The Statement of Qualifications (SOQ) must be numbered in the same order as the following areas, typed in 12-point Arial font, single spaced, and be no more than two pages in length. Applicants who fail to answer the questions or submit an SOQ may not be considered.
1. Describe your experience assessing cybersecurity control maturity using frameworks such as NIST CSF 2.0, HIPAA Security Rule requirements, or Zero Trust Architecture principles. Include specific examples of how you evaluated controls, validated documentation, or conducted stakeholder interviews.
2. Explain your experience supporting audits or compliance activities, including preparing evidence, documenting findings, and tracking remediation. Describe your experience presenting cybersecurity or compliance findings to stakeholders and interpreting those findings into clear, actionable recommendations.
3. Describe your experience analyzing technical or security data to develop baselines and monitor progress in cybersecurity posture. Include examples where you transformed assessment results into actionable outputs such as scorecards, dashboards, automation scripts, or comparative reports. Explain your role, the tools or methods used, and how your work supported decision making or improved security outcomes.
If you are using list eligibility from an on-line exam to qualify for this position, you MUST include with your application any documentation (i.e., copy of transcript, degree, license, etc.) to verify meeting the MQ’s or you may not be considered for the position.
The MQs will be verified prior to interview and/or appointment. If it is determined that an applicant does not meet the MQs of the classification, the applicant may not be considered and withheld from the eligible list.