Security and Compliance Specialist
Information Technology
FLSA: Non-Exempt
JOB SUMMARY
This position is responsible for assisting in the development and enforcement of the county’s cybersecurity policies, practices, and regulatory compliance efforts. The Security & Compliance Specialist monitors daily security events and supports in collaboration with other IT personnel. Emphasis is placed on foundational security knowledge and continuous learning to stay updated on emerging threats.
MAJOR DUTIES
Policy & Procedure Assistance:
- Supports the CIO in creating or updating cybersecurity policies aligned with relevant standards (e.g., NIST, CJIS, PCI DSS).
- Contributes to compliance audits and helps prepare documentation for external or internal reviews.
Security Event Monitoring:
- Monitors alerts from tools such as Endpoint Detection and AI Security Tools; identifies anomalies or potential threats.
- Coordinates with vendors to verify, document, and escalate alerts as necessary.
Incident Response Support
- Assists in investigations for security incidents, gathering logs and evidence for analysis.
- Works under guidance from senior staff or external Security Operations Center resources on containment, eradication, and recovery steps.
- Documents incidents and lessons learned in a centralized repository.
Vulnerability Management
- Runs vulnerability scans or reviews scan reports; recommends patching priorities to the Systems/Network Admins.
- Tracks remediation progress and follows up on open vulnerabilities.
User Awareness & Training
- Helps organize security awareness training sessions, including phishing simulations and educational resources.
- Support Cybersecurity committee activities
- Responds to user queries about security policies, basic best practices, and safe handling of data.
Compliance Monitoring
- Assists in maintaining records for regulatory frameworks (e.g., CJIS, HIPAA, PCI as applicable) and addressing any identified gaps.
- Prepares preliminary compliance reports for CIO review and external audits.
Documentation & Reporting
- Maintain a detailed log of security events, vulnerabilities, and compliance assessments.
- Generate periodic reports for the CIO, highlighting emerging threats, key findings, and actionable recommendations
KNOWLEDGE REQUIRED BY THE POSITION
- Knowledge of multiple computer systems, programs, and architecture.
- Knowledge of the principles and techniques of computerized information management, including system design and analysis, hardware and software, database applications, and network applications and capabilities.
- Knowledge of computer industry trends and standards.
- Knowledge of internet and worldwide web protocols.
- Knowledge of SQL server maintenance.
- Knowledge of cloud computing and the use of cloud techniques.
- Knowledge of cyber security principles.
- Skill in troubleshooting and resolving computer hardware and software problems.
- Skill in problem solving.
- Skill in prioritizing and planning.
- Skill in interpersonal relations.
- Skill in directing the work of personnel.
- Skill in oral and written communication.
SUPERVISORY CONTROLS
The Chief Information Officer assigns work in terms of department goals and objectives. The supervisor reviews work through conferences, reports, and observation of department activities.
GUIDELINES
Guidelines include industry best practices; manufacturer installation, operations, and repair manuals; NIS policies; and department and county policies and procedures. These guidelines require judgment, selection, and interpretation in application.
COMPLEXITY/SCOPE OF WORK
- The work consists of varied systems administration duties. Frequent changes to industry standards and the variety of systems to be managed contribute to the complexity of the position.
- The purpose of this position is to administer the county’s information technology systems. Successful performance contributes to the efficiency and effectiveness of a variety of county operations.
CONTACTS
- Contacts are typically with coworkers, vendors, contractors, and the general public.
- Contacts are typically to exchange information, resolve problems, motivate persons, and provide services.
PHYSICAL DEMANDS/ WORK ENVIRONMENT
- The work is typically performed while sitting at a desk or table or while intermittently sitting, standing, or stooping. The employee occasionally lifts light and heavy objects and distinguishes between shades of color.
- The work is typically performed in an office.
SUPERVISORY AND MANAGEMENT RESPONSIBILITY
None.
MINIMUM QUALIFICATIONS
- Education: Associates degree or Bachelor’s degree in Information Technology, Computer Science, or related field (or equivalent experience).
- Experience: 2-4 years of IT support experience (help desk, technical internship) with exposure to servers, virtualization, or networking.
- Certifications: Preferred certifications include CompTIA A+, Network+, or Server+; Microsoft MTA or M365 Fundamentals.
- Skills: Strong understanding of Windows Server, virtualization platforms, scripting (PowerShell), backup and recovery solutions, and system security protocols.
- Possession of or ability to readily obtain a valid driver’s license issued by the State of Georgia for the type of vehicle or equipment operated.