In addition to evaluating each candidate's relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate:
* Knowledge of Information Security Concepts, Risks, and Best Practices* Information Security Certification(s) in active status is desirable.
* Experience in security control frameworks and practical application (NIST 800-53, etc.)
* Well developed analytical skills to evaluate current security practices and potential security risks.
* Experience in security Incident management using NIST frameworks
* Experience in using one or more Security Vulnerability scan tools.
* Experience applying federal state, and/or local security policies, standards, and procedures.
* Knowledge of Infrastructure as a Service environments such as AWS.
* Knowledge of Security Information and Event Management (SIEM) tools such as Splunk.