SSAB→
Information Security Specialist at SSAB in Montpelier, IA
Skills
Job Description
This role will work to assisting in the operation of various programs to protect the confidentiality, integrity and availability of organizational assets including data, employees and physical assets from threats. The employee will respond to inquiries about policies, procedures, training, vulnerability reports, and monitor a group Inbox for IT security. This role will assist in operating established programs such as a Global Information Security Awareness and Training program, and a robust vulnerability management program and may be involved in the development of future programs and business practices across all areas of Information Security.
ESSENTIAL FUNCTIONS
Oversee and Govern • Prepare reports to keep organizational stakeholders apprised of security activities. • Plan, coordinate and implement components of existing security programs. • Support training and awareness program, assist in evaluations, planning future curriculum and managing users within the program • Develop detailed security documentation • Document cybersecurity countermeasures and risk mitigation strategies • Train colleagues on security protocols and best practices. Problem Solving Analyze • Determine the validity of trend data. • Advise Information management on risk levels and security posture. • Assess the effectiveness of cybersecurity measures utilized by systems • Develop content for vulnerability assessment tool(s). • Analyzing new methods used by cyber criminals Protect and Defend • Monitor potential targets for unauthorized access or use. • Validate intrusion facts and respond to incidents • Deploy defensive measures for Enterprise Infrastructure • Review results of network scans, conduct threats assessments and rank vulnerabilities based on risk • Determine deviations from baselines, acceptable configurations, assess the level of risks, and recommend appropriate countermeasures. • Work with the vulnerability management team to identify opportunities and assist in the coordination of mitigating countermeasures. • Conduct interviews of victims and witnesses to cybersecurity events. Investigate • Apply Tactics, techniques and procedures for a full range of investigative tools and processes as part of an Enterprise Incident Response team. • Collect, and preserve digital evidence for analysis in support of network vulnerability mitigation and/or criminal, fraud, counterintelligence, supporting internal audit and legal teams. • Test various security strategies and defenses Job Knowledge and Skills • Knowledge of network security and architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth). • Knowledge of basic system, network, and OS hardening techniques. • Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services. • Skill in applying host/network access controls (e.g., access control list). Teamwork • Able to work within a high performing cross-functional team environment • Accountable for own work & deadlines • Coordinate with other team members to resolve issues or complete project tasks Communication Skills • Provide initial user training including user documentation and training materials • Provide manager with weekly status updates and escalate issues if necessary • Communicate effectively with team members and users
QUALIFICATIONS - Education, Experience and Competencies
Required: • Associates degree in the field of computer science and or three years of equivalent work experience. Prior Experience in Networking, Software Development, Systems Engineering, Risk Analysis, Security Intelligence or IT Support. • High level or personal integrity demonstrated by an unblemished career history • Good Communication and management skills • Strong knowledge of written and spoken English, data pre-processing skill and presentation development. • Deeper knowledge of regulatory and compliance requirements. • Vulnerability Assessment skills • Regular and reliable attendance Preferred: • Certificate Program or professional Certificate or Volunteer work supporting information security. • Understanding of the NIST Cyber Framework and similar frameworks • One or more certifications within the information and cyber security area • Understanding of cryptographic solutions and standards.
WORK ENVIRONMENT AND PHYSICAL DEMANDS
• Operate in an office environment, routinely use standard office equipment such as computers, network tools/equipment, phones, photocopiers and scanners. This role is partially sedentary; however, some handling of materials is required. This would require the ability to walk, bend, kneel or stand, use of hands to finger, hold and handle, reach with hands and arms and to push/pull, lift or carry items up to 30 lbs.
POSITION TYPE – WORK HOURS - TRAVEL REQUIREMENTS
• Position is full time, exempt • Position works day shift, Monday through Friday – additional work as needed • Office presence required • Travel up to 10% of time in the field or at other SSAB locations
OTHER DUTIES
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that may be required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. Our Offer SSAB BENEFITS – starting at hire!
● Excellent Pay with Additional Bonus
● Very Affordable Health Insurance
Blue Cross/Blue Shield Medical
CVS/Caremark Prescription
Delta Dental
Superior Vision
● 401(k) with Employer Match – 5%
● Profit Sharing
● 10 Paid Holidays
● Vacation
● Company Paid Life Insurance - and STD and LTD*
● Optional Life, Hospital Indemnity, Critical Illness
● Healthcare and Dependent Care Flexible Spending Account (FSA)
● Tuition Reimbursement
● Employee Assistance Program