Information Security Analyst I - City

Oklahoma City Government

Apply for this job

Job Description

View More Jobs

Information Security Analyst I - City

Oklahoma City, OK, United States

(Hybrid)

Job Description

PAY AND FAIR LABOR STANDARDS ACT (FLSA) STATUS:Pay Range: 516Hourly Rate: $35.81 - $54.80FLSA Status: ExemptThe normal starting pay for this position is the minimum of the pay range listed above. A higher rate of pay may be considered, dependent on the qualifications and experience of the selected applicant and/or the City's step placement policy.APPLICATION, HIRING, AND BACKGROUNDWhen completing the application, applicants will be asked to respond to application questions. These application questions are based on the Job Requirements for the position. Completion of the application questions is required. Applicant responses to the application questions must specifically answer the questions asked. Responses to application questions must be supported by work history/information listed on the application/resume, sufficient to demonstrate qualifications for the position. Applicants may upload only two attachments. Attachments may include, but are not limited to a resume, cover letter, DD214 or NGB Form 22, transcripts, etc. Applicants may also choose to combine documents into one field for upload. Applications may not be reviewed if specific responses to application questions have not been provided.Each application submission is reviewed independently. For detailed information about the City's hiring and background processes, check out the: Quick Guide to Hiring and Background ChecksIf you have questions, check out the: Frequently Asked QuestionsTOTAL REWARDSAt the City of Oklahoma City, our Total Rewards package is designed to honor your service, fuel your growth, and support every part of your life. We offer:Competitive payAn average of $22,000 annually contributed toward your benefits and retirementA comprehensive package designed to support your health and wellness, financial security, work-life balance, and personal and professional growth and developmentExplore all the ways we invest in you: City of Oklahoma City Total RewardsPOSITION DESIGNATIONSThis job classification has been designated as a safety sensitive job classification in accordance with the Oklahoma Medical Marijuana and Patient Protection Act, 63 O.S., § 427.1 et seq., (OSCN 2019), effective August 29, 2019. This means employees in this job classification can be subject to disciplinary action up to and including termination if they test positive for marijuana components or metabolites, even if they possess a medical marijuana license.This job classification has been designated as a cyber security sensitive job classification effective June 26, 2023, in order to comply with United States Department of Justice, Federal Bureau of Investigation, Criminal Justice Information Services (CJIS) Division's Criminal Justice Information Services Security Policy (Version 5.9.2, 12/07/2022), 5.12 Policy Area 12 Personnel Security. The policy requires national fingerprint-based records checks be conducted prior to granting access to criminal justice information for all personnel who have unescorted access to unencrypted Criminal Justice Information (CJI) or unescorted access to physically security locations or controlled areas (during times of CJI processing). Employees in this job classification will be subject to a Criminal Justice Information Services (CJIS) Interstate Identification Index (III) Fingerprint Background check after receiving a conditional offer of employment. Additionally, employees in this job classification must complete the required CJIS Security and Privacy Training and pass the online certification test. JOB SUMMARY This job is located in the Technology Infrastructure Division of the Information Technology Department within the City of Oklahoma City and is under the direction of the Information Security Manager. The Information Security Analyst I will apply and monitor information security systems, tools, policies, and procedures required to protect critical City assets. ESSENTIAL JOB FUNCTIONS Trains professional staff in security impact to specialized City applications and procedures and assists in preforming administrative functions. Identifies unique system configurations to develop standard information security documentation. Adjusts capabilities to prescribed information security controls and countermeasures to mitigate risk to acceptable levels. Audits cybersecurity technology systems and configurations for compliance to frameworks, policies, regulations, and law. Identifies, assesses, documents, tracks, prioritizes, and remediates cybersecurity vulnerabilities. Researches, analyzes, documents, and evaluates software applications and hardware systems. Performs other duties as assigned. VETERANS PREFERENCEHonorably discharged veterans of the United States Active Duty Armed Forces, National Guard, and Reserve Forces who are not currently employed full-time by the City of Oklahoma City and who meet the qualifications for the position shall be given preference. To receive preference, veterans must submit verification of honorable discharge from the United States military service (Department of Defense Form DD214 or NGB Form 22) prior to the closing date of the vacancy announcement. MINIMUM QUALIFICATIONS Bachelor's degree or higher in Management Science and Computer Systems, Management Information Systems, Cybersecurity, or field related to the position; or equivalent combination of education and experience, substituting one year of experience in Cybersecurity for each year of education required. Minimum of four (4) years of experience in Cybersecurity. KNOWLEDGE, SKILLS, AND ABILITIES Knowledge of securing systems, including web, database, and remote access systems. Knowledge of Data Loss Prevention. Knowledge of penetration and vulnerability testing. Knowledge of Security Information and Event Management (SIEM) and other logging systems. Knowledge of enterprise level risk management platforms. Knowledge of Cybersecurity vulnerability risk classification. Knowledge of Cybersecurity incident response. Knowledge of documenting systems, processes, and procedures. Knowledge of and ability to apply administrative and managerial techniques and methodologies. Knowledge of security frameworks and regulatory compliance, such as ISO 27001 or NIST 800. Skill in communicating technical information to non-technical personnel, both verbally and in writing. Ability to work with both internal and external personnel through coordinated efforts. Ability to organize information pertaining to work assignments. Ability to obtain an employer approved security certification within one (1) year. PREFERRED QUALIFICATIONSAdvanced proficiency with SIEM/SOAR ecosystems, including pattern recognition, developing threat hunting queries, building and maintaining playbooks, performing deep log analysis, orchestrating log workflows, and integrating security tools through APIs to enhance automated detection and response.Skill in analyzing suspicious files, email attachments, scripts, and URLs; understanding malicious behaviors; and using sandboxing tools.Ability to analyze PCAPs, review firewall/IDS/IPS alerts, understand protocol behavior, and spot lateral movement or exfiltration patterns.Understanding of modern identity threats, such as token theft, Kerberos-based attacks, credential harvesting techniques, MFA fatigue, OAuth misuse, and attempts to bypass conditional access controls.Expertise in incident scoping, containment and remediation, including executing isolation actions, terminating malicious processes, collecting volatile memory, and validating eradication steps to ensure threats are fully removed.COMPETENCIES One City, One Team (Teamwork/Team Oriented) (1) Recognizes, values, and leverages the ideas, opinions, and perspectives of others; (2) participates willingly and effectively as a team lead or team member; (3) builds consensus; fosters team commitment, spirit, pride, and trust; (4) collaborates with others to accomplish goals and objectives and achieve results; (5) expresses facts, ideas, messages, and information (technical and non-technical) to individuals or groups clearly, concisely, accurately, understandably, with honesty, tact, and diplomacy and in a manner that is appropriate for the intended audience; (6) actively listens, clarifies information as needed; (7) [Core Value One City, One Team] shares information, resources and solutions across departments; (8) [Core Value One City, One Team] asks for help early and offers it often; (9) [Core Value One City, One Team] collaborates across teams before decisions are made.Service First (Customer Centric) (1) Demonstrates commitment to public service; (2) serves and satisfies internal and external customers in a timely and effective manner; (3) establishes, commits to, and maintains high standards for producing quality work products and being responsive to customers; (4) supports the Department/City's mission; develops and executes strategies with the customer in mind; (5) [Core Value Service First] acts quickly and follows through until the job is complete; (6) [Core Value Service First] serves everyone with genuine respect, diligence and professionalism; (7) [Core Value Service First] makes decisions with the people we serve in mind.Respect Always (Leads Through Influence) (1) Persuades others; builds consensus through give and take; (2) gains cooperation from others to obtain information and accomplish goals; (3) works with others towards achieving agreements that may involve exchanging resources or resolving differences; (4) understands the concepts, practices, and techniques used to identify, engage, influence, and monitor relationships with individuals and groups connected to a work effort including those actively involved; (5) leads through influence over the process and its results, and those who have a vested interest in the outcome (positive or negative). (6) [Core Value R

Newest government jobs in Oklahoma