Copy

 

Business Security Continuity Services Manager

 

Specific Requirements:

·         The Business Security and Continuity Services Manager is responsible for protecting data from compromise. Working within the policies and guidelines established by Minacs, the Manager would be responsible for analyzing, developing, implementing and enforcement of security requirements, privacy requirements, policies and technical guidelines.

 

·         In addition, the Manager will provide leadership in coordinating, developing communicating recovery environment requirements and contingency plans associated with Minacs' Business Units to protect the business in the event that facilities or technology resources are unavailable due to an unforeseen disruption. The Manager is responsible for coordinating the teams responsible for the planning and implementation of the Business Unit contingency plans to provide for manual/off-line procedure development designed to mitigate firm risk associated with the complete or partial failure of facilities, technology systems or applications related to an unforeseen disruption.

 

Responsibilities:

·         Provide ongoing evaluation of security measures, reporting findings to security management, identifying any vulnerabilities and make recommendations to reduce exposure.

·         Ensure systems and client programs are designed in accordance with security policies and guidelines

·         Investigate and manage security related incidents

·         Act as Minacs' representative for all security and/or Business Continuity audits, reviews, certifications or inquiries with internal and external clients.

·         Lead system owners through the management, process and mitigation of vulnerabilities including implementing system-hardening guidelines

·         Educate users concerning good security practices.

·         Assume coordinating responsibility for Business Continuity planning efforts, with a major focus on assuring adequacy of the contingency plans for critical business functions and applications, including developing and maintaining new and existing plans.

·         Developing and supporting security solutions.

·         Maintain documentation on security administration practices, policies and procedures.

·         Conduct annual testing of technology systems recovery strategy and provide management with a report documenting the results of the exercise identifying areas for improvement as appropriate.

·         Train selected internal personnel as Emergency Captains, to ensure appropriate coverage throughout the facility, in the event of emergencies, that may require evacuation, or other actions to protect the health and safety of facility personnel.

·         Conduct annual facility evacuation drills, to ensure an effective process is in place, and that all facility personnel are aware.

·         Define/architect physical security strategy.

·         Ensure functionality and maintenance of physical security controls, redundant power and environment detection systems.

·         Review new business opportunities to ensure proper privacy/security/business continuity requirements are appropriate, and adequately captured.

·         Review and approve change control requests.

·         Ensure compliance with all state and federal telemarketing compliance laws.

·         Stay current on all legislation regarding the telemarketing industry, including Do Not Call regulations,

·         Other duties as assigned by the Chief Security Privacy Officer.

 

Essential Qualifications:

·         Education/Knowledge:   Bachelor’s degree in Information Systems or a related field, or equivalent combination of education and relevant work experience is acceptable. We require three or more years of recent and relevant experience in the Information Systems and/or electronic information security area. Desirable Certification(s): CISSP certification or significant coursework toward certification, CISA, CBCP, SANS GIAC

 

·         Experience / Skill: Broad understanding of security technology. In depth understanding of information security policies and risk analysis. Ability to perform vulnerability identification, assessment and mitigation in heterogeneous environments. Ability to perform periodic internal audits to ensure compliance with Security policy and guidelines. Experience in dealing with a wide range of technical and non-technical personnel and issues. Have familiarity with vulnerability assessment and security auditing tools, security administration tools, security scanning tools, web application technologies, technical security implementations (Router ACLs Firewall Rules definition), multi-platform access controls, cryptography, digital certificate creation/administration, physical security controls and administration. Ability to instruct employees in security awareness and practices. Ability to relate business requirements and risks to technology implementation for security related issues. Strong oral and written communication skills  Working knowledge of MS Windows, and UNIX operating system controls and platforms. Knowledgeable of network operations, controls and components. In depth knowledge of business continuity disaster recovery concepts, controls and processes. Must work well under tight deadlines and schedules.

Minacs is an Equal Opportunity, Affirmative Action Employer

We thank all applicants however, only those under consideration will be notified.