Information Security and Compliance Specialist

2 weeks ago


Olympia, Washington, United States DevSelect Full time

Title:
Information Security and Compliance Specialist

Reports to:

CIO

Salary:
DoE

POSITION SUMMARY
This role is situated within the Digital Services division of DevSelect.

The Information Security and Compliance Specialist collaborates closely with the
CIO and CISO to manage and synchronize daily operations related to information security and compliance initiatives, policies, standards, and procedures across the organization.

This position is accountable for strategizing, influencing, and coordinating the company's information security policies, establishing procedures and guidelines to ensure that all information systems are operational, secure, and protected throughout the organization while adhering to applicable privacy and information security laws and regulations relevant to the retail sector.

Moreover, the Information Security and Compliance Specialist is tasked with leading during security incidents and ensuring the technical and administrative support for the formulation of Disaster Recovery and Business Continuity plans for the organization.

The incumbent interacts with the Information and Digital Services Core IT Operations team regarding security and compliance operational controls. Additionally, the incumbent serves as an internal consultant to the organization on matters concerning security and compliance.

RESPONSIBILITIES
- Assess acceptable risk levels for the enterprise and guarantee that IT environments are sufficiently safeguarded against potential risks and threats.
- Engage in the development and execution of suitable and effective controls to mitigate identified threats and risks.
- Assist in tactical follow-up on identified security issues and drive the design and implementation of solutions to diminish security risks.
- Lead the research, development, and communication regarding Security and Compliance matters, by maintaining and collaborating with operational units on the enforcement of IT security architecture, policies, procedures, solutions, and standards.
- Participate in and provide specific IT security-oriented leadership during incident response planning and the investigation of security breaches, and assist with disciplinary and legal matters associated with such breaches as necessary.
- Stay informed and advise the organization on the latest industry security and compliance best practices and technologies.

- Collaborate with Business Owners to analyze, document, and define requirements related to new development or maintenance and enhancements to existing security roles and permissions.

- Deliver services that comply with regulatory specifications.

- Work with internal and external auditors to document and confirm that all security administrative duties are properly executed and demonstrate overall compliance.

Qualifications
- A minimum of 5 years of operational and strategic experience in IT controls and information security, IT compliance, networking security, or IT audit is required.
- Experience in artifact management, including the development and maintenance of Policies, Standards, and other supporting documentation.
- Proficiency in documenting and maintaining the details of IT remediation projects, committee meetings, and findings from security testing and assessment projects.
- Operational experience with IT compliance requirements and processes, particularly PCI DSS and related PCI industry controls, mitigations, and incident responses.
- Operational experience in the inventory and classification of IT assets, and their update and maintenance.
- Experience in access control and identity management, including principles and management of access to network infrastructure, server platforms, Active Directory domains, and databases.
- Ability to provide subject matter expertise in configuration management and maintenance of access control and assessment for these systems.
- Knowledge of RADIUS, LDAP, and Cloud SSO solutions is advantageous.
- Skilled in the principles and management of key management and encryption systems for information in transit and at rest. Extensive knowledge of both symmetric and asymmetric cryptographic systems.
- Demonstrated extensive experience with vulnerability management.

Education
- 4-year college degree or demonstrated equivalent experience with appropriate time-in-role, with subject matter majors in Computer Science, Information Management, Information Security, or equivalent disciplines.
- A SANS, CISSP, or other equivalent industry-recognized Security certification is required.
- Additional certifications in IT audit or IT controls design and management are preferred.
- CObIT and/or ITIL certifications, education, or equivalent experience with control and operational frameworks are a strong plus.

Technical Skills
- Information security assessment and auditing procedures from both technical and business perspectives, and the use of formal methodologies such as NSAIAM Vulnerability scanning and auditing tools.
- Enterprise-scale network and host-based IDS architectures.
- Enterprise-scale firewall architectures.
- E-commerce application security.
- Computer investigation and forensics methods and technologies.
- Secure messaging architectures.
- Strong knowledge of regulatory bodies, and the regulations and guidance issued by these bodies.
- Strong knowledge of control and privacy laws and standards, such as GLBA, 581386, SOX, and PCI.
- Must possess strong project management and leadership aptitude; demonstrated professionalism in managing multiple projects and resources effectively.

General Knowledge and Abilities
- Experience with PKI certificate management and root certificate repositories.
- Working experience with penetration testing.
- Experience working in a SaaS-oriented Cloud environment.
- Project Management experience.
- Strong communication and facilitation skills.

Physical Requirements
- Office-based professional, no physical requirements.


#J-18808-Ljbffr

  • Olympia, Washington, United States State of Washington Full time

    About the Role:The State of Washington is seeking a proactive and analytical individual to join our Information Governance Office (IGO) team as an Information Governance Compliance Specialist. This role is essential in ensuring that our agency's data is managed responsibly and in accordance with applicable regulations.Team Environment:Our IGO operates in a...


  • Olympia, Washington, United States Providence Service Full time

    Position OverviewSecurity Specialist - Providence St. Peter HospitalWe are currently seeking Full-Time Security Specialists for variable shifts.The primary responsibility of a security specialist is to safeguard the hospital's personnel, assets, information, and reputation. This role involves executing duties with the utmost adherence to ethical standards,...


  • Olympia, Washington, United States DSI Security Full time

    Position OverviewAt DSI Security, we offer more than just a salary; we provide a career that embodies our core values and commitment to excellence. Joining our team means becoming part of a culture that prioritizes integrity and accountability, guided by our motto: Do What You Say You Will Do. We are dedicated to fostering a work environment that reflects...


  • Olympia, Washington, United States FPI Management, Inc. Full time

    Field Compliance Specialist (FCS)Company OverviewFPI Management, Inc. is a prominent Property Management firm overseeing a vast portfolio of communities nationwide.Position OverviewThe Field Compliance Specialist (FCS) is responsible for ensuring adherence to property program regulations by facilitating certifications, conducting audits, and offering support...


  • Olympia, Washington, United States FPI Management, Inc. Full time

    Field Compliance Specialist (FCS)Company OverviewFPI Management, Inc. is a prominent Property Management firm overseeing a vast portfolio of communities nationwide.Position OverviewThe Field Compliance Specialist (FCS) plays a crucial role in ensuring adherence to property program regulations by facilitating certifications, preparing for audits, and offering...


  • Olympia, Washington, United States FPI Management, Inc. Full time

    Field Compliance Specialist (FCS)Company OverviewFPI Management, Inc. is a prominent Property Management firm overseeing a vast portfolio of over 850 communities nationwide.Position OverviewThe Field Compliance Specialist (FCS) plays a crucial role in ensuring adherence to property program regulations by supporting certification processes, audit readiness,...


  • Olympia, Washington, United States State of Washington Full time

    Position Overview:The Washington State Department of Financial Institutions (DFI) is dedicated to safeguarding consumers and enhancing the financial well-being of Washington State. As a Program Specialist 3, you will play a pivotal role in ensuring regulatory compliance among financial service providers.Key Responsibilities:1. Monitor and evaluate the...


  • Olympia, Washington, United States Child Care Action Council Full time

    Child Care Action CouncilChild Care Action Council is a non-profit organization committed to developing and nurturing early learning environments that enhance the well-being of families and children. Our team collaborates at local, regional, and state levels with a diverse array of individuals and organizations to advocate for equity, inclusivity, and social...


  • Olympia, Washington, United States State of Washington Full time

    Position OverviewThe State of Washington is dedicated to fostering safe communities through effective regulation and oversight. As a Licensing Specialist, you will play a crucial role in upholding public safety and health standards.Key ResponsibilitiesAdminister and enforce laws related to liquor, tobacco, cannabis, and vapor products.Provide education and...


  • Olympia, Washington, United States Target Full time

    About the Role:As a Security Specialist at Target, you will be part of a team responsible for developing a secure work environment for all employees, temporary workers, vendors, and visitors. Your primary objective will be to contribute to the creation of a safe and secure workplace.Key Responsibilities:Contribute to the development of a secure work...


  • Olympia, Washington, United States GardaWorld Full time

    Job OverviewJoin GardaWorld as a Security Patrol SpecialistAt GardaWorld, we recognize that the right skills deserve the right opportunities. We are currently seeking dedicated individuals to join our team as Security Patrol Specialists.Every day at GardaWorld brings unique challenges and diverse assignments, offering flexible work schedules. As a leader in...


  • Olympia, Washington, United States Providence Health & Service Full time

    Position OverviewSecurity Officer - Providence Health & ServicesWe are currently seeking dedicated individuals for Full-Time Security Officer roles with flexible shifts.The primary responsibility of a security officer is to safeguard the hospital's personnel, assets, information, and reputation. Officers are expected to perform their duties while upholding...


  • Olympia, Washington, United States State of Washington Full time

    About the RoleWe are seeking a highly skilled and experienced Senior Systems Security Specialist to join our team at the State of Washington. As a key member of our organization, you will play a critical role in ensuring the safety and security of our transportation systems.Key ResponsibilitiesDevelop and implement comprehensive safety and security protocols...


  • Olympia, Washington, United States Tiffany & Co. Full time

    Overview:Tiffany & Co. embodies elegance, romance, and the iconic Blue Box, representing a legacy of excellence. For over 175 years, Tiffany has established a tradition of remarkable designs and romantic ideals. The rich heritage of celebrated artisans, significant milestones, and exquisite jewelry serves as the foundation for our employees' daily endeavors....


  • Olympia, Washington, United States MultiCare Health System, Inc. Full time

    Position OverviewAt MultiCare Health System, we are committed to fostering an inclusive environment for all our team members. Within our extensive healthcare network, you will discover a variety of fulfilling career paths, opportunities for advancement, secure work environments, and adaptable schedules.Our mission unites us - collaborating and healing for a...


  • Olympia, Washington, United States MultiCare Health System, Inc. Full time

    Company OverviewAt MultiCare Health System, we are committed to fostering a genuine sense of belonging for all our team members. Within our extensive healthcare network, you will discover a diverse array of fulfilling career paths, opportunities for advancement, secure work environments, and adaptable schedules. Our mission unites us - collaborating and...

  • Safety Specialist

    3 days ago


    Olympia, Washington, United States Malace HR Full time

    Job OverviewMalace HR is seeking a dedicated and experienced Workplace Health & Safety (WHS) Specialist to join our team. As a WHS Specialist, you will play a critical role in promoting a positive and safe work environment, ensuring compliance with standards, and maintaining a culture of excellence.Key ResponsibilitiesCompliance and Risk Management: Identify...


  • Olympia, Washington, United States State of Washington Full time

    About the RoleWe are dedicated to fostering a culture of belonging through our core values: Respect, Trust, Diversity, Inclusion, and Equity. As a key member of the Department of Licensing (DOL), you will play a vital role in promoting work-life harmony and creating a culture where employees can thrive.Key ResponsibilitiesConduct thorough examinations of...


  • Olympia, Washington, United States VOLT Management Full time

    **Job Summary**Volt Management is seeking an experienced IT Service Delivery Specialist to join our team. As an IT Service Delivery Specialist, you will be responsible for supporting the IT and Telecommunications infrastructure for multiple departments, ensuring the utilization of hardware, software, and communication systems are consistent with our...


  • Olympia, Washington, United States State of Washington Full time

    About the PositionThis is a challenging and rewarding role that requires a strong background in network security and a passion for staying up-to-date with the latest technologies and threats.Key ResponsibilitiesImplement high-level design solutions to ensure the security and integrity of the state's network infrastructure.Research and identify potential...