Salary Range: $54,416.96 - $106,182.70
DISTINGUISHING CHARACTERISTICS OF WORK
Responsible for the day-to-day operations of the in‑place security solutions while also handling detection, analysis, containment, eradication, and recovery from security breaches identified by those systems. Secondary tasks may include involvement in the implementation of new security solutions, participation in the creation or maintenance of policies, standards, baselines, guidelines, and procedures, as well as conducting vulnerability audits and assessments. This skilled technical position is responsible for administering and maintaining security controls focused on network security across the City’s enterprise in accordance with existing policies, procedures, and security best practices. The IT Security Analyst performs two core functions: fully awareness of the enterprise’s security goals, articulating technical security requirements, monitoring the effectiveness of the IT security controls framework, and assisting in raising security awareness and policy compliance among workforce members.
ESSENTIAL DUTIES
- Contribute to the planning, design, and creation of enterprise security architecture, policies, incident response plans, business continuity, and disaster recovery plans.
- Promote security awareness and cybersecurity goals with City staff.
- Stay informed on IT security industry trends, emerging threats, and solutions.
- Review, recommend, and implement security measures and enhancements.
- Deploy, integrate, and configure new and existing security solutions.
- Provide day-to-day support for the information security program, ensuring adherence to best practices across network, desktop, server, and mobile configurations.
- Design and maintain security controls, and define role-based access and secure business processes.
- Monitor security threats, systems, and network traffic, conduct vulnerability assessments, and ensure operational efficiency.
- Respond to security incidents, collaborate across teams for resolution, and ensure CIA (Confidentiality, Integrity, Availability) of City information.
- Administer and audit user access, defend against unauthorized access, and maintain effective malware protection.
- Train employees in security awareness and respond to incidents with post‑event analyses and remediation.
- Perform other related duties as assigned.
KNOWLEDGE, SKILLS, AND ABILITIES
- Extensive experience with and knowledge of Endpoint Protection, EDR, and MDR functionality.
- Experience with firewalls and associated management tools.
- Familiarity with Security, Education, Training, and Awareness (SETA) platforms.
- Strong understanding of AD, IP, TCP/IP, and other network administration protocols.
- Experience with the following access control schemes: Role‑based Access Control (RBAC), Mandatory Access Control (MAC), Discretionary Access Control (DAC).
- Strong understanding of Microsoft Windows Server 2016, 2019, & 2022, and Windows 11 or higher.
- Knowledge and experience in using automated tools for applying operating system, application, and firmware updates, hot fixes, and patches.
- Possess a high degree of integrity and trust, along with the ability to work independently on complex technical issues.
- Proven analytical and problem‑solving abilities with keen attention to detail.
- Ability to effectively prioritize and execute tasks in a high‑pressure environment.
- Good written, oral, and interpersonal communication skills.
- Ability to conduct research into IT security issues and products as required.
- Ability to present ideas in business‑friendly and user‑friendly language.
- Highly self‑motivated and directed.
- Team‑oriented and skilled in working within a collaborative environment.
PHYSICAL REQUIREMENTS
- Ability to effectively communicate and interact with other employees and the public through telephone and personal contact.
- Physical capability to effectively use and operate various office equipment such as a personal computer, calculator, copier, and fax machines.
- Work performed indoors within a quiet to moderately noisy environment.
- Ability to lift, carry, and/or push articles weighing up to 20 lbs.
MINIMUM TRAINING AND EXPERIENCE
- Bachelor’s degree from an accredited four‑year college or university with major coursework in computer science or a related field, or equivalent work experience.
- A minimum of four (4) years of relevant experience in IT Security, Audit, or Compliance inclusive of implementing security measures and deploying, configuring, maintaining, and integrating security solutions.
- English & Spanish speaking preferred.
- A combination of education and experience may be considered.
- Maintain one or more of the following certifications in good standing, or be able to obtain within nine (9) months of employment:
- CompTIA Security+
- CISM – Certified Information Security Manager
- CISSP – Certified Information Systems Security Professional
- CEH – Certified Ethical Hacker
- OSCP – Offensive Security Certified Professional
- CCSP – Certified Cloud Security Professional
- MTA/SF – Microsoft Technology Associate Security Fundamentals
- CSX Cybersecurity Fundamentals Certificate
- CCNA – Network Security
The City of Hialeah is an equal opportunity employer. There will not be any discrimination or harassment of any kind on account of age, color, race, religion, sexual orientation, national origin, disability, genetic information, marital or familial status, military service, or any of the protected categories. The City of Hialeah is a drug and alcohol free employer.