Educause Security Discussion mailing list archives

Job Posting: Security/Disaster Recovery Analyst at DePaul University in Chicago


From: "Yetnikoff, Arlene" <AYETNIKO () DEPAUL EDU>
Date: Fri, 16 May 2008 08:02:46 -0500

DePaul University is seeking applicants to fill a full-time
Security/Disaster Recovery Analyst position. 

To apply, please visit
https://hr.depaul.edu/careers/Jobs/opportunities.html and select
US-Illinois-Chicago as Location and Information Technology as
Information Technology as Category.  The requisition number on the next
screen is 15447.


Position title: Security/Disaster Recovery Analyst


Reporting to the Director of Information Security, the Security/Disaster
Recovery Analyst is responsible for supporting the integrity of the
University's Information Systems, the recoverability of the Information
Services data center environment and for helping provide a safe
computing environment in support of DePaul University's mission of
education, community service and research.

The Security/Disaster Recovery Analyst will work with system
administrators and engineers in the Information Services division and
other DePaul University divisions to review, implement and maintain
security measurements, policies and procedures throughout the
university.  The Security/Disaster Recovery Analyst will provide a safe
computing environment and help ensure the integrity of the university's
computer systems and the personal privacy of its users.      

The Security/Disaster Recovery Analyst is responsible for assisting in
the development of procedures to ensure the Information Services
division can respond to a disaster and that the data center information
technology resources for critical business functions can be resumed
within a defined time frame, the amount of loss can be minimized, and
any stricken information processing facilities can be repaired or
replaced as quickly as possible.  This includes assisting in the design,
development, maintenance, and exercising (testing) of the overall
disaster recovery plans for information processing of each critical
functional area of the organization. The Analyst will also be
responsible for leading any actual disaster recovery effort. 
  

*       Under general direction, assists in the coordination and
establishment of disaster recovery programs and business resumption
planning across critical business functions processed in the Information
Services data centers. Coordinates and monitors simulation testing
across all platforms. Aids in investigation, planning, documentation,
implementation, and maintenance of disaster recovery plans. Typically
requires a Bachelor's degree and one to three years of experience.


*       Under general direction, develops and maintains secure code
development practices.  Interfaces with application development teams to
assist in ensuring secure coding practices are followed.  Performs
security reviews of application systems.  Requires understanding of
application development methodologies and life cycles and ability to
understand software security assessment.

*       Under general direction, performs all procedures necessary to
ensure the safety of information systems assets and to protect systems
from intentional or inadvertent access or destruction. Interfaces with
user community to understand their security needs and implements
procedures to accommodate them. Ensures that the user community
understands and adheres to necessary procedures to maintain security.
Conducts accurate evaluation of the level of security required. May
require understanding of firewall theory and configuration. Must be able
to weigh business needs against security concerns and articulate issues
to management.


Principal Duties and Responsibilities:

1.      Assist in development and maintenance of secure code development
practices.  Interface with application development teams to assist in
ensuring secure coding practices are followed.  

2.      Performs security reviews of application systems.

3.      Conducts business impact analyses and assists University units
in determining critical business processes, identifying acceptable
recovery time periods, and establishing resources required for the
successful resumption of business-critical processing in the Information
Services data centers in the event of a disaster. 

4.      Establishes disaster recovery testing methodologies; plans and
coordinates the testing of recovery support and business resumption
procedures for Information Services data centers. Assures that recovery
procedures are effective for the restoration of key corporate resources
and for the resumption of critical data center information processing.

5.      Assists with conducting and designing disaster recovery training
for staff members in Information Services. Helps develop and review the
university data center and division emergency response procedures and
revises the procedures as necessary.

6.      Assists management in the development, review, and communication
of security policies and procedures. 


7.      Proactively identify project "problem areas" and create action
plans for quick resolution and enable appropriate parties to complete
work efficiently and effectively and help to remove barriers that will
slow team progress in security and disaster recovery areas.  Assist
management and project team members in the conflict resolution process. 

8.      Other duties as assigned.
        

Minimum Knowledge, Skills and Abilities (KSA's) required:
*       An intermediate knowledge of and experience in application
system coding environments and techniques.
*       An intermediate understanding of current disaster recovery
planning techniques and technologies as well as the methods used in
performing risk analyses and business impact analyses.
*       Working knowledge of data processing in order to assist in the
preparation of recovery procedures 
*       Strong understanding of application and system security concepts
and practices; good understanding of networking technology
*       Ability to plan and organize the testing of emergency response,
recovery support, and business resumption procedures.
*       Strong organizational and project planning skills.
*       Solid oral communication and written communication skills.
*       Must have working knowledge of Microsoft Word, Project, Excel 

Position Qualifications:
*       Bachelors Degree or equivalent work experience
*       3-5 years experience in Business Continuity/Disaster Recovery
and Information Security preferred

Current thread: