Technology Engineer - Associate (1041) - Security Specialty - Citywide (C00088) — San Francisco, CA
Full job description
Under general supervision, assists in analyzing, planning, implementing, maintaining, troubleshooting and enhancing technology. Serves as assistant technical contributor for systems or platforms.
The 1041 Technology Engineer Associate is the entry level in the Engineer series. The class is distinguished from the 1042 Technology Engineer by the complexity of the systems or networks supported. Positions at this level perform a significant portion of the work assigned to the journey level, but without the independence or full responsibility expected of positions at the journey level. Assignments are generally limited in scope and are set within procedural frameworks established by higher level positions. As experience accrues, the incumbent performs with increasing independence. Work requires incumbents to exercise some judgement in selecting appropriate established guidelines to follow. Significant deviations require prior approval. Interpretation of general administrative or operational policies is sometimes necessary.
Supervision Exercised:
None
Essential Duties:
- Maintains and operates information system security and privacy controls and countermeasures.
- Monitors and assists with the implementation of security and privacy controls and procedures in business processes related to use of information systems and assets.
- Monitors information systems for security incidents, vulnerabilities, and privacy risks; develops monitoring and visibility capabilities; reports on incidents, vulnerabilities and trends.
- Responds to information system security and privacy incidents, including investigation of, countermeasures to and recovery from computer-based attacks, unauthorized access and policy breaches; interacts with third-party incident responders, including law enforcement.
- Administers authentication and access controls, including provisioning, changes and deprovisioning of user and system accounts, security/access roles and access permissions to information assets.
- Monitors trends, news and changes in threat, compliance, and privacy regulatory environment with respect to organizational risk; assists in the execution of plans for compliance and mitigation of risk; assists in the completion of risk and compliance self-assessments and third-party risk and compliance assessments.
- Assists with the administration of information security and privacy training and awareness programs.
Education
Substitution:
One year of experience in analyzing, installing, configuring, enhancing and/or maintaining the components of a system or platform may be substituted for the required degree.
Positions with the Port
Selection Procedures
Preliminary Questionnaire:
Tech Engineer – Security Core Exam (Weight: 100%)
Candidates self-certifying meeting the Minimum Qualifications will be invited to participate in the online Tech Engineer – Security Core Exam. Candidates will be sent a web link via email that will allow them to take the online Tech Engineer – Security Core Exam that is designed to measure basic analytical and technical abilities associated with the target job, which may include but not be limited to:
- Knowledge of security operations including concepts, investigations and incident management
- Knowledge of security engineering
- Knowledge of communication and network security
- Knowledge of asset security operations
- Knowledge of identity and access management including controlling access and managing identity
- Knowledge of mobile security including managing and securing mobile devices and software
- Knowledge of security assessment and testing
This computer-administered test can be taken at home or at a time and location of one’s convenience, but only within a two week period specified on the test notification. Candidates must have access to a computer and reliable internet connection to participate in this exam. The test consists of 20 questions and it must be completed within 50 minutes. Questions are presented one at a time on the computer screen. There is no penalty for guessing. Candidates may not return to questions presented earlier in the exam; they can only move forward. A passing score must be attained on this test in order to continue further in the selection process. Test questions and answers are not available for public inspection or review.
Candidates’ scores on the Tech Engineer – Security Core Exam may also be applied to other announcements involving other job titles, when directed by the Human Resources Director.
Score Banking: Scores attained on the Tech Engineer – Security Core Exam will be 'banked' for three years, starting from the date of the examination. This means that, during this three-year time period, candidates need not take this test again. Rather, if another announcement you applied to and are deemed qualified for requires the Tech Engineer – Security Core Exam and is held within one year of your Tech Engineer – Security Core Exam date your score will be automatically applied to that announcement. However, after one year, a candidate has the option to either (a) apply his/her test score to the other announcement or (b) re-take the test. Re-testing is permitted no sooner than one year from the date of the test and only in association with a candidate’s eligibility for another announcement to which the candidate has applied and is deemed qualified. If a candidate opts to re-test, the re-test score becomes the candidate’s official score since it is the most recent.
Upon passing the exam, candidates will be placed on the