Information Security Program Specialist
Metropolitan Washington Airports Authority | |
United States, Virginia, Arlington | |
Jul 24, 2026 | |
|
Compensation Grade: S21Salary Range: $106,262.00-$154,080.00Opening Date: July 24, 2026Closing Date: August 8, 2026Please Note: All job announcements close at 11:59 p.m. of the day before the posted closing date. As an Information Security Program Specialist, you will support the Airports Authority's Information Security program by monitoring, testing and supporting existing security tools and researching and implementing new security tools.Information Security Program Specialist Serves in the Cyber Security Department in the Office of Technology at the Headquarters Office. Monitors, tests, and reports on security, confidentiality, integrity, and availability of the Airports Authority's information assets in compliance with national, industry and organizational regulations, policies and standards. Performs related functions. GENERAL RESPONSIBILITIES Serves as an internal information security subject matter expert on projects and other initiatives to identify security issues and mitigate them. Monitors, tests, and reports on user activity for adherence to security policies and procedures. Identifies user-related security problems and reports problem activity to appropriate managers. Recommends security solutions (e.g. firewalls, administrative controls), as appropriate. Regularly reviews regulations and monitors changes in legislation and accreditation standards affecting information security to support organizational compliance. Advises the Airports Authority on compliance issues and related security technologies. Serves as information security liaison for data owners, custodians, and users. Initiates and facilitates activities to create information security awareness within the Airports Authority. Reviews system-related security plans throughout the network; works closely with IT management to ensure that security is built in to all initiatives. Plans and schedules penetration testing, security appliance upgrades, and vulnerability assessments. Collects and reviews log files from various hosts on the network. Conducts network and system audits and continuous vulnerability assessments and prepares assessment reports. Conducts security review of new software systems and reviews and validates changes to production systems. Serves as a security team lead for security activities which involve external resources performing security tasks and other professional services (i.e. penetration tests, security assessments and audits). Monitors internal control systems to ensure appropriate access levels are maintained. Reviews and makes recommendations on the Business Continuity and Disaster Recovery Plans. May conduct information security risk assessments or collect forensic data for the Office of Legal Counsel or the Office of Human Resources. Performs other duties as assigned. QUALIFICATIONS Six years of progressively responsible experience in information technology security including applying industry and legal/regulatory standards and requirements (e.g., International Organization for Standardization (ISO), International Information Systems Security Certification Consortium ((ISC)2), Health Insurance Portability and Accountability Act (HIPAA), National Institute of Standards and Technology (NIST)) to network security for an organization. Knowledge of and ability to apply computer system/network techniques, requirements, sources, procedures, and specialized command languages, including firewall administration, for mainframe computers, Intel-based servers and workstations, workstation support, server administration; network device configuration, and data administration. Skill in effectively handling sensitive situations by ensuring that system security remains uncompromised and that evidentiary facts presented to management are based on expertly executed forensic investigation of system use/misuse. Ability to perform detailed analyses of data and information and make recommendations. Ability to speak and write effectively, with emphasis on communicating technical information to non-technical audiences. PREFERRED QUALIFICATIONS Certification as a Certified Information Security Manager (CISM) from the Information Systems Audit and Control Association (ISACA), Certified Information Systems Security Professional (CISSP) from (ISC)2, or Information Systems Security Engineering Professional (CISSP-ISSEP) from (ISC)2. EDUCATION A Bachelor's Degree in Information Security, Cybersecurity, Computer Science, or related field. CERTIFICATIONS AND LICENSES REQUIRED None. NECESSARY SPECIAL FACTORS Work is typically reviewed in progress and upon completion for quantity, quality, timeliness, teamwork, customer service, and other factors. May move computer equipment weighing up to 45 pounds. Is subject to hold-over and recall for IT emergencies and may need to work nights and weekends depending on operational requirements and other factors. #WP #DICE A background security investigation will be required for all new hires. Metropolitan Washington Airports Authority is an Equal Opportunity Employer.| Follow us on Twitter @MWAAcareers. | |
Jul 24, 2026