All interested applicants are required to submit a Statement of Qualifications (SOQ).
You must provide direct responses to each of the numbered items listed below. Each individual response must be numbered and include the full text of the numbered items prior to your response. Please include specific examples of your education, training, and/or experience.
The SOQ header should include the Job Control #, your name, “Statement of Qualifications” and your response. Resumes, cover letters and other material will not take the place of the required SOQ. Applications without an SOQ will not be considered. Your response to the SOQ should be no more than three (3) pages in length, formatted in 11pt Arial font, and should have a one-inch margin.
The SOQ serves as a key component of the examination and hiring process and will be used to evaluate your qualifications, as well as your written communication skills. The SOQ is considered a writing sample and must clearly reflect your own knowledge, skills, abilities, and experience. While tools such as artificial intelligence (AI) (e.g., ChatGPT), internet resources, or third-party reviewers may assist with research or preparation, by submitting your application you certify that your SOQ is your original work, written in your own words, and accurately represents your background and qualifications. Failure to submit an SOQ that is your own work, including the use of AI-generated or substantially AI-assisted responses that misrepresent your abilities, may result in disqualification from the examination or hiring process. If such misrepresentation is discovered after appointment, it may constitute dishonesty and could result in adverse action, up to and including dismissal from State service
- Describe your experience identifying, assessing, and mitigating information security risks. Include a specific example of a security risk you evaluated, the recommendations you made, how you collaborated with stakeholders, and the outcome.
- Describe your experience developing, implementing, or maintaining information security policies, standards, procedures, or compliance programs. Include the security framework(s) or regulatory requirements you worked with (e.g., NIST, ISO 27001, CIS Controls, HIPAA, CJIS, PCI DSS), your role, and the results of your efforts.
- Describe a situation in which you responded to a cybersecurity incident, security vulnerability, or audit findings. Explain your role, how you communicated technical information to both technical and non-technical stakeholders, the actions taken to resolve the issue, and the lessons learned.
Do not submit the “Equal Employment Opportunity” questionnaire (page 5) with your completed state application (STD. 678) – For exam use only.
Please do NOT include your Social Security Number on any of the submitted documents.