Information Systems Security Officer role responsible for IT security policies and incident response. Supporting NOAA's mission with expertise in federal information security and compliance standards.
Responsibilities
Develop and implement IT security policies and procedures to safeguard NOAA's information systems and data.
Support annual training for all personnel accessing sensitive information to ensure awareness and compliance with security protocols.
Provide guidance and instruction to staff regarding their individual responsibilities within the cybersecurity framework.
Implement and manage security technologies (firewalls, encryption, vulnerability scanning) to protect NOAA’s IT resources and ensure they remain secure.
Lead efforts to respond to and investigate IT security incidents, ensuring quick, effective resolution and coordination with relevant parties.
Collaborate with NOAA departments and external agencies to ensure a unified approach to IT security across the organization.
Oversee the accreditation of NOAA’s IT systems, ensuring systems meet established security standards and guidelines.
Provide continuous monitoring of NOAA’s IT infrastructure, ensuring ongoing situational awareness and early detection of security threats.
Assess vulnerabilities and security risks within NOAA’s systems, proposing and implementing risk mitigation strategies.
Participate in ongoing Security Assessments for each application, including support for achieving and maintaining an Authority to Operate (ATO), and addressing security issues identified in the POA&M and Security Assessment Report.
Implement data masking procedures to protect Personally Identifiable Information (PII).
Requirements
Proven experience in IT security roles, preferably in a federal or governmental environment.
Experience with Cloud Responsibility Model and keeping it updated.
Tracking and following Compliance Standards via NIST.
Experience using Tenable scan utility.
Experience using ArcSight and BigFix asset inventory tools.
Project Management (Self-directed management of projects).
Technical Writing.
Knowledge of security frameworks (NIST, ISO 27001, etc.) and security tools.
Familiarity with incident response processes and vulnerability management.
Experience with security accreditation and continuous monitoring.
Strong communication and collaboration skills, with the ability to work across multiple teams and agencies.
Ability to obtain and maintain a Public Trust background check.
Benefits
Comprehensive Health Benefits (Medical, Dental, and Vision) including High Deductible Health Plan where the company pays 100% of the deductible for your family.
Flexible Spending Accounts (FSA) & Health Savings Account (HSA).
Retirement Plan with 4% match and discretionary match at year end.
Paid Time Off (PTO): 15 days of PTO accrued per year; 7 holidays + 3 Floating holidays; 2 Innovation days (paid training days).
Security Director overseeing lab services and operations, ensuring compliance and security across global sites. Leading teams and integrating secure strategies for innovation and productivity.
Security Product Owner at Dell Technologies responsible for Lab Services and Operations. Translate strategy into initiatives while collaborating with cross - functional leaders in security engineering and Agile delivery.
Security Shift Manager responsible for safety operations at WarHorse Gaming Omaha. Supervising security staff and ensuring compliance with laws and regulations.
Security Supervisor managing safety and loss prevention for WarHorse Gaming in Omaha. Ensures compliance and oversees the security department operations on the casino floor.
Security Architect leading AI trust and governance strategies for Fortune 500 with Salesforce. Empowering organizations with cutting - edge security solutions in a collaborative environment.
Cloud Security Architect at Cayuse overseeing secure architecture design, implementation, and governance for cloud - native, microservices, and AI - enabled systems. Collaborating with stakeholders to ensure compliance and security practices.
Information Security Manager responsible for ensuring security of data, systems, and networks at Cayuse. Leading development and monitoring of security policies, practices, and controls.
Cyber Security Engineer II safeguarding systems at MSK, involved with complex technologies in cancer care security. Lead threat investigations and apply technical knowledge for security improvements.
Principal Security Engineer working on network security lifecycle and threat management for Verizon’s 4G/5G Cloud Networks. Collaborating with multiple teams to enhance cybersecurity posture.
Cybersecurity Engineer at Verizon responsible for security lifecycle and effectiveness across networks. Leading incident response and vulnerability management in a hybrid work role.