Role: Cyber and Physical Security Threat Assessment Specialist
Duration: 12 Months Contract
Work Type & Location: Conroe, Texas 77305-Onsite
The
Cyber and Physical Security Threat Assessment Specialist will be responsible for evaluating, identifying, and mitigating security risks across both cyber and physical domains. This position combines both the expertise in cybersecurity and physical security to deliver comprehensive threat assessments for an organization's assets, systems, and infrastructure. The specialist will work with internal teams and external stakeholders to assess vulnerabilities, develop security strategies, and recommend improvements to enhance overall organizational resilience.
Key Responsibilities - Cybersecurity Threat Assessment:
- Conduct comprehensive risk assessments to identify potential cyber threats and vulnerabilities across the organization’s IT infrastructure, applications, and networks.
- Analyze and evaluate cybersecurity risks related to software, hardware, and digital operations.
- Collaborate with IT and cybersecurity teams to ensure proper configuration, patching, and monitoring of systems.
- Implement penetration testing, vulnerability scanning, and threat modeling techniques.
- Monitor current threat intelligence sources to stay updated on emerging cyber threats.
- Provide recommendations to mitigate cyber risks and ensure compliance with relevant industry standards (e.g., NIST, ISO/IEC 27001).
- Physical Security Threat Assessment:
- Perform risk assessments related to physical security across facilities, personnel, and physical assets.
- Evaluate the effectiveness of current physical security measures (e.g., access control, surveillance systems, perimeter defenses, etc.).
- Conduct threat modeling for possible physical breaches, natural disasters, sabotage, or insider threats.
- Advise on the design and implementation of security systems, including physical access controls, surveillance equipment, and emergency response plans.
- Coordinate with building management and facilities teams to address any physical vulnerabilities identified.
- Integrated Threat Assessment:
- Develop and lead integrated threat assessments that combine both cyber and physical security risks.
- Analyze the interaction between cyber and physical security, assessing how one domain may affect or compromise the other.
- Propose holistic security strategies that protect both digital and physical environments.
- Reporting and Documentation:
- Prepare detailed reports outlining identified security risks, vulnerabilities, and recommended remediation strategies.
- Provide executive summaries and presentations for senior management and stakeholders.
- Maintain and update documentation on risk assessment processes, methodologies, and security policies.
- Collaboration and Consultation:
- Collaborate with cross-functional teams including IT, facilities management, legal, and risk management to ensure comprehensive threat assessments.
- Provide training and awareness programs for employees regarding physical and cyber security best practices.
- Engage with third-party vendors, contractors, and external security professionals when necessary.
- Compliance and Best Practices:
- Ensure that all threat assessments and security practices adhere to industry standards and regulatory requirements.
- Stay current with trends, regulatory changes, and new threats related to both cyber and physical security.
- Support incident response planning and business continuity efforts through integrated risk assessment activities.
Qualifications - Education:
- Bachelor’s degree in Cybersecurity, Information Technology, Criminal Justice, or a related field.
- Certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Protection Professional (CPP), or Certified Physical Security Professional (PSP) are preferred.
- Experience:
- At least 5 years of experience in cybersecurity, physical security, or a combined role that includes both domains.
- Proven track record in performing vulnerability assessments, threat modeling, risk assessments, and implementing security controls.
- Experience with threat intelligence tools, vulnerability scanning, and penetration testing tools.
- Knowledge of physical security systems, access control systems, and surveillance technology.
- Skills:
- Strong understanding of security frameworks, best practices, and regulatory requirements (e.g., NIST, ISO 27001, GDPR).
- Ability to communicate complex technical information to both technical and non-technical stakeholders.
- Excellent analytical, problem-solving, and critical-thinking skills.
- Strong attention to detail with the ability to manage multiple priorities and projects.
- Ability to work independently and as part of a team.