Explore a World of Opportunity with the State of Georgia!
We are the force that drives Georgia!
Georgia State Government is a large enterprise, composed of various agencies and entities with a common goal to improve the lives of Georgia's more than 10 million citizens!
Join Team Georgia and impact lives everyday while receiving a robust benefits package designed for every stage of your career!
Job Title:
Cybersecurity Specialist 2, GETS (GTA)Job Requisition ID:
JR0000001745Number of Openings:
0Shift:
Compensation Details:
$70,800 - $91,000Job Description:
Start your career in public service – JOIN OUR TEAM
Georgia Technology Authority (GTA) a Great Place to Work® certified!
The Georgia Technology Authority (GTA) is currently seeking a Cybersecurity Specialist 2 – in the Office of Information Security.
The Georgia Technology Authority (GTA) currently manages the delivery of IT infrastructure services to 89 Executive Branch agencies and managed network services to more than 1,200 state and local government entities. IT infrastructure services encompass mainframes, servers, service desk, end user computing, disaster recovery and security. Managed network services include the state’s wide and local area networks, voice, cable and wiring, and conferencing services.
Want to know more about our AWARD-WINNING Authority visit: https://gta.georgia.gov/
JOB SUMMARY: The GETS Cybersecurity Specialist 2 serves within the Georgia Enterprise Technology Services (GETS) Program, reporting to the Office of Information Security (OIS) and working under the direction of the GETS Security Program Office Director. This role is responsible for supporting statewide security, risk, and compliance initiatives across the GETS environment in close collaboration with service tower providers, agencies, and the Multi-Sourcing Service Integrator (MSI).
The specialist will assist in coordinating and implementing cybersecurity policies, procedures, and risk management standards, ensuring alignment with operational service delivery. This includes supporting governance functions and cross-functional security efforts related to system operations within the GETS framework.
This position will report directly to the GETS Security Program Office Director.
Job Responsibilities:
- Support overseeing the security, risk, and compliance services with Service Tower Providers in the development and implementation of programs, initiatives, security standards and practices to meet strategic risk management and security goals and objectives
- Support the management of all enterprise security related projects/issues of high complexity that require in-depth knowledge across multiple technical areas and business functions
- Ensuring efficient service delivery of security services of GTA and GTA Customers technical environments, including assistance with oversight responsibility for the managed services being delivered by service providers and to ensure efficient execution of all IT processes and meeting of service level requirements for the technical environment
- Evaluate and recommend risk and security mitigation strategies, techniques, and practices
- Support the development of GETS security processes to strengthen security measures and improve effectiveness and increase efficiency of the overall processes
- Serve as a security subject matter expert in the areas of strategic risk management, cybersecurity, and risk mitigation. Responsibilities include managing, providing direction and oversight of Service Tower Providers and the Multi Services Integrator.
- Support continuous monitoring, assessing, and reviews of the environment to safeguard resources and information assets across the GETS security program
- Advises GETS security management on technology, information system policy matters, and maintains continuous lines of communication by keeping the GETS Security program Director, Office of Information Security leadership, and agency ISOs informed of all critical information security issues.
- Responsible for privilege access management process and activities regarding PAM for the GETS security program.
- Serve as the main point of contact for all Firewall change reviews, discussions, and tasks.
- Serve as the main point of contact for all GETS architectural and requirements gathering reviews, discussions, and tasks.
- Responsible for review of monthly security reports provided to GETS Security Director by the Service tower providers.
The expected attainments through the Oversight, Integrator, Service Tower Provider, and GTA Customers dynamic includes:
- Support the EGRC functionality and process improvement around risk management for the GETS Security program
- Assists in the development and adoption of enterprise, policies, standards and procedures.
- Assist the GETS Security Office Director in the oversight activities of vendor security management for GETS vendors according to prescribed GTA standards
- Monitors and maintains GETS Security Messaging queues for the necessary security approvals
- Provide updates and/or escalations to GETS Security Director regarding audit performance and findings
- Assists with driving remediation efforts with the Service Tower Providers risk mitigation efforts
- Assess Service Tower Providers and agencies for compliance with policies and procedures
- Assists in internal and external client audits as it relates to IT security and compliance
- Assists with third-party IT assessments
- Assists in the development and implementation of information security programs relating to risk mitigation, security awareness and education, incident response, network and computer forensics, policy development, risk assessment, vulnerability scanning, trend analysis, certification and accreditation
- Reviews and provides improvements to existing processes, standards, risk, and security strategies related to information security management for GETS
- Provides guidance to project teams to help them comply with enterprise and IT security policies, industry regulations and best practices
- Identifies risk areas and implements methods for auditing and resolving non-compliance to information security standards
- Analyzes business impact and exposure based on emerging security threats, vulnerabilities, and risks
- Assists in the management of complex security issues, techniques, and implications across multiple environments
- Supports GETS Security Program Director in all activities related to the planning of information security management strategies, goals, and objectives
- Analyzes current trends and developments in the statewide environment to recommend strategies, actions and technologies to maintain a competitive advantage for an effective, efficient security posture
- Assists the GETS Security Office Director in the planning and implementation of security management initiatives for the GETS security program
- Acts as point of contact to agency customers to provide guidance on information security management issues
- Maintains relationships with agency information security and IT personnel, communicates office goals and objectives to internal and external stakeholders, and solicits feedback
- Serves as a Subject Matter Expert (SME) on the design, implementation, and review of security architecture for new technology project (s) whether on premise or cloud hosted environments.
- Performs other duties as assigned.
CORE Competencies
- Strong analytical, strategic, and tactical thinking skills to identify and drive decisions by appropriately escalating security issues
- Ability to adapt quickly in a dynamic and complex environment
- Ability to troubleshoot complex issues and problems to quickly determine effective resolutions
- Proficiency in project management processes
- Strong, oral and written communication skills with ability to understand technology sufficiently to clearly communicate the complexity in simple terms for key stakeholders
AGENCY SPECIFIC QUALIFICATIONS:
Minimum Qualifications:
- Bachelor’s degree in Information Security, Information Assurance, Computer Science, Information Systems, Information Technology, or a related field
- Three (3) years’ experience in information/cybersecurity, cybersecurity regulatory compliance, risk management which includes third party risk management, and cybersecurity program management
- Proven experience in:
- Governance, Risk, AND Compliance (GRC)
- Third party vendor risk management and vendor oversight
- Cybersecurity program management to include but not limited to Incident management and response oversight
- Vulnerability Management and oversight
- Identity and Privileged Access Management (IAM/PAM)
- Current entry level cyber certification per state guidelines (i.e. ((ISC)² Certified in Cybersecurity (CC), Security+, Network+, Microsoft SC-900 (Security, Compliance, and Identity Fundamentals), GISF*) Any GIAC certified entry level certification accepted or certified within 12 months of start date.
Note: An equivalent combination of education and job-specific experience that provided the knowledge, experience, and competencies required to successfully perform the job at the level listed may be substituted on a year-over-year basis.
Preferred Qualifications:
(Preference will be given to candidates who, demonstrate some or all of the following skills/experience):
- Proven advanced proficiency in managing third-party service providers across multiple service towers, including providing direction and oversight to Service Tower Providers.
- Proven advanced proficiency in Governance, Risk, and Compliance (GRC); vulnerability management; incident response; Security Operations Center (SOC) operations; Security Information and Event Management (SIEM) technologies; and security automation platforms.
- Proven proficiency with Enterprise GRC platforms (e.g., ServiceNow).
- Demonstrable ability to tailor risk methodologies and frameworks to business requirements.
- Proven advanced knowledge of cybersecurity NIST best practices, frameworks, and Special Publications, NIST FIPS (FIPS-199, FIPS-200, FIPS-140-2, FIPS-140-3), FedRAMP, ISO 27000 Series, CIS CSC, and regulatory requirements for FISMA, HIPAA, CJIS, SSA, PCI-DSS, and FTI.
- Project management experience preferred.
- Demonstrable working knowledge of major cloud platforms (AWS, Azure, Google Cloud) and enterprise network technologies, including engineered network security solutions.
- Proven advanced proficiency with Identity and Privileged Access Management (IAM/PAM) security practices and platforms (e.g., Okta, MSAAD, SailPoint).
- Professional certification beyond minimum: (CISSP, CISM, GSEC, CISA, CRISC, CGEIT, CAP, CASP+).
- Knowledge of security practices related to AI technologies.
COMPENSATION/WORKER TYPE/ADDITIONAL DETAILS:
Location: Atlanta, GA (Capitol Hill)/Fulton County
Hiring Salary: *$70,800 - $91,000
Worker Type: Hybrid – State of Georgia Remote Work Option
*Current Georgia state government employees will be subject to SPB rule provisions.
EARN MORE THAN A SALARY! In addition to a competitive salary, the Georgia Technology Authority offers a generous benefits package, which includes employee retirement plan; paid holidays annually; vacation and sick leave; health, dental, vision, legal, disability, accidental death and dismemberment, health and childcare spending account; in addition to telework opportunities depending upon position. More information on Benefits: https://team.georgia.gov/my-benefits/
Due to the volume of applications received, we are unable to provide information on application status by phone or e-mail. All qualified applicants will be considered but may not necessarily receive an interview. Selected applicants will be contacted by the hiring agency for next steps in the selection process. Applicants who are not selected will not receive notification.
Georgia Technology Authority does not discriminate in employment on the basis of race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or other non-merit factor.
Minimum Qualifications:
Equal Employment Opportunity Employer
The State of Georgia does not discriminate based on race, color, national origin, sex, religion, age, disability, or other protected categories in employment or the provision of services.
Qualified applicants may request reasonable accommodation when needed during the application and/or screening process by contacting the appropriate agency Human Resources department.