Chief Information Security Officer
Location: Columbia MD
Duration: 12 months extendable.
Visa: Visa independent candidates only.
Locals to Columbia MD are needed.
Job Description:
The candidate must possess at least 10 years of experience in
IT securityrelated roles such as security analyst network administrator or
similar positions.
Leadership: The Contractor must possess experience in management or
leadership roles as CISOs need to lead teams and make strategic decisions.
Perform a detailed cyber risk assessment that includes the following but not limited to:
Identifying estimating and prioritizing information cyber security risks ;
Examining HCCs current technology security controls policies and procedures to
assess potential threats or attacks; and
Evaluating HCCs threat landscape vulnerabilities and cyber gaps that pose a risk to
its assets.
B. Act as HCCs Qualified Individual (QI) to present quarterly reports to HCC Board of
Trustees and leadership as required and specified by GLBA.
C. Develop an information security program using a framework such as National Institute of
Standards and Technology (NIST) 80053 Center of Internet Security (CIS) Critical
Security Controls or CIS Implementation Group 1 (IG1) that protects HCC in accordance
with GLBA security requirements.
D. Provide information security leadership communication investigation mitigation
containment and postincident analysis in the event of a cyber incident.
E. Update and enhance existing cybersecurity policies and procedures as required by GLBA.
The policies include but not limited to:
1. Vulnerability management
2. Data management
3. Incidence response
4. Software management
5. Hardware asset management
F. Provide guidance when analyzing realtime threat analysis identified by HCCs security
operations center.
G. Perform thirdparty and partner evaluations Higher Education Community Vendor
Assessment Toolkit (HECVAT).
H. Develop and implement the strategy to conduct regular security audits and assessments to
identify vulnerabilities and ensure compliance with security policies.
I. Write a clear and concise incident response plan that meets industry standards.
J. Participate in meetings as needed. (i.e. weekly monthly quarterly ad hoc etc). Under
normal circumstances inperson meetings are not required. In the event of an incident or
breach an inperson meeting may be required.
Preferred certifications:
. Certified Information Systems Security Professional (CISSP)
Certified Information Security Manager (CISM)
Certified Information Systems Auditor (CISA)
...Craft Beer and Food! Vibrissa Beer is a production brewery and kitchen in historic Front Royal. We feature a full-service kitchen that specializes in upscale pub fare as well as nationally award-winning beer. Join our kitchen team in our Front Royal location. As a...
...Job Summary : We are seeking a motivated and customer-focused individual to join our team as a Remote Customer Service and Sales Associate. In this role, you will be... ...promptly to customer inquiries via phone, email, and virtual meetings. ~ Provide accurate information...
...Mount Vernon, NY Certified Nuse Midwife Job#16558534 Eligibility for Public Service Loan Forgiveness and National Health Service Corps... ...midwife license and certification from the American College of Nurse-Midwives. Southern New York offers a rich array of recreational...
Cinwaanka jagada: Khabiirka MaamulkaSoo Koobid Shaqo: Khabiirka Maamuleed wuxuu mas'uul ka yahay abaabulka iyo fulinta howlaha gaarka ah ee howlaha maamulka ee loogu tala galay Cuntada Qiyaasta 'Metro Meals on Wheels'.Khabiirka Maamulka waa shaqo waqti-buuxa ah oo u...
...experience driving critical cross-organizational programs? Are you equally comfortable digging in to... ...Business (B2B) market is ripe for innovation, and Amazon Business ( is looking for a Senior Technical Program Manager. This team is reshaping buying in the B2B world...