cccd

IT Cyber Security Systems Engineer (Senior Position)

$115KOrange County, CA
✓ Verified live on the employer's own system · added 4 days ago
Save search
Senior · 8+ yrs exp

Requirements

Education: Bachelor's degree or related field

Experience: 8+ years

License: Driver's license

Skills & tools

SecurityRegulatory ComplianceManual LaborRecruitingHiringLoan ProcessingManagementOperations

Benefits — mentioned in this posting

Health, dental & visionPaid time offFamily / parental leave401(k) / retirement
Apply on company site ↗ See your fit → free

Full job description

Summary

Leads, plans, designs, and implements processes and procedures for risk assessments, vulnerability analyses, and penetration testing to prevent, detect, and respond to cyber security attacks. Identifies threats and vulnerabilities in systems and software and provides high-tech solutions to cyber security team to contain, remediate, and document circumstances around confirmed security issues. Provides guidance to and informs cyber security administrators on user security policies, procedures, and practices that defend against hacking, malware, ransomware, insider threats, and cybercrimes.

Distinguishing Career Features

The Cyber Security Systems Engineer is a senior-level professional position with advanced technical knowledge and analytical skills to identify, develop, and implement effective cyber security program policies, procedures, and processes. The Cyber Security Systems Engineer monitors malware trends and applies in-depth understanding of cyber security threats in collaboration with cyber security administrators to develop and implement cyber defense strategies. The Cyber Security Systems Engineer is responsible for cyber security requirements for related legal and regulatory compliance.

Working Conditions

Work is performed indoors where some safety considerations exist from physical labor, positioning in cramped areas, and handling of medium weight, yet awkward materials.

This job specification describes the general nature of the work performed, representative duties as well as the typical qualifications needed for acceptable performance. It is not intended to be a complete list of all responsibilities, duties, work steps, and skills required of the job.

Note: D.E.I.A. - Diversity, Equity, Inclusion, Accessibility, and Anti-Racism

The Coast Community College District (Orange Coast College, Golden West College, and Coastline) continues to strengthen our efforts around diversity, equity, inclusion, access, and anti-racism. The Coast Community College District is focused on creating a culture of inclusive excellence by uplifting employees and students through an environment that is equitable, diverse, inclusive, and accessible. We have a strong focus and importance on D.E.I.A. and Anti-Racism (Diversity, Equity, Inclusion, Accessibility) and will be actively listening, assessing, and evaluating this throughout each stage of the application, recruitment, and interview process.

Title IX & Sex Discrimination

https://www.cccd.edu/employees/hr/title9/Pages/Staff-and-Faculty-Resources.aspx

Comprehensive Medical, Dental and Vision

We know that the health of our employees and their families is a priority. That's why we offer extensive health care benefits to benefits-eligible employees. We offer the District's Anthem Blue Cross PPO plan as well as three HMO's, Blue Shield Access Plus, Blue Shield TRIO, and Kaiser Permanente. We also provide District-paid dental and vision insurance.

Benefits are available to regular permanent employees working 20 or more hours per week. Benefits are not available to employees working less than 20 hours per week, temporary, hourly, or other short-term employees.

District-paid Life Insurance

The District provides Life and Accidental Death & Dismemberment insurance benefits, underwritten by VOYA. This district-paid benefit is equal to one time your annual salary and remains in effect until age 70. At age 70, your benefit is reduced to half.

Essential Duties and Responsibilities

Incumbents typically perform a substantial portion or all the following types of duties, as required to maintain cyber security systems:

1. Provides subject matter expertise in the strategic planning processes, providing technical input into enterprise security initiatives.

2. Oversees and leads research and planning of leading-edge technologies for cyber security.

3. Leads the design and engineering of security solutions.

4. Recommends strategic security standards and policies to the Cyber Security Administrator.

5. Provides strategic guidance and subject matter expertise to Cyber Security Administrators, as well as guidance to all levels of the Cyber Security Team.

6. Provides operational and project team leadership for multiple, simultaneous enterprise-wide cyber security initiatives.

7. Leads and provides process enhancement for risk assessments, vulnerability analyses, and penetration testing.

8. Oversees and responds to security incidents and vulnerabilities.

9. Coordinates the design and engineering of security solutions; participates in planning for future cyber security technology.

10. Performs complex forensic preservation tasks as required.

11. Provides technical expertise to internal and external entities, including internal investigators and external law enforcement and intelligence/government agencies.

12. Develops processes, procedures, and security standards to promote operational efficiency.

13. Designs and integrates new architectural features; provides complex architectural and engineering analyses.

14. Embeds advanced cyber defense techniques for incident response

15. Leads the tactical execution of Cyber Incident Responses.

16. Develops and deliver cyber security training material.

17. Presents enterprise-wide security solutions and analyses to internal and external stakeholders.

18. Provides input and support to the development of communications addressing system and network security principles and technology solutions.

19. Applies project management principles and methods to the leadership of security tasks or projects.

20. (NICE-T0028) Conducts and/or supports authorized penetration testing on enterprise network assets.

21. (NICE-T0047) Correlates incident data to identify specific vulnerabilities and makes recommendations that enable expeditious remediation.

22. (NICE-T0051) Define appropriate levels of system availability based on critical system functions and ensure that system requirements identify appropriate disaster recovery and continuity of operations requirements to include any appropriate fail-over/alternate site requirements, backup requirements, and material supportability requirements for system recover/restoration.

23. (NICE-T0090) Ensure that acquired or developed system(s) and architecture(s) are consistent with organization's cybersecurity architecture guidelines.

24. (NICE-T0119) Identifies, assesses, and recommends cybersecurity or cybersecurity-enabled products for use within a system and ensure that recommended products follow organization's evaluation and validation requirements.

25. (NICE-T0155) Documents and escalates incidents (including event’s history, status, and potential impact for further action) that may cause ongoing and immediate impact to the environment.

26. (NICE-T0161) Performs analysis of log files from a variety of sources (e.g., individual host logs, network traffic logs, security system logs, and intrusion detection system [IDS] logs) to identify threats to network security.

27. (NICE-T0163) Performs cyber defense incident triage, to include determining scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable expeditious remediation.

28. (NICE-T0175) Performs real-time cyber defense incident handling (e.g., forensic collections, intrusion correlation and tracking, threat analysis, and direct system remediation) tasks to support deployable Incident Response Teams (IRTs).

29. (NICE-T0181) Performs risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change.

30. (NICE-T0196) Provide advice on project costs, design concepts, or design changes.

31. (NICE-T0205) Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).

32. (NICE-T0248) Promotes awareness of security issues among management and ensures sound security principles are reflected in the organization's vision and goals.

33. (NICE-T0258) Provides timely detection, identification, and alerting of attacks/intrusions, anomalous activities, and misuse activities and distinguishes these incidents and events from benign activities.

34. (NICE-T0259) Uses cyber defense tools for continual monitoring and analysis of system activity to identify malicious activity.

35. (NICE-T0260) Analyzes identified malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information.

36. (NICE-T0284) Designs and develops new tools/technologies as related to cybersecurity.

37. (NICE-T0338) Write detailed functional specifications that document the architecture development process.

38. (NICE-T0380) Plans instructional strategies such as lectures, demonstrations, interactive exercises, multimedia presentations, video courses, web-based courses for the most effective learning environment in conjunction with educators and trainers.

39. (NICE-T0427) Analyze user needs and requirements to plan architecture.

40. (NICE-T0503) Monitors external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus) to maintain currency of cyber defense threat condition and determines which security issues may have an impact on the enterprise.

41. (NICE-T0517) Integrate results regarding the identification of gaps in security architecture.

42. (NICE-T0518) Performs security reviews and identifies security gaps in architecture.

43. (NICE-T0542) Translate proposed capabilities into technical requirements.

44. (NICE-T0548) Provides advice and input for Disaster Recovery, Contingency, and Continuity of Operations Plans.

45. (NICE-T0549) Performs technical (evaluation of technology) and nontechnical (evaluation of people and operations) risk and vulnerability assessments of relevant technology focus areas (e.g., local computing environment, network and infrastructure, enclave boundary, supporting infrastructure, and applications).

46. (NICE-T0550) Makes recommendations regarding the selection of cost-effective security controls to mitigate risk (e.g., protection of information, systems and processes)

47. (NICE-T0555) Document how the implementation of a new system or new interface between systems impacts the current and target environment including but not limited to security posture.

48. (NICE-T0557) Integrate key management functions as related to cyberspace.

49. (NICE-T0926) Develops or assists with the development of privacy training materials and other communications to increase employee understanding of company privacy policies, data handling practices and procedures and legal obligations.

50. Performs other related duties as assigned that support the objective of the position.

51. Required to abide by all District policies and procedures including Board Policy 3050 – Code of Professional Ethics.

Qualifications Education and Experience

The position requires a bachelor’s degree in computer science, cyber security or related technical field and 8 years’ experience in cyber security project development and implementation, and on-going administration of integrated networks. Or any combination of education and experience which would provide the required equivalent qualifications for the position.

AND

Demonstrated evidence of responsiveness to and understanding of the racial, ethnic, disability, gender identity, sexual orientation, socioeconomic, academic, and cultural diversity within the community college student population, including students with different ability statuses (e.g., physical and/or learning) as these factors relate to the need for equity-minded practice within the classroom.

Licenses and Certificates

Required: CISSP or CISM.

Preferred: PMP, CCNA, OSCP, any GIAC certification.

May require a driver license.

Physical Abilities

1. The general physical demands, working conditions, and essential job functions associated with this classification will be kept on file with the Office of Human Resources.

2. Essential functions will vary by position.

3. As defined by Title I of the Americans with Disabilities Act (“ADA”) and California’s Fair Employment and Housing Act (“FEHA”), the District shall engage in a timely, good faith interactive process with employees or employment applicants who are requesting or are in need of reasonable accommodations and, provide reasonable accommodations for employees or employment applicants who, because of their disability, are limited in or unable to perform one or more of the essential functions of their job in accordance with applicable state and federal law.

Conditions of Employment

Note: To be eligible for employment, you must possess authorization to work in the United States. The District does not sponsor visas or take over any established visa sponsorship.

This is a permanent, general funded, full-time, 12-months per year classified position. The normal hours of work will be Monday through Friday 8:00 am to 5:00 pm, with the flexibility to occasionally work extended hours and/or weekends, if necessary, to meet the department's needs. The effective date of employment will be arranged with the supervisor. The District provides medical, dental, and vision insurance for the employee and eligible dependents and life insurance for the employee. (Salary Schedule: EE-126)

Please note that job offers are conditional and are contingent upon the successful completion of satisfactory comprehensive background check (including Livescan fingerprinting) and satisfactory references, and approval or ratification by the District’s Board of Trustees or the Chancellor.

Regular attendance is considered an essential job function; the inability to meet attendance requirements may preclude the employee from retaining employment. The person holding this position is considered a mandated reporter under the California Child Abuse and Neglect Reporting Act and is required to comply with the requirements set forth in Coast Community College District policies, procedures, and Title IX. (Reference: BP/AP 5910 ) The Coast Community College District celebrates all forms of diversity and is deeply committed to fostering an inclusive environment within which students, staff, administrators, and faculty thrive. Individuals interested in advancing the District's strategic diversity goals are strongly encouraged to apply. Reasonable accommodations will be provided for qualified applicants with disabilities who self-disclose.

The SELECTED CANDIDATE is required to complete the following prior to employment:
  • Provide a Certificate of Tuberculosis Exam for initial appointment (Note: The certificate must be renewed every 4 years as a condition of continuing employment).
  • Have fingerprints taken by a Live Scan computer at the candidate’s expense (Clearance must be received prior to the first day of employment).
  • Present original documents for proof of eligibility to work in the United States including a Social Security Card; (Note: We are unable to sponsor or take over sponsorship of an employment Visa at this time.) AND
  • Participate in a new hire onboarding appointment with an Employment Services Representative.
Qualifications and Physical Demands

Note: NICE reference the Task Number as assigned by the National Institute of Standards and Technology (NIST) National Initiative for Cybersecurity Education / Cyber Workforce Framework (SP800-181). This framework provides guidance to employers and colleges/training for describing the task, knowledge, skills, and abilities for CyberWork.

Desirable Qualifications

- Certifications - MS 500, AZ 500

- Enrolled or completed training in Identity and Access Administration Associate (SC300)

Knowledge and Skills

1. (NICE-K0001) Knowledge of computer networking concepts and protocols, and network security methodologies. 2. (NICE-K0002) Knowledge of risk management processes (e.g., methods for assessing and mitigating risk). 3. (NICE-K0003) Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.

4. (NICE-K0004) Knowledge of cybersecurity and privacy principles. 5. (NICE-K0005) Knowledge of cyber threats and vulnerabilities. 6. (NICE-K0006) Knowledge of specific operational impacts of cybersecurity lapses.

7. (NICE-K0021) Knowledge of data

More jobs at cccd

Similar jobs near Orange County, CA

Tell me when more Senior Systems Security Engineer, Programs jobs post near Costa Mesa, CA We re-check every listing against the employer’s own board — no résumé needed.

Search IT Cyber Security Systems Engineer (Senior Position) jobs near Orange County, CA → Browse all live jobs

This posting was published by cccd on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.