City of Roswell, Georgia
JOB DESCRIPTION www.roswellgov.com/jobs
To perform this job successfully, an individual must be able to perform the essential job functions satisfactorily. Reasonable accommodations may be made to enable individuals with disabilities to perform the primary job functions herein described. Since every duty associated with this position may not be described herein, employees may be required to perform duties not specifically spelled out in the job description, but which may be reasonably considered to be incidental in the performing of their duties just as though they were actually written out in this job description.
Department: Administration
Pay Grade: 515
FLSA Status: Exempt
JOB SUMMARY
The Security Lead is responsible for the City's information security program and serves as the department's dedicated cybersecurity subject matter expert. This position leads security operations, network and perimeter security, physical security systems, artificial intelligence governance, risk and vulnerability management, incident response, security awareness, and compliance activities that protect the confidentiality, integrity, and availability of the City's systems, data, and facilities.
Working in close partnership with the Information Technology Director and the Service Manager, the Security Lead strengthens the City's security posture and resilience against evolving cyber threats, and ensures compliance with applicable laws, regulations, and standards. This is a focused, hands-on security role that influences practices across infrastructure, applications, end-user operations, and the City's physical security technology without direct supervisory responsibility. The role recognizes that cyber and physical security are converged disciplines, and that access control, surveillance, and facility protection are integral to the overall security program. The position also serves as the City's lead for the safe and compliant adoption of artificial intelligence, guiding how these tools are evaluated, deployed, and monitored across departments.
ESSENTIAL JOB FUNCTIONS
Security Program and Governance
- Leads the City's information security program, including security strategy, standards, policies, and procedures aligned with recognized frameworks and best practices.
- Drafts and proposes security policies and procedures, and maintains current knowledge of security trends, threats, and advancements.
- Serves as the primary security advisor to the Information Technology Director and to departments on security matters.
Risk, Threat, and Vulnerability Management
- Conducts and coordinates threat and vulnerability assessments and recommends and implements remediation and safeguards against threats such as malware, ransomware, and intrusion.
- Identifies, evaluates, and prioritizes security risks, and recommends projects and controls to reduce exposure.
- Reviews infrastructure, application, and access configurations for security gaps in partnership with operations staff.
Network and Perimeter Security
- Administers and maintains the City's firewalls, including rule set design, change review, firmware and patch management, logging, and periodic rule recertification to remove unused or overly permissive access.
- Manages virtual private network (VPN) and secure remote access services for staff, remote sites, and third-party vendors, including multifactor authentication, certificate and credential lifecycle, session logging, and timely revocation of access.
- Designs and maintains network segmentation that isolates sensitive environments, including criminal justice information systems, operational technology, physical security systems, and guest or public wireless networks.
- Reviews and hardens perimeter, wireless, and remote access configurations, and validates that vendor and site-to-site connections are documented, least privilege, and monitored.
Security Operations and Incident Response
- Overseessecurity monitoring, logging, and alerting, and coordinates response to security events and incidents.
- Leads incident response and recovery activities, including containment, investigation, documentation, and post-incident review.
- Manages and coordinates data backup verification, disaster recovery testing, and tabletop exercises supporting operational resilience.
Physical Security Systems
- Serves as the Information Technology lead for the City's electronic physical access control systems, including badge readers, door controllers, credentials, and access management software, in coordination with Facilities and other departments.
- Administers access levels, badge issuance and deactivation, and audits access records to confirm that permissions match current job duties and that credentials are revoked promptly upon separation or role change.
- Administers the City's security camera and video management systems, including system health, storage and retention schedules, user permissions, and the secure handling and release of recorded footage in coordination with Legal, Police, and open records staff.
- Ensures that networked physical security devices, including cameras, readers, controllers, and recorders, are inventoried, patched, credentialed, segmented, and monitored to the same standard as other technology assets.
- Conducts physical security assessments of data centers, server rooms, network closets, and other critical technology spaces, addressing access control, environmental and alarm monitoring, camera coverage, and visitor and vendor escort procedures.
- Recommends standards for the placement, specification, and replacement of cameras and access control devices, and coordinates related projects with Facilities, Police, departments, and vendors.
- Supports investigations and incident review by retrieving access control and video records in a manner that preserves evidentiary integrity and complies with retention, privacy, and criminal justice information requirements.
Security Awareness and Compliance
- Develops and delivers security awareness initiatives, including phishing simulation campaigns and staff training.
- Ensures compliance with applicable laws, regulations, and standards, including Georgia Crime Information Center (GCIC) and criminal justice information (CJIS) requirements.
- Maintains security documentation, reporting, and metrics that communicate security posture to leadership.
Artificial Intelligence Governance and Secure Adoption
- Leads the implementation of the City's artificial intelligence program, including the rollout of approved AI tools, supporting standards and procedures, and the phased adoption plan across departments.
- Maintains and administers the City's artificial intelligence policy and governance framework, aligned with recognized standards such as the NIST AI Risk Management Framework, and brings recommendations forward to the technology governance body.
- Reviews andapprovesproposed AI tools, features, and vendor capabilities before deployment, evaluating data handling, model training practices, retention, access controls, contractual terms, and overall risk to the City.
- Establishes and enforces requirements for the safe use of AI, including restrictions on entering confidential, personally identifiable, criminal justice, or otherwise sensitive information into third-party tools, and the requirement for human review of AI output.
- Develops and delivers staff training and guidance on the responsible use ofAI, andserves as the primary advisor to departments evaluating AI-enabled solutions.
- Monitors AI usage across the City for compliance with policy, investigates unapproved or unsafe use, and maintains an inventory of approved AI tools and their associated use cases and risk classifications.
- Conducts periodic reviews and audits of AI systems in use, documenting compliance status, identified risks, and remediation actions, and reports results to the Information Technology Director and governance body.
- Tracks evolving federal, state, and local requirements affecting the governmental use of artificial intelligence, and updates City policy and practice accordingly.
Coordination and Vendor Management
- Evaluates, recommends, and coordinates security tools and services, and works with vendors on assessments and remediation.
- Communicateswith the Director, staff, other departments, and external partners to coordinate work and resolve security issues.
- Performs other duties as required.
MINIMUM QUALIFICATIONS
Education and Experience
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a closely related field required.
- At least three (3) years of experience in information security, network administration, or systems administration with a demonstrated security focus.
- Hands-on experience administering firewalls and VPN or secure remote access technologies.
- Any equivalent combination of education, training, and experience that provides the requisite knowledge, skills, and abilities may be considered.
Preferred Qualifications
- Experience with security frameworks, incident response, and vulnerability management.
- Experience in a municipal, public safety, or CJIS-regulated environment.
- Experience supporting electronic access control, badge reader, or video surveillance systems, and familiarity with the convergence of physical and cyber security.
- Experience developing or administering artificial intelligence governance, acceptable use, or emerging technology risk policies.
Licenses or Certifications
- Must possess and maintain Georgia Crime Information Center (GCIC) certificationwithin 30 days after hire.
- One or more security certifications preferred, such as CompTIA Security+, CISSP, CISM, or equivalent.
- Must possess and maintain a valid Georgia driver's license, as the position requires travel between City facilities to support physical security systems.
COMPETENCIES AND REQUIRED KNOWLEDGE, SKILLS, AND ABILITIES
Knowledge Of
- Cybersecurity principles, frameworks, and best practices.
- Risk management, threat and vulnerability assessment, and incident response.
- Network, server, and endpoint security, and identity and access management.
- Applicable compliance requirements, including GCIC/CJIS.
- Firewall administration, VPN and secure remote access technologies, and network segmentation.
- Electronic physical access control systems, badge and credentialmanagement, andvideo surveillance and video management systems.
- Physical security controls for data centers, server rooms, and network facilities, including environmental and alarm monitoring.
- Records retention, privacy, and evidentiary handling requirements applicable to access control and video records.
- Artificial intelligence concepts, generative AI tools, and the associated data privacy, security, and compliance risks in a government setting.
- AI governance frameworks and responsible use practices, such as the NIST AI Risk Management Framework.
Ability To
- Assess, prioritize, and communicate security risks to technical and non-technical audiences.
- Lead incident response calmly and methodically under pressure.
- Influence security practices across teams without direct authority.
- Coordinate effectively with Facilities, Police, departments, and vendors on integrated physical and cyber security systems.
- Evaluate emerging technologies, including artificial intelligence, and balance innovation and business value against security, privacy, and compliance risk.
- Exercise sound, independent judgment in evaluating security information and selecting alternatives.
PHYSICAL DEMANDS
The work involves light physical exertion, typically requiring some combination of stooping, kneeling, crouching, and crawling. It may also involve lifting, carrying, pushing, and pulling objects and materials weighing 12-20 pounds. Tasks may require extended periods at a keyboard or workstation, as well as travel between City facilities and occasional work on ladders or lifts when inspecting or supporting camera and access control equipment. The ability to perceive and discriminate colors, shades, sounds, odor, depth, texture, and visual cues or signals is also necessary. Some tasks also require oral communication skills.
WORK ENVIRONMENT
Regular work may involve exposure to adverse environmental conditions, such as dust, electric currents, or bright/dim light, when supporting infrastructure, server, or network environments. Work may also occur outdoors or in mechanical, roof, or confined spaces when supporting cameras, access control devices, and related field equipment, and may require occasional response outside normal business hours for security events.
The City has the right to revise this job description at any time. This description does not represent in any way a contract of employment.
The City of Roswell, Georgia commits to a policy of equal employment opportunity for applicants and employees, complying with local, state and federal laws. The City's policy is to employ qualified persons without discrimination regarding race, creed, color, religion, age, sex, country of national origin, marital status, disability, sexual orientation, gender identity, genetic information, political affiliation, ethnicity, or status in any other group protected by federal/state/local law.
Learn more about this Employer on their Career Site
