Cyber Security Information Officer

St Mary's County Government

Leonardtown (MD)

On-site

USD 109,000 - 115,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

St Mary’s County Government is seeking an Information Security Officer to oversee day-to-day security operations across county information systems. Responsibilities include threat monitoring, policy development, and risk mitigation for networks, systems, and applications county-wide.

The role reports to the Deputy Director of Information Technology and collaborates with county departments and allied agencies to strengthen cyber defense and compliance with security standards.

Qualifications

  • Four-year college degree or equivalent in information security.
  • 3–5 years of experience in a security analyst or related role.
  • One or more certifications: CEH, CISM, CompTIA Security+, CISSP, or GSEC.
  • Experience securing on-premise and hosted systems and applications.
  • Experience with risk management and compliance frameworks (NIST, COBIT, ISO).

Responsibilities

  • Monitor online security-related resources for new threats and vulnerabilities.
  • Lead vulnerability assessments and remediation activities.
  • Develop and enforce security policies and procedures county-wide.
  • Coordinate security efforts with IT teams, departments, and allied agencies.
  • Supervise assigned staff and provide technical guidance.

Skills

Threat hunting
Policy writing
Analytical thinking
Communication
Autonomous problem-solving

Education

Bachelor’s degree in cybersecurity or related field
Certifications: CEH, CISM, CISSP, or Security+
Experience in security analytics

Tools

Azure AD
Office 365 MFA
Entra ID
Intune
BitLocker
Windows Defender
SQL / IIS / Windows Server

Job description

The Information Security Officer (ISO) is responsible for assisting with the day-to-day operations of securing the county’s various information systems. Reporting to the Deputy Director of Information Technology, the ISO is tasked with providing technical expertise in all areas of network, system, and application security for the entire county network including supported sub-agencies. The ISO works closely with the various teams in the Information Technology department, county departments, and allied agencies (Metcom, St. Mary’s County Health Department, St. Mary’s County Libraries, St. Mary’s County Public Schools, etc.) that utilized county infrastructure to ensure that systems and networks are always designed, developed, deployed, and managed with an emphasis on strong, effective security and risk management controls. The ISO leads the county-wide Cyber Security Planning Committee with county, state, and federal Cybersecurity compliance for all county and county allied agencies. Assesses the vulnerability management program, reviews annual cybersecurity assessments and penetration tests, and research and reports on emerging threats, to take pre-emptive risk mitigation steps for multiple county agencies. The ISO effectively correlates and analyzes security events within the county’s unique network environment to proactively detect threats and mitigate attacks before they occur by establishing policies and procedures which defend against remote attacks of the county infrastructure. Performs other duties as assigned.

The hiring salary for this position is $109,116 - $114,628 annually; full salary range for this position is $109.116 - $187,928

  1. Monitor online security-related resources for new and emerging cyber threats;
  2. Ensure compliance with county, state, and federal cybersecurity laws and policies;
  3. Proactively monitor the network environment to detect and implement steps to mitigate cyber-attacks before they occur;
  4. Provides technical expertise regarding security-related concepts to operational teams within the Information Technology Department and the entire county government network;
  5. Assesses new security technologies and threats to determine potential value to protect and defend the enterprise;
  6. Prepare for, review, investigate, report, and respond to real-time alerts within the environment;
  7. Review real-time and historical reports for security and/or compliance violations;
  8. Reviews vulnerability assessments of the county’s systems and networks and implements corrective actions and polices to improve cyber posture.
  9. Supervises assigned staff;
  10. Performs other duties as assigned.
  1. Technical knowledge of enterprise-class technologies such as firewalls, routers, switches,
  2. wireless access points, VPNs, and desktop and server operating systems;
  3. Demonstrate experience implementing and/or enforcing security and compliance
  4. Strong writing skills, as well as the ability to articulate security-related concepts to a broad
  5. range of technical and non-technical staff;
  6. Working experience with creating, implementing, and managing a threat hunting program within a corporate environment; Understanding of Microsoft’s enterprise technology platform, including Azure, Active Directory, SQL, IIS, Office365, MFA / 2FA authentication, Entra ID, Intune, BitLocker, Windows Defender, and the Windows server and desktop operating systems; frameworks such as NIST, Cobit, and ISO;
  7. Must be a proficient problem-solver that can work autonomously.
  1. Four-year college degree or equivalent industry training and certifications;
  2. Three to five years of experience in a security analyst or related position;
  3. One or more of the following certifications: CEH, CISM, CompTIA Security+, CISSP, GSEC
  4. Experience with managing and securing both on-premise and hosted systems and applications;
  5. Experience with application, website, and database security.
Physical and Environmental Conditions:

Work demands occasional strenuous effort. For example, handling of moderately heavy boxes, moderately heavy tools, equipment, or materials of up to 30 to 60 pounds.

Work environment involves everyday risks or discomforts which require normal safety precautions typical of such places as offices, meeting or training rooms, residences, or commercial vehicles, e.g., use of safe workplace practices with office equipment, avoidance of trips and falls, observance of fire regulations and traffic signals, and/or working in moderate outdoor weather conditions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer
Cyber Security Engineer

Stafford County Government • Stafford (VA)

On-site
USD 97,000 - 133,000
Countywide Information Security Leader
Countywide Information Security Leader

St Mary's County Government • Leonardtown (MD)

On-site
USD 109,000 - 115,000
Associate Division Director, Cyber Security Officer
Associate Division Director, Cyber Security Officer

UNAVAILABLE • Salt Lake City (UT)

Hybrid
USD 150,000 - 190,000
Hybrid work environment
Paid leave: holidays, vacation, sick,
Personal day
+3
Enterprise Security Analyst
Enterprise Security Analyst

The County of Galveston • United States

On-site
USD 67,231 - 82,172
Flexible health benefits
Full family coverage for medical, dental, and vision
Strong retirement security with county matching
+2
Cybersecurity Engineer
Cybersecurity Engineer

County of Roanoke Virginia • Roanoke (VA)

On-site
USD 110,000 - 150,000
Operational Technology Cyber Security Manager (Systems Analyst)
Operational Technology Cyber Security Manager (Systems Analyst)

Center for Digital Governmtent • Annapolis (MD)

On-site
USD 110,000 - 150,000
Medical/Health Insurance Plans
Pension Plan
Holidays
+3
IT- Cybersecurity Operations Manager
IT- Cybersecurity Operations Manager

Horry County Government • Conway (SC)

Hybrid
USD 110,000 - 180,000
Cybersecurity Engineer
Cybersecurity Engineer

Koitecc Solutions • Roanoke (VA)

Hybrid
USD 120,000 - 155,000
Director I, Cybersecurity Operations
Director I, Cybersecurity Operations

College of Southern Maryland • La Plata (MD)

On-site
USD 140,000 - 190,000
Health insurance
State Retirement Pension
Wellness programs
+1
Information Security Engineer
Information Security Engineer

maricopa • Phoenix (AZ)

Hybrid
USD 86,000 - 146,000
Tuition reimbursement
Hybrid work options
Growth opportunities
+4