Systems Administration & Information Security Manager

University of North Alabama

Florence, AL

ID: 7225418
Posted: March 6, 2024
Application Deadline: Open Until Filled

Job Description

Description
This position is responsible for the daily operation, maintenance, and support of all server operating systems, application software, and appliances, as assigned. Additionally, this position manages the daily operations of systems administrators and security analysts. This position is also responsible for overseeing and managing information security.

Additional responsibilities include maintaining integrity and security of all server and appliance operating systems; designing and implementing server redundancy, survivability, protection, backup, and recovery systems; providing strategic guidance and coordination for information security risk and compliance management; verifying continuing needs for server hardware and software support agreements; determining the benefit versus risk of new software and hardware implementations; and conducting technical reviews of all special projects connecting with or having a potential impact on university server-based applications.

This position will serve as the primary technical resource for all of the information security programs/needs and is responsible for developing and implementing information security administrative educational plans. This position works closely with CIO and other ITS leadership to ensure consistent and high-quality IT services are provided to all constituents, including students, faculty, and staff.

Essential Job Duties
Manage, oversee, and backup daily operations of systems administrators as well as the management and maintenance of systems, including but not limited to: Microsoft environment (on-campus and cloud), System Center environment, backup environment, virtual environment, and user shares;
Manage and maintain Linux environment;
Maintain a comprehensive information security program and lead information security planning efforts in support of information systems and processes;
Oversee and manage backup and recovery systems for campus servers and appliances, including both on-campus and cloud options;
Design, oversee, and manage strategies for utilization of on-campus and cloud resources, including Microsoft resources, backup tools, etc.
Responsible for policy and procedure development, implementation, and compliance regarding information security guidelines and requirements for both on-premise and cloud-based systems;
Develop, coordinate, and lead security orientation and security awareness training programs and communications for campus;
Coordinate, support, and perform security reviews, audits, and risk assessments;
In direct consultation with supervisor, develop and maintain the university security incident response plan and serve as the primary contact during significant information security incidents;
Monitor and audit the information and data security environment in accordance with best practices and standards;
Serve as a resource for all information security issues to the University community;
Provide periodic reporting on IT risk and compliance issues to supervisor and/or administration;
Work with vendors to retrieve software/hardware renewals and/or upgrade price quotes;
Read literature, participate in conferences, and perform other related activities in order to understand the leading-edge developments in IT-related and information security-related fields;
Perform all other duties as assigned.

ADDITIONAL DUTIES:
Review, configure, and monitor on-campus and cloud-based systems for functionality and availability;
Assist team members in implementing, upgrading, monitoring, and maintaining campus applications such as email, calendar, portal, etc.;
Design, implement, manage, and monitor technical, administrative, and physical controls to protect the confidentiality, integrity, and availability of information resources;
Assist team members in installing, maintaining, monitoring, and supporting integration between active directory, ERP, portal, and learning management systems;
Oversee team members in the creation, support, documentation, and security of file shares for campus users;
Perform operational, compliance, and consultative functions to include providing guidance and oversight for vulnerability management and system hardening;
Provide technical assistance for security reviews, audits, and risk assessments;
Participate in developing data protection strategies and disaster recovery planning for university information systems;
Provide technical expertise and assistance in support of policy and procedure development, implementation, and compliance;
Log and monitor security events for network, database, processing, storage, backup, firewall, endpoint, IPS products, and other information security systems;
Perform regular network and system vulnerability scans;
Coordinate information security efforts with other departmental staff and other campus departments;
Serve as primary system administrator for spam filtering, multi-factor authentication, security certificate management, single-sign-on, and privilege access management systems;
Monitor email and provide remediation for spam and phishing attacks;
Works with various departments in designing and implementing new IT-related projects, as they relate to information security;
Provide guidance, strategic planning, management, purchase or renewal options, etc. for security incident event management (SIEM), both in the cloud and on premises;
Serve as GDPR data protection officer;
On call 24x7 to ensure accessibility, data integrity, information security compliance, incident response, and other functions;
Represent the department and university at a variety of on-campus meetings or off-campus technical or information security conferences or events;
Responsible for ensuring necessary documentation is complete and kept up-to-date;
Considered one of staff subject matter expert in area.
Minimum Qualifications
Bachelor's degree in a related field is required;
Five years of systems administration or information security-related experience is required;
Supervisory experience is required;
Security, risk, and/or compliance experience is preferred;
Project management experience is preferred;
Experience in security information and event management, security incident tracking, end-point protection, cloud services security, and/or encryption is preferred.

LICENSES, CERTIFICATIONS, OR REGISTRATIONS:
Security+ certification required;
Certified Information Systems Security Professional (CISSP) is preferred;
Certified Information Security Manager (CISM) certification is preferred;
Microsoft, Linux, or other OS certifications are preferred.