Job Description
Job Posting:
00033759
Opened:
06/13/2023
Closes:
06/27/2023
Position Title:
Cybersecurity Analyst II-III
Class/Group:
0322/0324 – B27/B29
Military Occupation Specialty Code:
Army-17C, 25B; Navy-IT, 682X; Coast Guard-IT; Marine Corps-0631, 0679, 0681, 8055; Air Force-3D0X3
Fair Labor Standards Act Status:
Exempt
Number of Vacancies:
1
Division/Section:
Office of the Chief Information Security Office (Security Policy & Governance)
Salary Range:
$6916.67-$8333.33/monthly
Duration:
Regular
Hours Worked Weekly:
40
Work Schedule:
This position may be eligible for flexible work hours and/or a hybrid work schedule if certain program guidelines are met; working arrangements may change at any time at the sole discretion of the agency.
Travel:
Occasional
Agency Address:
300 West 15th Street, #1300 / Austin, Texas 78701
Web site:
https://dir.texas.gov/
Refer Inquiries to:
People and Culture Office
Telephone:
(512) 475-4957 or (512) 463-5920
How To Apply:
- Select “Apply Online” to apply for the job at https://capps.taleo.net/careersection/ex/jobsearch.ftl?lang=en
- You must create a CAPPS Career Section candidate profile or be logged in to apply.
- Update your profile and apply for the job by navigating through the pages and steps.
- Once ready, select “Submit” on the “Review and Submit” page.
- If you have problems accessing the CAPPS Career Section, please email the CAPPS Recruiting Help Desk at capps.recruiting@cpa.texas.gov
Special Instructions:
- Applicants must provide in-depth information in the EXPERIENCE & CREDENTIALS section to demonstrate how they meet the position qualifications. Incomplete applications may result in disqualification.
- Resumes may be uploaded as an attachment but are not accepted in lieu of the information required in the EXPERIENCE & CREDENTIALS section of the application.
Interview Place/Time:
Candidates will be notified for appointments as determined by the selection committee.
Notice:
Section 651.005 of the Government Code requires males, ages 18 through 25 years, to provide proof of their Selective Service registration or proof of their exemption from the requirement as a condition of state employment.
Equal Opportunity Employer
The Department of Information Resources does not exclude anyone from consideration for recruitment, selection, appointment, training, promotion, retention, or any other personnel action, or deny any benefits or participation in programs or activities, which it sponsors on the grounds of race, color, national origin, sex, religion, age, or disability. Please call 512-463-5920 to request reasonable accommodation.
Department Of Information Resources Position Description
Division:
Office of the Chief Information Security Office (Security Policy & Governance)
Class/Group:
0322/0324 – B27/B29
Title:
Cybersecurity Analyst II-III (Governance, Risk & Compliance Analyst)
FLSA:
Exempt
The Opportunity
The Texas Department of Information Resources is the state agency charged with protecting the state’s data and critical technology infrastructure, managing a multi-million-dollar cooperative contracts program, and providing strategic technology leadership, solutions, and innovation to all levels of Texas government. DIR is a fast-paced and collaborative environment with highly motivated and engaged employees dedicated to achieving the best value for the state.
The person in this role performs highly complex (senior-level) information security analysis functions that include planning, implementing, and monitoring security program elements and services that support government organizations throughout the state of Texas in the protection of information resources. This person will be responsible for assisting in the development and implementation of the state’s Risk Authorization and Management Program. Additionally, she/he will assist with the statewide information security governance, risk, and compliance program development and operations. Will interact frequently with state agency and other governmental agency personnel using a variety of communication mechanisms to convey service delivery information and program implementation details with the purpose of engaging organizations with the statewide security program. Works under limited supervision, with considerable latitude for the use of initiative and independent judgment.
What We Do
The ideal candidate will have the ability to highlight their strengths in the following functions:
• Assists with establishing the Texas Risk and Authorization Management Program (TxRAMP) for state agencies and institutions of higher education and serves as the subject matter expert in certifying cloud vendors under the TxRAMP program.
• Provides support to agencies, vendors, and others on TX-RAMP and GRC program functions.
• Assists in developing the vision for the program, improving operational efficiency, and bringing new GRC services to customers.
• Researches and evaluates new and emerging GRC services; Supports efforts, as part of the GRC development and support team responsible for design, development, and implementation of new processes, applications, and reporting using the DIR GRC system.
• Supports the statewide clearinghouse on information security matters including policy and compliance management, risk management, incident management and data breach reporting within the enterprise governance, risk, and compliance framework.
• Assists in the development and implementation of enterprise security strategies, policies, and plans, as well as the formulation and dissemination of standards and guidelines to manage statewide information and information asset related risks, threats, and vulnerabilities.
• Analyzes statewide security data and assists in the preparation of presentations and reports in support of the statewide security program to be delivered to DIR Executive Management and Board of Directors, customers, and the state leadership.
• Performs other work-related duties as assigned.
Qualifications:
Education
• Graduation from an accredited four-year college or university with major course work in Business, MIS, Computer Science, Information Security, or related field.
• Additional work-related experience may be substituted for education on a year-for-year basis (High-school diploma and six (6) years of experience without a degree.
Experience and Training Required
• Two (2) to four (4) years of progressively responsible experience in the IT industry.
• Two (2) years of experience developing and implementing security program functions into a risk-based security program with the ability to demonstrate in-depth knowledge of policy development, risk evaluation, and cost benefit analysis to support security program decisions.
Experience and Training Preferred
• Project management certification and training
• Experience with State of Texas information security requirements including Texas Administrative Code §202.
• Experience with Federal Information Security Management Act (FISMA) and National Institute of Standards (NIST) 800 Series Special Publications or other security standards and regulations.
• Experience collaborating with outsourced IT service delivery organizations.
• One of the following certifications: Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Information Systems Manager (CISM), Certified in Risk and Information Systems Control (CRISC), Certified Cloud Security Professional (CCSP) or equivalent.
• Experience in using or developing governance, risk, and compliance software and platforms.
Knowledge, Skills, and Abilities
• Knowledge of data communications, networking, computer programming and systems analysis
• Knowledge of information security operations and services processes
• Knowledge of principles, practices, and techniques of management controls and information security protections as applied to state government.
• Knowledge of Texas State government and related information technology processes
• Knowledge of security metrics, benchmarking activities and expectations, and security operational monitoring processes
• Ability to handle multiple projects and initiatives.
• Ability to prepare technical issues papers and research reports, and effectively deliver oral presentations and written reports to IT and non-IT management.
• Ability to advise technical staff from customer agencies.
• Ability to establish and maintain effective and cordial working relationships at all organizational levels, including agency management, direct supervisors, co-workers, internal and external customers.
• Ability to understand, follow and convey brief oral and/or written instructions.
• Ability to communicate both verbally and in writing, in a clear and concise manner.
• Ability to work independently and as part of a team, and to support and contribute to a cohesive team environment.
• Ability to work under pressure and exacting schedules to complete assigned tasks.
• Ability to work a flexible schedule to meet required deadlines.
• Ability to travel as necessary to support agency requirements.
• Ability to comply with all agency policy and applicable laws.
• Ability to comply with all applicable safety rules, regulations, and standards.
Computer Skills
• Proficiency in the use of a computer and applicable software necessary to perform work assignments e.g., word processing, spreadsheets (Microsoft Office preferred), presentation software, and data analysis/reporting software.
Other Requirements
• Regular and punctual attendance at the workplace.
• Criminal background check.
Working Conditions
• Frequent use of computers, copiers, printers, and telephones.
• Frequent standing, walking, sitting, listening, and talking.
• Frequent work under stress, as a team member, and in direct contact with others.
• Occasional bending, stooping, lifting, and climbing.
• Occasional travel