| Posted Date |
Fri Jun 26, 2009 |
| Closing Date |
Thu Jul 02, 2009 or until filled |
| Salary |
* Negotiable * |
| FLSA Status |
Exempt |
| Department |
Information Resources - Security |
| Job Category |
Information Technology |
| Hours |
8:00 A.M. - 5:00 P.M. |
| Requisition Number |
09002782 |
| Position Number |
34937 |
| Experience & Education Required
(any one of the following): |
1. Bachelor's degree in computer science and technology or related
field. Three (3) years of experience and two (2) years of those
years in an information security position or role. Prior
experience with software or appliances used for vulnerability
scanning, remote system administration, network monitoring
2. and protection, and security notification preferred.
|
| Skills And Abilities |
|
| Security |
This position is security-sensitive and subject to Texas Education
Code §51.215, which authorizes UT Southwestern to obtain
criminal history record information.
|
| Job Duties |
1. Conducts and coordinates risk analysis and risk assessments on
existing and proposed systems, documents findings, and recommends
risk mitigation strategies.
2. Assists departmental technical support staff in identifying and
implementing appropriate security safeguards and coordinates
efforts to ensure compliance with security patch application and
virus protection policies.
3. Directs response to security incidents to prevent additional loss
and to obtain and preserve forensic evidence.
4. Directs root cause analysis efforts to determine improvement
opportunities when failures occur. Maintains a database of
security incidents and provides reports to management and external
regulatory agencies.
5. Maintains a database of registered servers and ensures accurate
information pertaining to data classification and protection
strategies.
6. Assists in the development of information system security standard
configurations using variations of the NIST checklist.
7. Disseminates security notices and alerts to campus technical
support personnel. Coordinates campus-wide information security
collaboration and communication initiatives.
8. Drafts policies and procedures and makes recommendations to ensure
the security of information assets against unauthorized or
accidental modification, destruction, or disclosure.
9. Remains knowledgeable of changes in security technology, industry
practices, and state and federal regulatory requirements.
10. Conducts security training and develops awareness programs and
materials for both technical and non-technical computer users.
11. Presents technical briefings as required.
12. Performs other duties as assigned.
|
| Comments |
|