Information Security Lead
Please Note: This is not a student worker position. It is a full-time position with Amarillo College, posted by the Human Resources Recruiting team. For additional employment info, visit the Amarillo College Job Board on NEOED.
Summary
At Amarillo College, our mission is: Transforming our community and economy through learning, innovation, and achievement. Every team member, regardless of job title or duties, is responsible first and foremost, for assisting students in every way.
This is an exciting time to work for Amarillo College! We are seeking our next Information Security Lead who will be all-in on our mission and who works collaboratively with all areas of Information Technology and other functions of the College to ensure compliance with the State of Texas Department of Information Resources (DIR) information security requirements. This position supports and implements information security initiatives required by the Texas Administrative Code, Chapter 202, and assists in protecting the confidentiality, integrity, and availability of Amarillo College’s information systems and data.
Qualifications
EDUCATION:
Required: Associate’s Degree in Computer Information Systems (CIS), Networking, or a related field; or an equivalent combination of education and experience.
Preferred: Bachelor’s Degree in Computer Information Systems (CIS), networking, or a related field.
EXPERIENCE:
Required:
- Two (2) years of hands-on networking and/or information security experience.
- An equivalent combination of education and experience may be considered. Three (3) additional years of directly related experience may be substituted in place of the required Associate’s degree.
Preferred: Experience working in a higher education and familiarity with Texas DIR Security Requirements.
Job Duties & Responsibilities
- Develop and maintain an agency-wide information security plan in accordance with §2054.133, Texas Government Code.
- Create, update, and enforce information security policies and procedures to support compliance requirements and mitigate security risks.
- Collaborate with business and technical teams to implement security controls that meet compliance standards and institutional security objectives.
- Provide training and direction to personnel with significant information security responsibilities.
- Offer guidance and support to College leadership, information owners, custodians, and end users regarding compliance and security responsibilities under government regulations.
- Ensure annual information security risk assessments are completed and documented by information owners.
- Maintain and review an inventory of information systems to ensure clear ownership and accountability.
- Develop, propose, and enforce policies related to information security.
- Establish and coordinate procedures with the CIO, IT Infrastructure Manager, information owners, and custodians to protect information resources from unauthorized modification, destruction, or disclosure.
- Coordinate data security reviews, including risk assessments of third-party vendors, for new applications or services handling confidential data.
- Verify security requirements are defined and risk mitigation plans are implemented prior to acquiring new IT hardware, software, or systems that handle high-impact or confidential data.
- Report annually on the effectiveness of security controls and the overall institutional security posture.
- Notify supervisors of any non-compliance with applicable regulations or security policies.
- Develop and maintain onsite security manuals and documentation to support security initiatives.
- Submit required monthly state security reports to maintain regulatory compliance.
- Manage and maintain the Remote Monitoring and Management (RMM) solution, including report generation, system updates, and optimization scripts.
- Monitor Endpoint Detection and Response (EDR) alerts to ensure timely identification and response to potential security threats.
- Ensure Software-as-a-Service (SaaS) solutions comply with TxRamp or FedRamp standards to maintain regulatory and security compliance.
- Conduct periodic phishing simulations to help employees identify and respond appropriately to cybersecurity threats.
- Coordinate external penetration testing through the Department of Information Resources (DIR) to identify and address potential security vulnerabilities.
- Enforce cybersecurity training compliance and disable system access for users who are not compliant with required security training.
- Participate in and complete performance evaluations and assessments as assigned.
- Perform other work-related duties as required.
- As an Amarillo College employee, seek knowledge of and pledge to actively engage in a culture of caring striving to serve students, peers and the community by embracing the AC Core Values: Wow, Family, Fun, Innovation, and Yes!
Knowledge, Skills & Abilities
- Ability to work effectively with diverse users of varying technical skill levels.
- Knowledge of Cisco networking environments and proficiency with current operating systems for PCs and servers.
- Familiarity with software development practices and industry standards.
- Professional demeanor when interacting with students, faculty, staff, and external partners.
- Ability to remain calm and composed when addressing resistance, indifference, or challenging situations.
- Ability to work independently as well as collaboratively within a team environment.
- Ability to perform effectively under pressure while managing multiple priorities and deadlines.
- Knowledge of college and departmental policies, procedures, and safety regulations.
- Ability to adapt to changing priorities and evolving technology environments.
- Ability to maintain a positive and collaborative team environment during challenging situations.
- Demonstrated initiative, commitment, and dedication to achieving project and team objectives.
- Strong analytical and problem-solving skills with the ability to develop solutions for complex technical issues.
- Ability to comply with all college, state, and local procedures, rules, and regulations.
- Ability to maintain professionalism while supporting students, faculty, staff, visitors, and colleagues.
Salary: Amarillo College follows a lag pay strategy, with starting offers typically between the minimum and midpoint of the pay grade, rarely reaching the maximum to support long-term growth within each position.
Pay grade 14 Amarillo College Pay Grades (salary is determined by Human Resources based on education, work experience and internal comparisons).
Physical Demands: While performing the duties of this job, the employee is frequently required to travel between offices and buildings, and requires the ability to lift, carry, push, pull and/or maneuver office supplies up to twenty-five (25) pounds as needed.
Working Conditions: Must be willing to work a flexible schedule (days, nights, weekends, holidays, and varying events if necessary).
Work Environment: This position operates in a professional office environment and routinely uses standard office equipment including computers, phones, copy machines, and filing systems. The work environment may involve frequent interruptions in a high-traffic area. Software commonly used includes Microsoft Office, Colleague, and other educational and security-related applications. Work may occasionally occur outside the office environment with minimal supervision.
Notice of Background: Applicants selected for employment will be required to undergo a pre-employment criminal history background check and possibly a pre-employment drug test.
Promotional Opportunity Policy: Under the Amarillo College Promotional Opportunity Policy, only current appointed or part-time non-appointed employees will be considered for a position during the first five (5) working days from notice or posting.
Amarillo College is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, disability, or protected veteran status.