- on-site position with a posibility of one day remote****
In No Particular Order, They Are
Seeking someone with cyber security experience. There are 3 general categories of activities that the individual would be working on.
Coordinating security projects. The individual does not need domain specific expertise on any given project, but should be familiar with security terminology and concepts and be able to apply that knowledge to new projects. Sample projects include privileged access management, secure file sharing, and attack surface management. For this category, were looking for broad familiarity with the security field, and not deep knowledge of any particular area like firewalls or PCI compliance.
Heavy involvement with various compliance efforts. None of these is a solo effort, but would be a significant chunk of time daily to reach out to others, collect information, review it, and put it into a format that provides sufficient documentation to demonstrate compliance. These include assisting with the Spring 2023 PCI compliance data collection, assisting with complying with the new GLBA regulations related in this case to cyber security surrounding student loans, and looking at ways to improve the universitys cyber governance, cyber risk management, and overall compliance efforts.
Help respond to others daily not-too-technical cyber security concerns. We would train someone on the specifics. Examples include requests to create accounts or provide access, and attending meetings where the topic requires someone from security to be present, but no final decision to be made, and possibly reviewing new technology requests to determine if there are security concerns.
Ideally this would be someone with at least 6 months of experience, but willing to consider a new graduate or newly certified person if theres prior non-security work experience and a good match. For example, given that theres a lot of coordination involved, someone with experience managing projects, even if they were not cybersecurity projects, might be a good fit. But the individual would be working with technical material all the time, and someone shy about technology would not be a good fit.