Job Description:
The Security Officer is a pivotal position within the ITS security framework, responsible for safeguarding digital assets, data, and infrastructure for ITS and ITS’s clients. Reporting directly to the Cybersecurity department, this role plays a crucial part in maintaining a secure environment, responding to security incidents, and ensuring compliance with security standards. Additionally, the Security Officer encompasses several sub-roles, each contributing to the broader security mission.
Job Responsibilities:
Sub-Roles of the Security Officer:
- SOC Incident Responder (SOC IR):
- Play a key role in incident response activities, working alongside the Incident Manager and the SOC team.
- Assist in coordinating and executing incident response plans to mitigate security threats.
- Provide timely and effective incident reports to the Incident Manager.
- Security Standards Analyst (SSA):
- Assist in the documentation and reporting of security standards and compliance assessments.
- Collaborate closely with the Security Standards Manager (SSM) to maintain a strong security posture.
- Ensure ITS's compliance with security policies, standards, and industry best practices.
- Conduct regular security assessments and audits of ITS and ITS clients to identify vulnerabilities and areas for improvement.
- Assist in developing and updating security policies, procedures, and guidelines.
- Assist vCIOs, CAMs and Sales teams with supporting data to help support, expand, or sell new service to new and existing clients.
- Virtual Security Officer (vSO)/ Virtual Chief Security Officer (vCSO):
- Act as a dedicated point of contact for practice management, providing virtual Security Officer/ Chief Security Officer services.
- Offer guidance and support for active engagements with clients.
- Conduct meeting with clients.
- Collaborate with 3rd parties and other ITS departments to align security practices with framework-specific needs for clients.
Collaborative Support:
- Collaborate with the First Responder, SOC Threat Hunter, and other security team members to enhance the overall security posture.
- Participate actively in security incident exercises, drills, and simulations to improve response readiness.
- Communicate effectively with team members, sharing knowledge and expertise to strengthen the security team.
- Join the incident response on-call rotation.
Statement of Transition:
Given the knowledge requirements of the Security Officer position it is expected that internal transfers will have considerable responsibilities on their existing teams. If selected for the position as Security Officer a transitionary plan will be developed in conjunction with the Security Officer Candidates most recent direct manager and relevant team. Even after each Security Officer is fully transitioned it is expected that they will assist local teams with emergencies.
Job Qualifications:
- Bachelor's degree in Cybersecurity, Information Technology, or a related field (preferred).
- Relevant security certifications such as CompTIA Security+, Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM) are a plus.
- Strong knowledge of security principles, best practices, and industry standards.
- Exceptional analytical and problem-solving skills.
- Outstanding communication and interpersonal skills.
- Ability to work both independently and collaboratively as part of a team.
- A high level of attention to detail and a commitment to maintaining the confidentiality and integrity of sensitive information.
This position offers an opportunity to contribute significantly to the organization's security efforts, grow within the cybersecurity field, and play a critical role in protecting our digital assets. The Security Officer will report directly to the Cybersecurity department and work in various sub-roles to enhance our security posture and respond effectively to security incidents.