnerability management across multiple locations.
Senior Manager of Application Security leading initiatives to protect applications at Nordstrom through strategic leadership and AI - driven tooling. Collaborating with engineering to ensure secure software development practices.
Information Security Engineer responsible for deploying and supporting security tools across cloud and on - premise systems. Collaborating with IT to mitigate security risks in a hybrid work environment.
Casual Retail Security Officer for MSS Security ensuring safety at Tweed Mall in Tweed Heads. Responsible for patrols, incident response, and customer service.
Financial security advisor at Desjardins developing client relationships and selling life and health insurance products. Focusing on customer satisfaction and personalized financial solutions.
Principal Information Security Consultant at Westpac focusing on security protocols and employee benefits for staff. Hybrid role centrally located with opportunities for professional development and employee perks.
Engineer supporting secure development lifecycle processes for product lines in the energy sector. Collaborating with R&D on security requirements and compliance audits.
Automation Oversight Engineer providing oversight of compliance in automated device configurations for Comcast Business. Managing configuration checks and reporting, ensuring reliable oversight and improvement strategies.