A
Statement of Qualifications (SOQ) is required for this position. The SOQ must
be no more than three (3) pages, single-spaced, with one-inch margins, in
12-point font, organized and numbered as reflected below. The SOQ must discuss
the applicant’s applicable experience as it pertains to each item below.
Applicants who do not follow these requirements may be disqualified from the
hiring process. A resume is required but does not take the place of the SOQ.
Letters and other materials will not be considered in the place of the SOQ.
You
must respond to all the following items:
1. Describe
your experience drafting and maintaining IT or information security documents,
such as policies, procedures, configuration guides, or security baselines.
Provide specific examples.
2. Explain
your familiarity with information security policies, standards, and frameworks
such as SAM, SIMM, NIST SP 800-53/171, CIS Benchmarks, DISA, STIGs and how you
have applied them in practice.
3. Provide
an example of when you assisted with or prepared documentation for an audit,
assessment, or compliance review. Explain your role and how your work
contributed to the outcome.
4. Describe
how you have communicated complex technical information to non-technical staff
or stakeholders. What strategies did you use to ensure clarity and adoption?
5. Describe your experience conducting risk
assessments and developing risk treatment plans. Include examples that
demonstrate how you identified, analyzed, prioritized, or mitigated risks.
NOTE:
Artificial intelligence (AI) tools such as ChatGPT, website searches, and
third-party reviewers can be helpful in researching responses to the SOQ;
however, by submitting your application for this position, you understand and
acknowledge the SOQ you submit is your own work, in your own words, and
accurately reflects your knowledge, skills, abilities, and experiences.
Submitting an SOQ that is not your own may be cause for disqualification from
the hiring process.