Security Analyst Iii positions focus on delivering results in their domain. This page aggregates open Security Analyst Iii roles and what employers typically expect.
Under limited supervision, Security Analyst III position is responsible for technical aspects of information security within the South Carolina Judicial Branch (SCJB), as well as for implementation of industry standard security controls that are applied consistently throughout our organization. Reports to and works closely with the Chief Information Security Office in the implementation of technical controls to safeguard the electronic data, communications, and physical and intangible assets within SCJB. **ESSENTIAL DUTIES AND RESPONSIBILITIES OF THE POSITION** Physical, virtual, & web application Firewall management. Applies technical analysis of data security information and uses critical thinking and troubleshooting skills to resolve security incidents, as reported either by end users, other IT teams, or as evident from routine log analysis. Modifies firewall security rules to accommodate changing network environment while maintaining best practices in security. Manage VPN technology used by IT department and vendors. Performs hardware & software upgrades to existing firewall devices and installs new firewall devices as needed for growth. Endpoint Security management. Uses SCJB-approved software on all SCJB workstations (local & remote) and Servers to analyze suspicious data traffic, such as, but not limited to, browsing malicious websites or downloading malicious files. Acts on automatically generated reports to follow up on suspicious activity, running security scans or collaborating with the IT Help Desk for additional scans and user assistance as needed. Assist in running internet usage reports as requested by management to monitor appropriate usage of SCJB resources. Email Security monitoring. Receives, investigates, and sends alerts upon reports of suspicious email by end users or email filtering system. Updates email filtering system as needed to prevent ingress of malicious email. Two Factor Authentication management. Monitors and maintains health of the two factor authentication system for SCJB user accounts, to prevent unauthorized remote access to SCJB systems. Responds to escalations from IT Help Desk concerning any issues with system, such as access failures. Physical Security system monitoring. Collaborates with Security Coordinator in HR, BPS officers, and General Services to troubleshoot technical issues with building access control and video system, utilizing contracted vendor for hands-on support. Coordinate changes, maintenance, and installation of new systems with affected personnel. Logging & Security Monitoring. Uses internal enterprise logging system to investigate security issues and anomalies. Integrate new log sources, both on-prem and cloud, and maintain health of logging system. Responds to alerts provided by external security monitoring vendor, creating security incidents as needed to remediate any issues. Security Awareness coordination. Assists with the setup and maintenance of our security awareness training portal. Assists with periodic security training assigned to staff, and works closely with IT Help Desk to investigate and resolve issues. Designs and distributes Phishing Assessments on periodic basis to test employees security awareness. Data Encryption. Supports best practices of encrypting sensitive data over Email by management of Email DLP system. Works in advisory capacity to Networking to ensure endpoint device encryption adheres to security best practice. Research, Test, and Implement new security systems. Will work with the Chief Information Security Officer in the design, creation, and testing of new security systems as approved by SCJB. Works closely with other teams as needed to coordinate testing, installation, and communication. Produces documentation on newly-developed security systems that is useful for the average computer user, where such systems require interaction with the user. Conducts vulnerability scans for existing and new systems introduced by IT Development tea…