TOYO SOLAR TEXAS LLC
JOB DESCRIPTION
Position Title: Cybersecurity Specialist
Department: Information Technology
Location: Humble, Texas
Reports To: IT Manager / IT Director
Employment Type: Full-Time
FLSA Status: Exempt
Position Summary
The Cybersecurity Specialist is responsible for protecting TOYO Solar Texas LLC’s information systems, networks, data, and technology infrastructure from cybersecurity threats and unauthorized access. This position supports the development, implementation, monitoring, and continuous improvement of cybersecurity controls across the manufacturing facility and business operations.
The Cybersecurity Specialist will work closely with IT, Operations, HR, Finance, Logistics, and other departments to protect company information, intellectual property, employee records, financial and trade data, and other sensitive information.
The position will also support the Company’s cybersecurity compliance requirements, including applicable CTPAT security requirements and recognized cybersecurity frameworks such as NIST. CTPAT specifically identifies intellectual property, customer information, financial/trade data, and employee records as assets requiring cybersecurity protection.
Key Responsibilities
1. Cybersecurity Program & Compliance
- Develop, implement, maintain, and periodically review written cybersecurity policies, standards, and procedures.
- Support compliance with CTPAT cybersecurity requirements and applicable Company security standards.
- Assist with implementation and maintenance of cybersecurity controls aligned with recognized frameworks, including NIST.
- Conduct cybersecurity risk assessments and recommend appropriate corrective and preventive measures.
- Maintain cybersecurity documentation and evidence necessary for internal reviews, customer requirements, audits, and compliance activities.
- Review cybersecurity policies and procedures at least annually and recommend updates based on changes in risk, technology, operations, or identified incidents.
CTPAT requires comprehensive written cybersecurity policies and encourages alignment with recognized frameworks such as NIST.
2. Network & Systems Security
- Monitor Company networks, systems, endpoints, servers, and security tools for vulnerabilities, suspicious activity, and unauthorized access.
- Maintain and monitor firewalls, antivirus/anti-malware solutions, endpoint protection, intrusion-prevention/detection tools, and other cybersecurity technologies.
- Ensure security software and systems receive appropriate updates and patches.
- Perform or coordinate regular vulnerability scans and security testing.
- Track identified vulnerabilities through remediation and verify corrective actions are completed.
- Assist with securing manufacturing, business, and other connected systems as applicable.
CTPAT requires protection against malware and internal/external intrusion as well as regular testing of IT infrastructure and timely correction of identified vulnerabilities.
3. Identity & Access Management
- Administer and monitor user access based on job responsibilities and business need.
- Conduct periodic access reviews for systems containing sensitive or confidential information.
- Coordinate with HR and management to promptly modify or terminate system access following transfers, terminations, or other employment-status changes.
- Maintain individually assigned user accounts and appropriate authentication controls.
- Support implementation and administration of multi-factor authentication (MFA), strong passwords/passphrases, and other authentication technologies.
- Monitor privileged and administrative accounts.
CTPAT requires access to be based on assigned duties and requires computer/network access to be removed upon employee separation. It also requires individually assigned accounts and protected authentication.
4. Security Monitoring & Incident Response
- Monitor security alerts and investigate potential cybersecurity incidents.
- Identify and respond to unauthorized system access, suspicious activity, malware, phishing, social-engineering attempts, and potential data breaches.
- Document cybersecurity incidents, findings, remediation activities, and lessons learned.
- Escalate significant cybersecurity incidents to management in accordance with Company procedures.
- Support incident containment, recovery, business continuity, and restoration of systems and data.
- Assist management with post-incident reviews and implementation of corrective actions.
- Maintain appropriate cybersecurity incident-response documentation.
5. Data Protection & Recovery
- Implement and monitor safeguards for confidential, proprietary, employee, financial, trade, and business information.
- Support encryption of sensitive and confidential data.
- Monitor and verify data backup processes.
- Assist with testing data restoration and disaster-recovery procedures.
- Ensure backup systems and storage methods are appropriately protected.
- Support secure handling, inventory, sanitization, and disposal of IT equipment and media containing sensitive information.
CTPAT recommends appropriate backups and encrypted storage of sensitive/confidential data and requires controlled sanitization or destruction of media containing sensitive import/export information.
6. Remote Access & Endpoint Security
- Maintain secure remote-access controls, including VPN and MFA where applicable.
- Monitor Company laptops, mobile devices, removable media, and other endpoints for compliance with cybersecurity requirements.
- Assist with mobile-device and bring-your-own-device security requirements where applicable.
- Prevent unauthorized software, devices, and storage media from compromising Company systems.
- Maintain controls related to properly licensed and authorized software.
7. Cybersecurity Awareness & Training
- Develop and support cybersecurity awareness training for employees.
- Provide education on phishing, social engineering, password security, data protection, suspicious emails, removable media, and safe use of Company systems.
- Conduct or coordinate periodic phishing simulations and other security-awareness activities as appropriate.
- Communicate emerging cybersecurity risks and recommended precautions to employees and management.
- Work with HR and department managers to address repeated or significant violations of cybersecurity policies.
8. Manufacturing & Operational Security
- Partner with IT and Operations to identify cybersecurity risks affecting manufacturing operations and connected production systems.
- Support appropriate segmentation and protection of production and business networks.
- Assist with cybersecurity reviews before introducing new systems, equipment, applications, or connected technologies.
- Coordinate with equipment vendors and third-party technology providers regarding cybersecurity requirements.
- Support business continuity and recovery planning for technology-related disruptions.
9. Vendor & Third-Party Security
- Assist in evaluating cybersecurity risks associated with vendors, contractors, service providers, and other third parties with access to TOYO systems or sensitive information.
- Review third-party access and recommend appropriate security controls.
- Ensure external IT providers follow applicable Company cybersecurity requirements.
- Assist with cybersecurity questionnaires, assessments, and remediation activities involving third parties.
This is particularly relevant to CTPAT because its business-partner screening guidance specifically includes contracted IT providers and vendors that handle sensitive information or equipment.
Qualifications
Required:
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; equivalent combination of education and relevant experience may be considered.
- 3+ years of experience in cybersecurity, information security, network security, or a related IT security role.
- Working knowledge of firewalls, endpoint protection, vulnerability management, network security, identity and access management, and security monitoring.
- Understanding of cybersecurity incident response and risk-management principles.
- Knowledge of Microsoft Windows environments, Active Directory/Microsoft Entra ID, Microsoft 365, and related enterprise technologies.
- Ability to investigate technical security issues and communicate findings to both technical and non-technical personnel.
- Strong documentation, analytical, organizational, and problem-solving skills.
- Ability to maintain confidentiality when handling sensitive Company and employee information.
Preferred:
- Experience in a manufacturing or industrial environment.
- Experience with NIST Cybersecurity Framework or similar recognized cybersecurity standards.
- Familiarity with CTPAT cybersecurity requirements.
- Experience with vulnerability scanning, SIEM, EDR, MFA, VPN, firewalls, and security-monitoring technologies.
- Familiarity with operational technology (OT), industrial control systems (ICS), or manufacturing-network security.
- Security+, CySA+, CISSP, CISM, CEH, or similar cybersecurity certification.
Knowledge, Skills & Abilities
- Cybersecurity risk assessment and vulnerability management.
- Network and endpoint security.
- Identity and access management.
- Incident investigation and response.
- Data protection, backup, and recovery.
- Security policy and procedure development.
- Cybersecurity awareness and employee training.
- Ability to prioritize cybersecurity risks based on business impact.
- Ability to work effectively across departments and with external vendors.
- Strong written and verbal communication skills.
- High degree of integrity, discretion, and attention to detail.
Physical & Work Environment Requirements
- Primarily office and manufacturing-facility environment.
- Must be able to access production, warehouse, server/network, and other operational areas as required.
- May be required to respond to urgent cybersecurity incidents outside normal business hours.
- Must comply with all TOYO Solar Texas LLC safety requirements and required PPE when entering designated manufacturing areas.
Pay: $75,000.00 - $95,000.00 per year
Benefits:
- 401(k)
- Dental insurance
- Health insurance
- Life insurance
- Paid time off
- Vision insurance
Experience:
- Cybersecurity: 3 years (Required)
Work Location: In person