Jobs
>
Saint Paul

    Data Security Consultant - Saint Paul, United States - Quetica, LLC

    Quetica, LLC
    Quetica, LLC Saint Paul, United States

    1 month ago

    Show more Collapse job
    Default job background
    Description

    Job Description

    Job Description

    Quetica is seeking a part-time Data Security Consultant and Local Agency Security Officer resource to work with the Minnesota Department of Public Safety (DPS) and Driver and Vehicle Services (DVS) to conduct comprehensive audits of data systems including its infrastructure, policies and procedures, to assure: 1) all data meets or exceeds federal Criminal Justice Information Services (CJIS) security guidelines; 2) are Payment Card Industry (PCI) compliant; and 3) meet or exceed current "best practices" regarding driver's license and motor vehicle data security; and to serve as a Local Agency Security Officer (LASO) for DVS's use of CJIS.

    At a high level, the resource will act as the primary information security contact between DVS and the CJIS System Agency (CSA) under which DVS interfaces with the Federal Bureau of Investigation (FBI) CJIS Division and the Minnesota Bureau of Criminal Apprehension (BCA). The Local Agency Security Officer (LASO) actively represents DVS in all matters pertaining to information security, disseminates information security alerts and other material to constituents, and maintains information security documentation to include system configuration files. The LASO will assist with information security audits or hardware and procedures, and keeps the CSA informed as to any information security needs and problems.

    The part-time work is expected to be done remotely.

    Sample Tasks include:
    • Assist with evaluation of architecture interfacing with other state/federal/local systems.
    • Assist with assessing the security of any equipment needed.
    • Assist with the evaluation of data integrity and data security.
    • Assist with ensuring all background check compliance is met for all project team members.
    • Assist with creating procedures to ensure the proper access rights are granted.
    • Assist in building User Acceptance Testing (UAT) scenarios to ensure security requirements are properly tested and documented.
    • Assist with architecture reviews of all environments.
    • Assist with the evaluation and testing of disaster recovery plans.
    • Assist with the development of change management processes and procedure projects.
    • Provide written documentation and recommendations.
    • Review agency network diagrams and access control lists (ACL) for compliance with FBI CJIS Security Policy and BCA CJDN Security Policy.
    • Work with DVS staff, review IT security audit documentation from local agencies which access DVS systems and data to determine compliance with FBI CJIS Security Policy and BCA CJDN Security Policy requirements.
    • Provide technical guidance, principles, standards, and best practices to guide criminal justice agency infrastructure design and system implementations to comply with FBI CJIS Security Policy and BCA CJDN Security Policy.
    • Perform technical analysis of vendor solutions to assess compliance with FBI CJIS Security Policy and BCA CJDN Security Policy.

    Access public government data to the extent allowable by law, including data in the State's possession that would otherwise be classified as not public under Minnesota Statutes section Analyze security needs for all DVS projects, DVS systems, and systems that interface with DVS systems. Transition and train new DVS security staff for duties including: Work with DPS agencies and other government entities to ensure driver and vehicle data is accessible for utilization for mission critical functions while maintaining all security requirements.

    • Deputy Registrar Security
    • Identity Access Management (AIM)
    • PCI Compliance
    • Policy Auditing
    DVS securities and LASO duties
    • DVS Securities duties will include:
      • Deputy Registrar Security
      • IAM
      • PCI Compliance
      • Policy Auditing
      • Physical Security of Facilities
      • Fraud and Investigations
      • ADLMV Management
      • Technical Review/Architect
    • The LASO duties will include:
      • Identify who is using the CSA approved hardware, software, and firmware and ensure no unauthorized individuals or processes have access to the same.
      • Identify and document how the equipment is connected to the state system.
      • Ensure that personnel security screening procedures are being followed as stated in FBI CJIS Security Policy and the MNJIS 5002 policy
      • Ensure the approved and appropriate security measures are in place and working as expected.
      • Support policy compliance and ensure the CSA ISO is promptly informed of security incidents.
      • Conduct an annual audit of CJIS compliance and track remediation efforts on any items found
      • Maintaining CJIS compliant network architecture
      • Properly vetting all individuals with access to DVS physical and logical resources through the access control systems and best IAM practices
      • Properly vetting all software and hardware vendors for CJIS compliance
      • Working closely with MN.IT to utilize enterprise resources when possible and involving MN.IT on all technical projects
      • Active involvement in all data access requests that may contain CJI to ensure CJI is protected accordingly
      • Work through vendor agreements to ensure all security requirements are met or exceeded
      • Reviewing MN.IT scans of DVS resources and monitoring identified vulnerabilities and remediation efforts
    Provide knowledge transfer. Audit identity and access management to assure they are properly managed and maintained for all systems utilized to access driver's license and motor vehicle registration data; and recommend remedial action when required. Audit the driver's license and motor vehicle systems for PCI compliance; and recommend remedial action when required.Minimum Qualifications
    • Six (6) years' experience in a security architect or engineer role.
    • Three (3) years' experience in network engineering, including firewall management.
    • Four (4) or more engagements, within the last ten (10) years, in a security architect or engineer role where the engagement was longer than three months each.
    • Experience with the design and implementation of information systems, in organizations with more than 50 people, with an emphasis on data, network, and infrastructure security.
    • CISSP or GIAC certification.
    • Comprehensive knowledge of hardware, software, application, and systems engineering.
    • Broad knowledge of database systems, web-based technologies, and network security.
    • Systems thinking – the ability to see how parts interact with the whole ("big picture" thinking).
    • Knowledge of IT governance and operations.
    • Interpersonal and leadership skills – servant leadership, collaboration, facilitation, and negotiation skills.
    • Communication skills – both written and verbal.
    • Ability to explain complex technical issues in a way that non-technical people may understand.
    • Time management and prioritization.
    Mode of Interview

    Interviews will be conducted remotely via Microsoft Teams.

    Project Schedule

    Anticipated Project Start Date: July 1, 2024
    Anticipated Project End Date: June 30, 2026

    Company Overview

    Quetica is a specialized consulting and product development firm led by industry experts with deep expertise in engineering, information technology and big data solutions. Quetica helps state and government agencies, commercial clients and financial institutions globally to efficiently and effectively accelerate business growth, achieve sustainable cost reduction and accomplish better service levels through delivery of hands-on practical expertise and world class solutions.

    Powered by JazzHR

    jfjrRix5Uh


    We have other current jobs related to this field that you can find below


  • Infinity Systems Oakdale, United States

    The German Pension Insurance Association is the largest pension insurance provider in Germany and a cornerstone of social security in the country. We accompany people throughout their entire lives - from the beginning of their career to retirement. 23.3 million insured persons, 9 ...


  • Securian St. Paul, United States Regular, Full time

    At Securian Financial the internal title for this position is Info Security Consultant or Info Security Sr Con. The title and salary will be determined based on experience and applied skills. · Position Overview · The Cybersecurity Risk Consultant operates within the Cybersecuri ...


  • Hollstadt Consulting Minneapolis, United States

    Title - Data Security Consultant · Anticipated Project Start Date: July 1, 2024 · Anticipated End Date: June 30, 2026 · Location: Hybrid - St. Paul · Part-Time hours · Desired Skills: · Six (6) years' experience in a security architect or engineer role. · Three (3) years' experie ...


  • QSI Corporation Minneapolis, United States

    Information Security Consultant, Sr. ** Contract to Hire ** · The company is seeking an experienced Information Security Consultant for a contract to hire opportunity in our Information Security and Risk Management division. This is an information security governance/oversight po ...


  • Genesis10 St. Paul, United States Temporary, Full time

    Genesis10 is seeking a Data Security Consultant and Local Agency Security Officer (LASO) for a contract with our client in St. Paul, MN. 100% Remote. · Key Responsibilities: Assist with evaluation of architecture interfacing with other state/federal/local systems. · Assist with a ...


  • Article Ted Minneapolis, United States

    WEx is a full-service Nationwide Security Management and Consulting firm specializing in providing professional security solutions. · Watson Express offers top notch consulting services. Its our job to protect our clients assets and make sure their business is secure. We will de ...


  • NetSP Minneapolis, United States

    Category · Services · Description · NetSPI is the proactive security solution used to discover, prioritize, and remediate security vulnerabilities of the highest importance. We help secure the most trusted brands on Earth with our Penetration Testing as a Service (PTaaS), Attack ...


  • ADT Minneapolis, United States

    Job Description · Company Overview: · The next generation of ADT Commercial is here. At Everon, we truly believe that our people are the difference - for our organization, the customers we serve and the communities we protect. When you're a part of Everon, you'll have the oppor ...


  • Hollstadt Consulting Minneapolis, United States

    Title - Data Security Consultant · Anticipated Project Start Date: July 1, 2024 · Anticipated End Date: June 30, 2026 · Location: Hybrid - St. Paul · Part-Time hours · Desired Skills: · Six (6) years' experience in a security architect or engineer role. · Three (3) years' experie ...


  • Everon Minneapolis, United States

    Company Overview: · The next generation of ADT Commercial is here. At Everon, we truly believe that our people are the difference – for our organization, the customers we serve and the communities we protect. When you're a part of Everon, you'll have the opportunity to be a part ...


  • Everon Minneapolis, United States

    Company Overview: · The next generation of ADT Commercial is here. At Everon, we truly believe that our people are the difference – for our organization, the customers we serve and the communities we protect. When you're a part of Everon, you'll have the opportunity to be a part ...


  • Low Voltage Contractors Minneapolis, United States

    **About You:** We are looking for a Security Sales Consultant who will s **Benefits:** Competitive pay starting at $75,000 plus commissions and a potential sign-on bonus depending on experience and qualifications. A full benefits package which includes: Health, Dental, Vision, Di ...


  • Hollstadt Consulting Minneapolis, United States

    Title - Data Security Consultant · Anticipated Project Start Date: July 1, 2024 · Anticipated End Date: June 30, 2026 · Location: Hybrid - St. Paul · Part-Time hours · Desired Skills: · Six (6) years experience in a security architect or engineer role. · Three (3) years ex ...


  • Low Voltage Contractors Minneapolis, United States

    **About You:** We are looking for a Security Sales Consultant who will s **Benefits:** Competitive pay starting at $75,000 plus commissions and a potential sign-on bonus depending on experience and qualifications. · A full benefits package which includes: Health, Dental, Vision, ...


  • Honeywell Golden Valley, MN, United States

    Innovate to solve the world's most important challengesAs an Advanced Cyber Security Architect/Engineer at Honeywell, you will lead the design and implementation of cutting-edge cybersecurity solutions, assessing and evaluating the security posture of a variety of Honeywell Produ ...


  • Securian Financial Group Champlin, United States

    Job Description · At Securian Financial the internal title for this position is Info Security Consultant or Info Security Sr Con. The title and salary will be determined based on experience and applied skills. · Position Overview · The Cybersecurity Risk Consultant operates with ...


  • Article Ted Minneapolis, United States

    WEx is a full-service Nationwide Security Management and Consulting firm specializing in providing professional security solutions. · Watson Express offers top notch consulting services. It's our job to protect our clients assets and make sure their business is secure. We will de ...


  • DEFENDERS Minneapolis, United States

    Company Overview: · The next generation of ADT Commercial is here. At Everon, we truly believe that our people are the difference - for our organization, the customers we serve and the communities we protect. When you're a part of Everon, you'll have the opportunity to be a part ...


  • Entrust Shakopee, United States

    Career Growth, Flexibility and Collaboration · Entrust is dedicated to keeping the world moving safely by enabling trusted identities, payments, and data protection around the globe. Headquartered in Minnesota, we offer our colleagues the ability to work globally, in a flexible a ...


  • Gillette Children's Saint Paul, United States Full time

    This position provides leadership and strategic planning for all Gillette Children's properties. Major responsibilities include safety, security, emergency management, real estate planning, construction, design and project management, and space allocation. · This position exists ...