Unknown Company

Information Security Officer - Air Travel Operations

houston, tx • Posted 2 weeks ago
Onsite Full Time General

Information Security OfficerLocation: Houston, TXType: C2C/C2HJob Description:Under the direction of the City of Houston (COH) Chief Information Security Officer (CISO), duties, functions and responsibilities of this position include:Expand and implement the existing Houston Airport System (HAS) information security risk management strategy and rolling 3-year IT Security Master Plan; ensure IT Security Plan alignment with the COH Cybersecurity Master Plan and controls address the confidentiality, integrity and availability of HAS systems, data and informationDirect an ongoing, proactive risk assessment program for all new and existing HAS systems and remains familiar with HAS’s goals and business processes so effective controls can be put in place for those areas presenting the greatest information security riskOversee all ongoing activities related to the development, implementation and maintenance of HAS’s information security policies and procedures by ensuring these policies and procedures encompass the overall security of Information Technology (IT) and Operational Technology (OT) systemsResponsible for communicating risks and recommendations to mitigate risks to the COH CISO, COH CIO and HAS Director in cost/benefit terms so decisions can be made to ensure the security of information systems and information entrusted to HASEnsure HAS vulnerabilities are managed and mitigated per COH Cyber Division policyAssist with the development of HAS specific, role-based information security awareness training programs, and works with COH Cyber Division, HAS divisions and programs to present to staff as appropriateWork with COH CISO to ensure proper protections, technical and physical controls are in place to protect HAS assets based on cyber industry standards (e.g., NIST 800-53)Work with COH CISO on a design and plan to allow COH Security Operations Center (SOC) visibility into HAS operationsAssist with the development and implementation of an HAS business continuity/disaster recovery plan to offset the impact caused by intentional and unintentional actsResponsible for collecting, analyzing, and escalating security events; aligning with the COH Cyber Division on facilitating proper incident responseResponsible for consuming threat intelligence received from the COH Cyber Division to mitigate identified threats to HAS IT and OT assetsEvaluate security incidents and determines what response, if any, is needed and coordinates with COH CISO and COH Cyber Division on proper responses when critical systems, sensitive data or sensitive information are compromisedAssist the COH CISO with HAS insider threat investigationsRemains competent and current through self-directed professional reading, developing professional contacts with colleagues, attending professional development courses, attending training, conferences, and/or courses as directed by COH CISO, and obtaining certifications relevant to job dutiesAct as the primary liaison to COH IT Security Working Group and makes recommendations to the COH CISO; assists in the implementation of citywide changes to work methods and procedures to make security measures more effective.Requirements:B.A. or B.S. degree in Management and Information Systems (MIS), Computer Science, Engineering or a closely related fieldCertified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), GIAC Security Essentials (GSEC), Project Management Professional (PMP) certifications preferredA strong understanding of both industry and federal government security standards and best practices, such as National Institute of Science and Technology (NIST), Control Objectives for Information and Related Technology (COBIT) for Information Security, and SANS Critical ControlsAt least 5 years of experience developing and implementing cybersecurity plans and controls in a critical infrastructure focused organization.

Strong understanding of the department’s core business functions and business strategy.Responsible for developing a cyber strategy to address the security of IT and OT environment including design, process, and controls with consideration of future regulatory complianceProvides subject matter expertise and coordinating, accumulating, writing/updating of appropriate technological processes and procedures to maintain a secure and operational environmentInterfaces as required with HAS workstation users, HAS server and desktop teams, HAS application support and HAS hardware/software vendors; coordinates projects with users for deadline requirementsParticipate in projects to establish and maintain policies, processes, and controls in compliance of cyber security regulatory standards or best practice frameworks including Center for Internet Security (CIS) and National Institute of Standards and Technology (NIST) where applicableAssist the COH CISO in research, design and implementation of cyber security solutionsAssist in the collection and correlation of data for regulatory or other cyber security related audits or RFI’s (Request for Information)Provide Governance and support for Industrial Internet of Things (Edge, Cloud, etc.)Participate in Cyber Vulnerability Assessments, Penetration Testing, and real activation or tabletop exercises of Incident Response PlansResponsible for pro-actively monitoring and assessing security events through available system logs and security tools and coordination with the COH Security Operations CenterKnowledge and experience with Windows, Active Directory, group policy, DNS, encryption, patch management, anti-virus, system configuration managementKnowledge and experience with LAN, WAN, VPN, routers, firewalls, servers, IDS/IPS, SIEM and DLPSolid expertise in formal/structured IT security risk assessment methodology, including understanding the implementation challenges and advantages across all levels of hardware platforms and software applicationsExperience with a wide variety of operating systems: Windows Server, Windows 10, Windows 7, Linux etc.Knowledgeable of Cyber Kill Chain and Diamond Model of Intrusion Analysis modelsKnowledge of SIEM, IDS, anti-virus/anti-malware and firewall technologiesSolid knowledge and understanding of networking and TCP/IPWell-developed interpersonal skills.

Information Security Officer - Air Travel Operations in houston at Unknown Company

Typical pay
$34,060–$39,520

For context, most security guards earn between $34,060–$39,520 a year according to Bureau of Labor Statistics wage data. What this particular role pays is set by the employer — check the description above.

This position is listed as full time and onsite.

Back to Job Search