Information Technology Specialist (Information Security Officer)
Oakland, Ca
• Assures implementation, monitoring, maintenance and enforcement of the Information Security Program.• POC for VA Security Control Assessment (SCA) performed by Deloitte. SCA is part of the NIST Risk Management Framework (NIST 800-37). Uploaded POAM, SOP’s, artifacts and documentation into RiskVision.• Plans, establishes, and implements local policies and procedures to ensure IS reliability and accessibility.• Conducts system security evaluations, audits, and reviews.• Develop and review privacy impact assessments, incident response plans, and risk assessments- assesses security incidents to determine impact and initiates corrective action per NIST SP 800-53, Rev 4. • Takes appropriate measures to resolve and report incidents, as required.• Advise director on all facets of IS and recommends resolution of issues when appropriate. • Authorize access to various applications and information systems.• Works with IT Operations and business staff to develop, update, and implement a facility security policy, local circular or standard operating procedures that define implementation of national policies for information security• Performs daily, weekly, monthly, quarterly, bi-annual, and annual audit reports to review controls, activities, vulnerabilities, and purge the system of obsolete records• Reporting and escalating issues as appropriate