Under the general direction of the Deputy Chief Information Security Officer (DCISO), an Information Technology Supervisor II in the Information Security Office (ISO), the incumbent performs State Controller’s Offices (SCO) Information Security Program activities, such as, security risk management to ensure SCO business and technical environments have and maintain an appropriate security posture. Additionally, as an Information Security Program Specialist the incumbent will provide information security consultative or administrative services to the SCO regarding security awareness training and education, security compliance, policy and procedure development, security incident management, physical security and Mainframe access control.
Duties Performed:
(Candidates must perform the following functions with or without reasonable accommodations.)
- Physical Security Systems Administration – As part of physical security administration, responsibilities include managing and supporting systems like CCure for electronic badging and access control, alarm and intrusion detection, and video surveillance platforms like ExacqVision or similar solutions, as well as ISTAR or equivalent access control panels. Duties involve processing and managing badge requests, access changes, clearances, and terminations in compliance with approved policies. Additionally, monitoring alarms, alerts, and system activity is essential, along with investigating and documenting physical security events and access violations. Regular reviews of badge access, clearance levels, alarm activity, and video monitoring logs are conducted to ensure security integrity. The role also requires responding to after-hours and on-call physical security alarms and incidents when necessary, and coordinating with vendors and contractors for system maintenance, troubleshooting, and upgrades. Also, Administer and execute the SCO ISO’s Physical Security Program. Respond, identify and resolve complex physical security system change requests, alarms, and other physical security system issues. Monitor and review physical security system performance.
- Physical Security Program Support - Responsibilities include assisting with the development, maintenance, and updating of physical security policies, procedures, and documentation to ensure alignment with State and NIST guidelines. This role involves conducting basic physical security risk assessments and supporting corrective action efforts to mitigate identified vulnerabilities. Additionally, guidance is provided to staff regarding badging, access control, and overall physical security requirements. Maintaining accurate and up-to-date documentation for physical security systems, configurations, and workflows is also a key responsibility to ensure compliance and operational efficiency. Also, performing routine testing of alarms, access control systems, and video surveillance equipment to ensure proper functionality. This role involves identifying system issues and escalating or coordinating resolution with senior staff or vendors as needed. Additional duties include assisting with system integrations and implementing changes that impact physical security platforms, as well as tracking incidents, outages, and system modifications for accurate reporting and follow-up.
- Incident Management - Efficiently and effectively respond to, investigate, and report information security incidents within the SCO’s business and information asset environments. Observe and enforce SCO’s incident management program defined policies, processes, procedures; work with program-identified resources to prepare for and prevent incidents; detect, report, and analyze possible or known incidents; contain and eradicate discovered incidents; recover from incidents; and prepare lessons learned from incidents identify program or process improvement. The role also involves performing various technical or administrative tasks for the Information Security Office (ISO) to ensure smooth operations. Additionally, this position serves as backup support to other ISO team members during periods of high workload, helping maintain continuity and efficiency across the team.
- Security / Privacy Awareness Training & Education – Plan, prepare and provide security and privacy awareness training and education to SCO managerial, supervisory, business, technical and contractor staff; translate the organization’s security / privacy values and requirements into operational environments, ensure compliance with legal and statutory requirements and provide a framework for security posture assurance actions.
- Miscellaneous Division Support - Assist with division technical duties in various program areas to support organizational needs using a variety of skills and software.