Responsibilities
- Adhere to established information security policies, procedures, and operational guidelines.
- Create and revise documentation for information security processes and protocols.
- Collaborate with the Office of Innovation and Technology to deploy, manage, and maintain security systems and related software, including firewalls, intrusion detection, encryption, and antivirus solutions.
- Manage user accounts, access permissions, and authorization levels for systems and applications.
- Secure network connections for local area networks and public-facing websites.
- Protect databases and ensure secure internal and external data transmissions.
- Analyze findings from penetration testing and work with application owners to resolve vulnerabilities.
- Implement corrective measures to prevent recurrence of security incidents and recommend improvements.
- Prioritize and manage multiple security issues, track tickets, and ensure timely resolution.
- Conduct research on emerging security threats, tools, and mitigation techniques as assigned.
- Provide security expertise and guidance for IT projects within the department.
- Contribute to the development and evaluation of RFPs and contracts for security-related tools and services.
- Promote a service-focused culture while upholding network security standards.
- Demonstrate the ability to locate accurate information and solutions independently.
- Leverage available tools and resources to effectively resolve security-related inquiries.
- Develop and sustain cooperative relationships with internal teams, external vendors, and technology partners involved in security operations.
- Gain familiarity with operational workflows and technical requirements of supported systems within the department and partner offices.
- Engage in regular planning and prioritization discussions with senior IT leadership and key stakeholders.
- Advocate for security priorities and technology requirements within the IT organization.
- Monitor security projects and services, assess performance against SLAs, and report on outcomes and user satisfaction to leadership.
Responsibilities
- Follow documented information security policies, processes, and procedures.
- Document new information security processes and update existing information security.
- Coordinate deployment, management, and maintenance of all security systems and their corresponding or associated software, including firewalls, intrusion detection systems, cryptography systems, and antivirus software with the Office of Innovation and Technology (OIT).
- Administer and maintain end user accounts, permissions, and access rights.
- Manage connection security for local area networks and DPH web sites.
- Manage and ensure the security of databases and data transferred both internally and externally.
- Review results of penetration tests and collaborate with application owners to mitigate or eliminate identified risks and vulnerabilities.
- Identify and implement necessary improvements to prevent incidents from recurring and proposing appropriate solutions and/or next steps.
- Prioritize information security issues, work on multiple tickets concurrently, monitor existing tickets, and manage resolution.
- Research information security topics, tools, techniques, and threats as directed.
- Serve as an information security resource on DPH IT projects.
- Participate in RFP/contract development and review for tools and services specifically related to DPH Security Operations.
- Actively promote a customer-oriented approach to maintain a secure DPH network.
- Know how to find answers.
- Understand available tools and resources to determine correct answers to security issues.
- Build and maintain collaborative and consultative relationships with OIT, DPH Divisions/Units as well as vendors related to DPH operational security systems and processes being managed and or supported by DPH Health IT and OIT Operations Security Teams.
- Gain an understanding of OIT and DPH processes and requirements as they relate to the DPH supported systems.
- Conduct regular reviews, priority-setting, and planning sessions with the Health IT Director, the Health IT Infrastructure Manager, the Health IT Enterprise Data Services Manager, and other stakeholders.
- Serve as an advocate for those priorities, plans, and other technology needs within DPH Health IT.
- Monitor, evaluate, and regularly report to Health Director on IT security related IT projects, services, and support; the delivery of services according to service level agreements; and levels of client satisfaction.