Job Title: Cybersecurity and Compliance Specialist
Job Location: Hybrid (San Francisco Bay Area)
Job Type: Contract
Job Summary:
The Cybersecurity and Compliance Specialist will be responsible for the comprehensive security and protection of the Company IT systems. This role encompasses a range of cybersecurity duties, from malware protection to disaster recovery planning, as well as enforcing compliance with relevant guidelines. The specialist will ensure that the client agency’s systems are protected against threats, regularly tested, and compliant with all necessary regulations, including those outlined in the Privacy Handbook.
Key Responsibilities:
Network Vulnerability Scanning and Remediation:
- Perform regular network vulnerability assessments, identifying and addressing security gaps to maintain a secure IT environment.
Security Appliances and Policy Management:
- Oversee the management of security appliances, establishing and enforcing comprehensive security policies and procedures.
Authentication and Authorization Management:
- Manage authentication and authorization systems, including enforcing Multi-Factor Authentication (MFA) to enhance system security.
Access Control:
- Maintain access control permissions for systems, applications, and data to ensure only authorized personnel have access to sensitive information.
Disaster Recovery and Business Continuity Planning:
- Develop, implement, and maintain a full disaster recovery and business continuity plan for both local and off-site data recovery.
Disaster Recovery Testing and Backup Maintenance:
- Conduct regular disaster recovery testing and continuous monitoring and maintenance of all backup systems to ensure data integrity.
Malware Protection:
- Implement and manage malware protection across all systems to prevent unauthorized access and cyber threats.
Patch Management:
- Conduct regular patch management for Microsoft and non-Microsoft software, ensuring all systems are up-to-date with the latest security updates.
End-User Security Awareness Training:
- Provide training and resources to end-users, increasing awareness of security best practices and preventing potential security breaches.
Compliance Management:
- Ensure that the client agency complies with all relevant security compliance requirements, including those outlined in the Privacy Handbook.
Qualifications
- Education: Bachelor’s degree in Cybersecurity, Information Technology, or a related field. Relevant certifications (e.g., CISSP, CISM, CompTIA Security+) are preferred.
- Experience: Minimum of 10+ years in cybersecurity, with a strong focus on vulnerability management, disaster recovery, and compliance.
- Skills:
Deep understanding of cybersecurity principles, including malware protection, vulnerability management, and disaster recovery.
Experience with security policies, authentication systems, and access control.
Familiarity with compliance standards and regulations, particularly in a public sector or related environment.
Strong communication skills for end-user training and awareness initiatives.