Our Values:
- Integrity
- Common Sense
- Innovation
- Accountability
Position Data:
Information Security Analyst-J23-U29-H
Regular
Non-Exempt (eligible for overtime)
Overview:
Pay Range: $44.70 - $56.69 per hour (TS Teamsters Pay Plan IT45,Step 1-13)
Hiring Range:$44.70 - $47.44 per hour (TS Teamsters Pay Plan IT45, Step 1-4 DOQ)
Job Closing Date: Open Until Closed with weekly reviews starting August 10, 2026.
The mission of Yakima County Government is to provide accessible, responsive and responsible public service through leadership and teamwork committed to understanding and meeting public needs.
There is one Information Security Analyst opening with the Yakima County Technology Services Department. This position is responsible for leading the County's cyber security initiative and developing and implementing network design for a wide variety of journey level network projects.
- No Remote Work for this position
Benefits included in position:
- Health Care Benefits (Medical, Dental, Vision, Basic Life and Basic LTD)
- Retirement Benefits
- Paid Vacation
- Paid Holidays
- Paid Sick Leave
Note: This is a Technology Services Teamsters Contract Bargaining Unit Position.
This recruitment may be used to fill future vacancies that occur within 90 days of the closing of this position. (This excludes Yakima County Sheriff's Office and Department of Corrections)
Responsibilities:
Essential Duties:
Network Security:
- Leads the county Cyber-security preparedness initiative. Assesses current preparedness of county cyber environment and determines the best means to mitigate threats in both the short and long term.
- Monitors, researches, forecasts and leads the Technology Services team to ensure proper defense and responds to worldwide cyber threats as incident leader when a cyber-attack occurs.
- Conducts an after action analysis and determines if any corrective action is required. Researches, drafts and recommends corrective action plans to be implemented by those affected and Technology Services.
- Oversees the remediation of virus and malware infections, to maintain security on the network. Intervenes in network or user level connections when necessary to maintain network security and remedi...
- Intervenes in network or user level connections when necessary to maintain network security and remedi...
- Creates, develops, and maintains various network documentation, including diagrams, backup equipment configuration information, and security access levels.
- 2. Implementation and operation of standardized security frameworks (NIST, CIS, CJIS, HIPAA, etc).
- Establish an inventory of authorized devices and software that can be connected to the network in order to prevent unauthorized devices from being attached to the network and to prevent attacks by malware and viruses.
- Creates secure configurations for hardware and software on mobile devices, laptops, workstations and servers and network devices such as firewalls, routers, and routers in order to ensure the security of the network. Secures data transmissions and storage, based on the data's content and associated classification, to ensure against theft.
- Performs gap analysis to identify security areas employees are not adhering to, and use this as a basis for implementing a security awareness program. Establishes an incident response and management process with trained resources for dealing with any adverse event or threat to be able to quickly respond to an attack and restore service to the County. Establishes the processes and tools needed to properly back up critical information to restore County business functions. Establishes a process to ensure that network ports, protocols and services are only turned on when needed, to protect against attacks on the network.
- Perform continuous vulnerability assessment and remediation to search for security risks and establishes malware defenses to detect/prevent/correct the installation and execution of malicious software on all devices to prevent the corruption and/or theft of County assets. Designs and implements network perimeters and analyzes audit logs to search for successful cyber-attacks. Performs penetration tests and deploys processes and tools to detect/prevent/correct security weaknesses in web applications, software, wireless local area networks, access points and wireless client systems in order to defend against attacks.
- Establishes controls for which persons, computers, and applications have a need and right to access information based on an approved cl