Job ID: ID:760291 (99690402)
Hybrid/Local Security Analyst (CISSP/CISM/CISA/GIAC/GCIH/CompTIA Security+/CEH/12+) with IDS/IPS, SIEM, EDR/MDR, Vulnerability management, NIST CSG, CIS, GDPR, HIPAA, AWS/Azure/GCP experience
Location: Boise, ID (Idaho Judicial Branch – Administrative Office of the Courts – IT)
Duration: 4 Months
Skills:
Incident response Required 5 Years
Firewall, IDS/IPS Required 3 Years
SIEM Required 2 Years
Endpoint Detection and Response (EDR), Managed Detection and Response (MDR) Required 2 Years
Vulnerability management Required 2 Years
Security Awareness and Training Required 1 Years
Compliance with and assessment against security frameworks such as NIST 800-53, NIST CSG, CIS Top 18 Required 3 Years
Cloud security Required 1 Years
Project management Highly desired 1 Years
Certifications such as CISSP, CISM, CISA, or GIAC GCIH Nice to have 1 Months
Exceptional communication skills (both written and verbal) are required for this position. Required
Description:
The Idaho Judicial Branch is seeking a highly skilled Cybersecurity Specialist to join our team. The position plays a key role in assessing, strengthening, and documenting the cybersecurity posture of our organization.
IMPORTANT NOTES – Read Fully:
1 – This is ONLY budgeted as a 4-month position. Candidates you submit MUST be aware of this and MUST be Ok with accepting a position that will only run for 4-months in duration.
2 – This position requires ONSITE work in a hybrid schedule. Ideally the client would like someone who can be there 3-days per week onsite, however they can be somewhat flexible with the onsite schedule. Fully remote is NOT an option for this position. Please only submit candidates local to Boise who are able to commit to working onsite in a hybrid schedule.
3 – Please answer all questions in the Questions section appropriately. If you do not answer the questions as required, your candidate will not be considered for screening.
JOB DETAILS:
This Cybersecurity Specialist will be responsible for implementing security best practices, identifying vulnerabilities, and ensuring compliance with legal and regulatory requirements. The position requires strong documentation and writing skills as well as the ability to collaborate effectively with IT, cybersecurity, and business stakeholders.
Key Responsibilities:
Cybersecurity Risk Assessment & Remediation: Conduct thorough assessments of the organization’s current security posture, identifying vulnerabilities and implementing remediation measures to mitigate risks.
Security Architecture & Solution Design: Assist in designing and implementing security controls and systems to protect critical assets, data, and networks.
Incident Response Support: Support incident response efforts by identifying and addressing potential security threats, conducting root cause analysis, and assisting with incident reporting and recovery efforts.
Documentation & Reporting: Create and maintain clear, detailed security documentation, including policies, procedures, and incident reports. Ensure that security measures are clearly documented for internal and external stakeholders.
Collaboration with Stakeholders: Work closely with IT, cybersecurity teams, and business units to ensure alignment of cybersecurity initiatives with organizational goals and regulatory requirements.
Compliance Assurance: Ensure that cybersecurity policies and practices are aligned with applicable legal and regulatory requirements (e.g., GDPR, HIPAA, NIST).
Training & Awareness: Provide support for developing training materials and conducting awareness sessions on security best practices for various stakeholders across the organization.
Security Monitoring: Assist in configuring and monitoring security tools (e.g., SIEM, IDS/IPS, EDR) to proactively detect and mitigate security threats.
Required Skills and Experience:
Cybersecurity Expertise: A minimum of 4-6 years of hands-on experience in the field of cybersecurity, with a strong understanding of threat detection, vulnerability management, risk assessment, and incident response.
Technical Proficiency:
· Experience with SIEM tools, IDS/IPS systems, firewalls, endpoint protection, and network security.
· Familiarity with data encryption techniques, secure network design, and cloud security principles.
Strong Documentation & Writing Skills:
· Proven ability to create clear, concise, and detailed documentation, including incident reports, security policies, procedures, and technical designs.
· Ability to communicate complex security concepts to both technical and non-technical stakeholders in an understandable and actionable way.
Compliance & Regulatory Knowledge:
· Knowledge of key cybersecurity frameworks and compliance requirements, such as NIST, ISO/IEC 27001, GDPR, and HIPAA.
· Experience ensuring security measures meet regulatory and legal standards.
Collaboration & Communication Skills:
· Strong interpersonal and communication skills to effectively collaborate with cross-functional teams (IT, legal, compliance, and business units).
· Ability to work with stakeholders to understand business needs and align security initiatives accordingly.
Risk Management & Incident Response:
· Experience in identifying and managing cybersecurity risks, as well as responding to and mitigating security incidents.
· Ability to support incident response and assist with post-incident analysis and reporting.
Preferred Skills and Experience:
· Certifications: Relevant certifications such as CISSP, CISM, CISA, CompTIA Security+, CEH (Certified Ethical Hacker), or similar.
· Cloud Security: Experience securing cloud environments such as AWS, Azure, or Google Cloud, and using cloud-native security tools.
· Attention to Detail: Precision and accuracy in documentation, analysis, and implementation of security measures.
· Adaptability & Problem Solving: Ability to quickly adapt to new security challenges, troubleshoot complex issues, and come up with effective solutions.
· Project Management Skills: Ability to prioritize tasks, manage deadlines, and work independently or as part of a team to achieve objectives in a timely manner.
· Analytical Mindset: Ability to assess security risks and vulnerabilities and develop strategies for remediation.