Review and provide feedback on build and hardening documentation:
Receive hardening guides from technology teams and review them for accuracy, completeness, and compliance with industry standards such as CIS, DISA, vendor, etc.
Provide consultation and feedback on deviations and exceptions to hardening requirements
Contribute to the development of internal hardening standards for operating systems, middleware, network devices, and other technology as required, including but not limited to:
Windows, Linux, Unix, F5, Cisco, macOS, etc.
Build and maintain hardening compliance policies in Qualys:
Use the Qualys Policy Compliance module to create scan policies aligned with the Citizens tailored hardening standards
Tailor and scope controls and policies to match organizational requirements
Work closely with technology and enterprise architecture stakeholders to maintain workflow efficiency
Develop and improve governance for hardening compliance:
Work closely with enterprise data stakeholders to develop metrics and visualizations for policy compliance
Develop, maintain, and continuously improve reporting to various enterprise architecture layers
Create automated workflows for data gathering, analysis, and reporting
Create tracking metrics for exceptions to the standard configurations
Review and provide feedback on build and hardening documentation:
Receive hardening guides from technology teams and review them for accuracy, completeness, and compliance with industry standards such as CIS, DISA, vendor, etc.
Provide consultation and feedback on deviations and exceptions to hardening requirements
Contribute to the development of internal hardening standards for operating systems, middleware, network devices, and other technology as required, including but not limited to:
Windows, Linux, Unix, F5, Cisco, macOS, etc.
Build and maintain hardening compliance policies in Qualys:
Use the Qualys Policy Compliance module to create scan policies aligned with the Citizens tailored hardening standards
Tailor and scope controls and policies to match organizational requirements
Work closely with technology and enterprise architecture stakeholders to maintain workflow efficiency
Develop and improve governance for hardening compliance:
Work closely with enterprise data stakeholders to develop metrics and visualizations for policy compliance
Develop, maintain, and continuously improve reporting to various enterprise architecture layers
Create automated workflows for data gathering, analysis, and reporting
Create tracking metrics for exceptions to the standard configurations