
Cyber Security Specialist (ERP) (Temporary)
- Portland, OR
- Temporary
- Full-time
Under the direction of management, the incumbent serves as a technical expert in the area of cybersecurity and the tools and processes required to protect PCC’s cyber assets and its user community. The incumbent provides project coordination to ensure the highest levels of information security, identifying the necessary methods, solutions, and practices. The Cybersecurity Specialist works with other teams at PCC to develop training materials and communicate new concepts in cybersecurity.This position is responsible for implementing and coordinating major segments of PCC’s enterprise security portfolio. The incumbent takes a lead role in detecting, remediating, protecting and maintaining information security on a district level.What You'll Do and Who We Are Looking ForSuccess Criteria:These qualifications, skills and abilities are critical for success in this position.
Throughout the screening process, you will be evaluated based on the demonstration of these qualifications.
- Successful experience with Cyber analytics techniques including threat hunting and forensics analysis; investigating and remediating cyber incidents; implementing, configuring, operating and trouble-shooting security tools (for example, Vulnerability Management, SIEM, endpoint agents, CASB, etc.) to detect, research, analyze, respond to, and mitigate information security-related vulnerabilities, threats and incidents
- Demonstrated collaboration and communication skills to partner and align with users at all technical skill levels and roles across the organization
- Comprehensive knowledge of the cyber security landscape, cyber security product categories and available technologies. Able to relate and apply this knowledge to their work.
- Experience in compliance with regulatory requirements, security and privacy laws and Frameworks; including, but not limited to, PCI, SOX or GLBA, HIPPA, ISO 27001/2, NIST, or IRS Publication 107
- Understanding of project lifecycle management, including demonstrated experience coordinating a technical project, working with a project team, and influencing without direct authority
- Responds to cybersecurity incidents, and acts as escalation point for high-priority or highly complex incidents.
- Coordinates the day-to-day operations of PCC’s information security and data structures by overseeing the operational performance of PCC’s security systems.
- Implements, monitors, and operates intrusion detection systems, intrusion prevention systems, SIEM, and other tools to detect, research, analyze, respond to, and mitigate information security-related vulnerabilities, threats and incidents.
- Evaluates current and future security-related requirements. Develops or recommends technical and operational solutions to enhance PCC’s cyber incident response capability.
- Performs software upgrades, defines performance criteria, and documents configurations and system specifications.
- Provides secure implementation guidance and governance throughout project life cycle. Identifies and ensures security issues are understood and addressed.
- Assists management in the development of incident control documentation, cyber incident response procedures, and other standards, policies, and procedures.
- Works with customer and peer organizations to perform research, testing, evaluation, and implementation of security procedures.
- Trains and guides staff on cybersecurity, response practices, tools, and capabilities.
- Acts as a resource to other departments within the College.
- Remains current on best practices, threat intelligence and technology advances in the areas of cybersecurity.
- Acts as the college’s technical resource for cybersecurity. Installs, configures and tests security related technologies.
- Troubleshoots and corrects security and data related problems.
- Monitors the work of service providers and/or contractors engaged by PCC.
- Provides regular and special reporting, including reports of risks, control deficiencies, remediation strategies, and performance metrics. Performs other duties as assigned.
- Help with Workday ERP Security matrix
- High school diploma or equivalent
- Associate’s Degree in Computer Information Systems or related discipline (Relevant experience may substitute for the degree requirement on a year-for-year basis.)
- Four years of applied work experience in cybersecurity, such as developing and deploying security related tools and infrastructure, monitoring and remediating security threats, and implementing active cyber defense and operational practices
- CISSP, CCNA, CISA, and/or GIAC or comparable certification
- Proven leadership in project management
- Understanding of connections among technology, the organization and leadership in relation to business processes and problem resolution
- Experience of compliance with regulatory requirements, laws and frameworks, including, but not limited to PCI, SOX, GLBA, HIPPA, ISO 27001/2, NIST, or IRS Publication 1075
- Experience in the following:
- log collection and analysis
- investigating cyber incidents and remediating
- operating and trouble-shooting security tools (SIEM, endpoint agents, CASB, etc.,)
- conducting third-party risk assessments
- vulnerability and patch management
- threat intelligence and risk assessment
- Functional knowledge of at least one scripting language