In addition to evaluating each candidate's relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate:
Experience monitoring and assessing security controls in the information system, including review of server logs, firewall activity, systems activity, and security alerts.
Experience investigating system alerts and security incidents or attacks, taking appropriate actions to reduce exposure and secure systems and data.
Ability to work independently and under direction in small teams as a technical specialist to test, enhance, and maintain network infrastructure to reduce risk and protect data.
Knowledge of procedures for incident handling, particularly for analyzing incident-related data and determining the appropriate response.
Experience conducting research into security vulnerabilities, suggesting solutions, and implementing risk mitigation strategies through patching and system configuration.
Ability to effectively communicate both in writing and verbally.