Security Analyst to analyze security posture ratings for 61+ Online Driver Training Organizations licensed to operate by the State of Ohio Department of Public Safety.
This work can be done at any time, including nights and weekends.
This is a fully remote position, and other employment is permitted (candidate must be able to dedicate approximately 10 hours per week analyzing and communicating results).
The Department of Public Safety will provide access to the Third-Party Risk Management (TPRM) tool, Bitsight, and the assessment communication tool, OneTrust.
This position will function as part-time Cyber Security Consultant with specific responsibilities that include:
1. Review initial security assessment provided by online driver training companies at the time of application.
a. DPS to provide the security assessment questionnaire
b. Security Consultant to validate the security assessment is accurately and thoroughly completed
2. Review updated security assessment provided by online driver training companies for submission of changes of security controls.
3. Document and address concerns or clarifications needed for the security assessment review with the online driver education companies.
a. Security Consultant to compare responses against the assessment and industry standards
4. Review online driver training company annual attestations of compliance.
a. Security Consultant to validate the security assessment is accurately and thoroughly completed
b. Security Consultant to communicate any deficiencies in annual attestation to the online driver training company and facilitate the accurate completion of the attestation of compliance.
5. Contact and work with Bitsight to configure monitoring parameters. Use Bitsight functionality to direct the findings and remediation recommendations to the online driver training company.
6. Discuss findings with online driver training company
a. Security Consultant will use OneTrust as the Governance Risk and Compliance (GRC) tool to assess and communicate
b. Security Consultant does NOT assist the online driver training company determine corrective path of action.
7. Upon complaint for investigation, including but not limited to, reviewing updated monitoring results to confirm no falsification or other violation has occurred.
8. Run Bitsight reports and provide the information the business needs for administrative action. Communicate with DPS Driver Training Program Office on a consistent basis with status updates.
9. Monitor upcoming changes to the controls and communicate with the Driver Training Program Office with the specifics.
10. May need to provide testimony at administrative hearings. Any testimony is based on processes and expertise on security controls, if needed.
Required/Desired Skills| Skill Required /Desired Amount of Experience | |||
| Experience with Cybersecurity frameworks (NIST CSF, ISO 27001), Third-party risk assessment, Vendor Management, Data Privacy | Required | 3 | Years |
| Vulnerability management experience | Required | 3 | Years |
| Utilize Bitsight security ratings to assess driving school security posture | Required | 3 | Years |
| Daily or weekly tracking of vendor security ratings in Bitsight to detect drops in security performance | Required | 3 | Years |
| Generate automated reports and dashboards for business highlighting provider risk exposure and their security control effectiveness | Required | 3 | Years |
| Manage remediation plans within the GRC OneTrust to closure. | Required | 3 | Years |
| No. Question | |
| Question1 | Do you understand, and will abide by, the provision in your subcontract with OST that it is PROHIBITED for government equipment to be taken or used outside of the United States by your contractors? The consequences of this occurring can and will result in repercussions to you, the prime vendor, regardless if the candidate works for a sub-vendor of yours. It will also result in immediate termination of the contractor and make them ineligible for rehire in the program. |
| Question2 | Where does your candidate currently live? Please provide City/State. |
| Question3 | Interviews will be required to be in-person at the Shipley building at 1970 West Broad Street. Is your candidate willing and able to interview in person? Please do not submit candidates who are unable to interview in person. |
| Question4 | Candidate will be required to complete a Federal fingerprint check, conducted by DPS. Do you accept? |
...and surrounding areas Pay: $16$18/hr | Weekend Shifts Available | Bi-Weekly Pay |... ...including days, nights, and overnights. These part-time and PRN opportunities are ideal for caregivers... .... Benefits & Support Paid Time Off Direct Deposit Merit-based pay...
...Some Reading Specialist Positions are paid with Grant Funding Job Summary: Position is responsible for implementing a comprehensive literacy program at the assigned school through coaching supporting and guiding teachers in best practices for literacy instruction...
Founded in 1963, Everglades Equipment Group is a family owned and operated full-service John Deere dealership with 19 locations covering central and south Florida. Everglades Equipment Group serves a wide range of customers from some of the largest agricultural producers...
...telecomm leader, is seeking a Senior Product Designer to help shape the future of digital... ...hr-70hr based on experience~Location: Remote~Hours: PST hoursResponsibilities... ...preferred)~Strong portfolio showcasing UX thinking, systems design, and high-...
...re Looking For ~ Bachelors degree in Analytics, Marketing, Economics, Statistics, Business, or a related field. ~12 years of experience... ...concepts. Experience working with large datasets or event-level data. To Apply ~ If you are excited by the opportunity to...