Job Description
IT Security Manager
Job Announcement No: 25-062
Vacant Position(s): 1
Department: Information Technology
Applications Accepted through Sunday, June 15, 2025
Salary Range: $79,705.60 ($38.32/hr.) – $127,524.80 ($61.31/hr.)
Grade: 112
Hours: 8:00am – 5:00pm (Flexible)
Position Summary:
The IT Security Manager is responsible for the management and operation of all aspects of the safety and security of the information systems at CWS. Daily activities include vulnerability scanning and remediation, incident response, and planning and implementation of security measures within the information systems ecosphere, including but not limited to SCADA networks, administrative networks, and external facing products or applications.
Essential Functions:
•Performs system, network, and end-point audits and scans as required using industry standard methods and applications
•Utilize and maintain security tools such as firewalls, anti-malware software, and intrusion detection/prevention systems.
•Analyze external threats and exploits to determine the impact on the organization, i.e., email security, third party security alerts, cloud computing applications and services, etc.
•Work with Information Technology Operations Team to monitor daily activities on the network
•Work with SCADA system team to harden and protect SCADA networks and endpoints using ISA/IEC Framework/Standards or similar standards
•Work with IT, SCADA and other departments to ensure compliance with all applicable cyber security laws and initiatives, such as the America Water Infrastructure Act (AWIA) Risk and Resilience Assessment or PCI DSS
•Liaison for all enterprise information security matters, i.e., cyber insurance carriers, third-party entities, MSS, etc.
•Manage and monitor Cyber Awareness Training programs, i.e. KnowB4, associate on-boarding, monthly publications, etc.
•Assess and implement NIST Risk Management Framework or similar standard
•Create and maintain system security plans, risk assessment reviews, disaster recovery plans, standard operating instructions, and business impact analyses
•Respond to associate’s cybersecurity work requests and inquiries.
•Document and provide findings as part of the risk assessment process.
•Create regular reports and brief management on state of corporate security
•Work with Information Technology Development Team to maintain a Secure Software Development Life Cycle
•Apply a continuous improvement process when considering secure-by-design.
•Manage project tasks, timelines, deliverables, and communication
•Ability to be adaptive and flexible to support CWS and departmental priorities
•Other tasks as needed for successful project completion
•May be required to work during emergency conditions
•Regular attendance is required
•Job performance must conform to all CWS policies and procedures
•Specific knowledge of CWS Environmental Management System Policy and Procedures
Additional Duties
•Participate in departmental and corporate incentive, strategic, and/or ad hoc teams as assigned
•Perform other related duties as assigned.
Job Requirements
Physical Requirements, Activities, and Working Conditions
•Ability to operate a personal computer including keyboard and mouse.
•Ability to visually read computer monitor.
•Must be able to remain seated and operate a personal computer for extended periods of time.
•Ability to type 40 words per minute.
•Ability to receive detailed information through oral communication, written definitions and examples.
•Ability to convey detailed information to co-workers and customers accurately and quickly.
•Ability to operate motor vehicles
Education and/or Experience
•Bachelor’s degree in Computer Science, Information Systems, or Cybersecurity major required
•Minimum 3 years’ experience in either vulnerability management or related information security field
•Holds at least one (1) IT Security certification
•Experience in threat and vulnerability management, penetration testing, security operations
•Familiar with industry standard security best practices and vulnerability management processes including compliance reporting
•Advanced experience with vulnerability scanning tools and other vulnerability management tools
•Familiarity with multiple programming and scripting languages
•Demonstrate knowledge of networking concepts and devices - firewalls, routers, switches, and load balancers, DNS, VPNs, switching, subnetting, etc.
•Demonstrate an understanding of network and web related protocols, such a TCP/IP, UDP, IPSEC, HTTP, HTTPS, and routing protocols
•Experience developing and improving KPIs, metrics, and trending for vulnerability management functions
•Understanding of how applications, networking, operating systems, and databases work (basic command-line skills or knowledge)
•Familiarity with security tools and dashboards, i.e., SIEM, MXDR, EDR, IDS, IPS, Email Security, etc.
•Familiarity with automated service desk ticket system
•Strong communication and writing skills.
•Awareness and pride in 100% user satisfaction.
•SharePoint experience is preferred
•Ability to manage and develop complex projects independently.
•Good oral and written communications skills, demonstrating a good working relationship with customer base.
•Prior work record indicating dependability and conscientiousness.
Licenses, Certifications, Registrations
•Valid South Carolina Driver's License required.
Training Needs:
•OSHA and Departmental safety training as required.
•Standard Operating Instruction (SOI) per department requirements.
•ISO 14001 standards for department and company.
•See Department Competency and Training Matrix for this position.
Potential Career Path:
ELIGIBILITY FOR PROMOTION TO VARIOUS POSITIONS THROUGHOUT THE COMMISSION DEPENDS UPON INDIVIDUAL QUALIFICATIONS, AND NOTED JOB PROGRESSIONS ARE NO GUARANTEE OF CAREER PATH TO THESE OR ANY OTHER JOB(S) AT THE COMMISSION.
•Director of Information Technology