Technology Engineer – Principal (1044) – Security Specialty - Citywide (C00100) — San Francisco, CA
Full job description
Under general direction, provides direct ongoing supervision to other Technology Engineers and/or provides technical leadership and direction and assumes technical responsibility for completion of major projects, or serves as the top technical authority for one or more related specialties. Performs and reviews complex work involving analysis, planning, designing, implementation, maintenance, troubleshooting and enhancement of systems or platforms. Serves as the lead technical architect for systems or platforms.
The 1044 Principal Technology Engineer is the highest level in the Engineer series and may be assigned to function as a supervisor, expert or project leader. When assigned as a supervisor, develops, coordinates and executes policies, methods and procedures, and supervises personal; when assigned as an expert, performs work requiring a very high level of technical knowledge of a specific area or ability to integrate at a high level the knowledge of several areas (this is not considered to be a part of the normal career path for employees in this series; rather it is reserved for those employees with a mastery of specific technologies or a particular expertise); when assigned as a project leader, manages and provides technical leadership of projects involving large-scale, complex and highly analytical tasks. Work is performed within a broad framework of general policy and requires creativity and resourcefulness to accomplish goals and objectives, and in applying concepts, plans and strategies which may deviate from traditional methods and practices.
Supervision Exercised:
May supervise subordinate Engineers staff and technical staff in the assigned work unit; or as a Project leader, coordinate a team of workers within the assigned work unit or jointly with other unites. May be expected to provide consultation and guidance to Technology professionals and non-Technology professionals.
Essential Duties:
- Architects, designs, implements, maintains and operates information system security and privacy controls and countermeasures; supervises and trains operators in the administration of these systems; documents the operation, use and expected outputs of these systems.
- Analyzes and recommends security and privacy controls and procedures in acquisition, development and change management lifecycle of information systems, and provides oversight to ensure compliance.
- Analyzes and recommends security and privacy controls and procedures in business processes related to use of information systems and assets, and provides oversight to ensure compliance.
- Monitors information systems for security incidents, vulnerabilities and privacy risks; develops monitoring and visibility capabilities; reports on incidents, vulnerabilities and trends to IT or executive management.
- Oversees the response to information system security and privacy incidents, including investigation of, countermeasures to and recovery from computer-based attacks, unauthorized access and policy breaches; engages, interacts and coordinates with third-party incident responders, including law enforcement.
- Oversees the administration of authentication and access controls, including provisioning, changes and deprovisioning of user and system accounts, security/access roles and access permissions to information assets.
- Analyzes trends, news and changes in threat, compliance, and privacy regulatory environment with respect to organizational risk; advises organization management and develops and executes plans for compliance and mitigation of risk; oversees risk and compliance self-assessments and engages and coordinates third-party risk and compliance assessments.
- Analyzes and oversees the development of information security and privacy governance, including organizational policies, procedures, standards, baselines and guidelines with respect to information security, privacy, and use and operation of information systems.
- Oversees the development and administration of information security and privacy training and awareness programs.
Education
Experience
Five (5) years of experience analyzing, installing, configuring, enhancing, and/or maintaining the components of a system or platform.
Substitution:
Positions with the Port
Selection Procedures
Preliminary Questionnaire:
Tech Engineer – Security Core Exam (Weight: 100%):
Candidates self-certifying meeting the Minimum Qualifications will be invited to participate in the online Tech Engineer – Security Core Exam. Candidates will be sent a web link via email that will allow them to take the online Tech Engineer – Security Core Exam that is designed to measure basic analytical and technical abilities associated with the target job, which may include but not be limited to:
- Knowledge of security operations including concepts, investigations, and incident management
- Knowledge of security engineering
- Knowledge of communication and network security
- Knowledge of asset security operations
- Knowledge of identity and access management including controlling access and managing identity
- Knowledge of mobile security including managing and securing mobile devices and software
- Knowledge of security assessment and testing
This computer-administered test can be taken at home or at a time and location of one’s convenience, but only within a two week period specified on the test notification. Candidates must have access to a computer and reliable internet connection to participate in this exam. The test consists of 20 questions and it must be completed within 50 minutes. Questions are presented one at a time on the computer screen. There is no penalty for guessing. Candidates may not return to questions presented earlier in the exam; they can only move forward. A passing score must be attained on this test in order to continue further in the selection process. Test questions and answers are not available for public inspection or review.
Candidates’ scores on the Tech Engineer – Security Core Exam may also be applied to other announcements involving other job titles, when directed by the Human Resources Director.
Score Banking: Scores attained on the Tech Engineer – Security Core Exam will be 'banked' for three years, starting from the date of the examination. This means that, during this three-year time period, candidates need not take this test again. Rather, if another announcement you applied to and are deemed qualified for requires the Tech Engineer – Security Core Exam and is held within one year of your Tech Engineer – Security Core Exam date your score will be automatically applied to tha