Security Lead

Posted yesterday

aquarius professional staffingCovington (KY)

SENIORITY

Manager

Apply

About the role

Are you a dedicated Security Specialist / Lead looking to be a vital asset to a very well known organization based in the downtown Cincinnati area? Don't miss your chance and apply now!Contract to HireWhat you will be doing as the Security Specialist / Lead: Develop, implement, maintain, and continuously improve CMSNet-wide cybersecurity policies, standards, procedures, and governance practices. Assist participating agencies in developing and implementing agency-specific security procedures that align with CMSNet requirements while recognizing individual agency governance authority and operational needs. Maintain alignment with applicable cybersecurity frameworks and requirements, including CIS Controls, the NIST Cybersecurity Framework, CJIS Security Policy, and relevant county and state requirements. Establish cybersecurity maturity objectives, performance measures, assessment methods, and reporting structures to evaluate and communicate the effectiveness of the cybersecurity program. Maintain a CMSNet-wide cybersecurity risk register and lead periodic, structured risk assessments across participating agencies. Assist agencies in interpreting and applying security obligations established through CJIS, Local Rules, Supreme Court Rules of Superintendence, and other applicable judicial, county, or regulatory requirements. Participate in CMSNet Steering Committee activities and provide cybersecurity expertise regarding policies, governance matters, risk considerations, and multi-agency security initiatives. Monitor emerging cybersecurity risks, regulatory developments, and industry practices and recommend appropriate changes to policies, procedures, and security controls. Lead cybersecurity incident response activities throughout the incident lifecycle, including preparation, detection, analysis, containment, eradication, recovery, and post-incident review. Maintain and regularly update the CMSNet Incident Response Plan, including defined responsibilities, communication protocols, escalation procedures, severity criteria, and notification requirements. Maintain incident response documentation and resources, including service-level expectations, response runbooks, contact information, notification trees, system references, and architecture documentation necessary to support an effective response. Coordinate multi-agency incident response activities with Network Support, Application Support, County Technical Services, LASOs, agency leadership, vendors, and other appropriate partners. Establish and maintain procedures for preserving cybersecurity evidence, including log retention, system imaging, documentation, and chain-of-custody requirements. Oversee CMSNet enterprise vulnerability management processes, including authenticated and unauthenticated internal and external vulnerability scanning. Review identified vulnerabilities, assess risk and remediation priorities, and coordinate corrective actions with Technical Services, agency information technology teams, system owners, and contracted vendors. Track vulnerability remediation efforts and communicate significant risks, unresolved vulnerabilities, and remediation progress to appropriate leadership and stakeholders. Oversee security governance related to service accounts, multifactor authentication, password requirements, privileged access, and other identity and access management practices. Serve as a primary cybersecurity advisor and resource for participating CMSNet agencies and agency leadership. Build and maintain productive working relationships with agency information technology teams, County Technical Services, LASOs, leadership, and other stakeholders to promote coordinated cybersecurity practices. Assist agencies with adopting or adapting CMSNet cybersecurity policies, standards, and practices while respecting individual agency governance and operational authority. Coordinate annual cybersecurity awareness and training programs across CMSNet agencies. Manage and monitor cybersecurity requirements applicable to vendors and third-party service providers, including CJIS background requirements, required security training, data protection obligations, and other contractual security requirements. Coordinate periodic vendor security reviews, risk assessments, compliance verification, and documentation requirements. Evaluate cybersecurity considerations associated with proposed technology acquisitions, hosted services, cloud environments, third-party integrations, and other external technology solutions. What you will need as the Security Specialist / Lead: Bachelor’s degree in IT, Cybersecurity, Computer Science, or equivalent experience.5+ years of hands-on cybersecurity experience in enterprise or government environments. System Implementation experience, ideally ERP.AWS experience Ability to work independently Broad understanding of security protocols and policies. Experience advising senior leadership on best practices for IT Security.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this