Job Description:
Position Summary. The IT Coordinator provides day-to-day technology support for WCOE, including end-user help desk support, administration of WCOE's cloud-based productivity tools (Microsoft 365 / Google Workspace, including SharePoint Online), video conferencing platforms (Microsoft Teams and Zoom), reasonable cybersecurity practices, and support for WCOE's cyber liability insurance compliance. Work shall be performed using practical information-security practices appropriate to a small for-profit organization, with reference to commercial standards such as ISO/IEC 27001/27002 and PCI DSS where applicable, and in compliance with applicable state data privacy laws. The IT Coordinator shall be compensated at the rate of Twenty Dollars ($20.00) per hour, with an aggregate annual maximum of Four Thousand Five Hundred Dollars ($4,500), equivalent to two hundred twenty-five (225) compensable hours per year. The monthly target should be approximately nineteen (19) hours, recognizing that actual hours may fluctuate from month to month based on operational needs (e.g., onboarding cycles, event preparation, software renewals, or incident response). Hours billed in any single month above the monthly target require advance written coordination with the WCOE Executive Board to ensure the annual aggregate is not exceeded. The annual aggregate cap is the binding limit on compensation and shall not be exceeded without prior written approval of the Executive Board. All compensation shall be paid as 1099 contractor income. . Duties and Responsibilities. The IT Coordinator shall perform the duties below in a manner consistent with reasonable small-organization information-security practices and applicable law. Duties are organized by functional area for clarity. (a) Identity and Access Management (i) Administer WCOE user accounts, licenses, and group memberships across Microsoft 365 / Google Workspace, Microsoft Teams, Zoom, the password manager, and cloud file storage; (ii) Onboard new board members, contractors, and authorized volunteers within two (2) business days of notification, including provisioning of branded email, group memberships, file/folder access, and platform access; (iii) Offboard departing board members, contractors, and volunteers within two (2) business days of notification, including disabling accounts, revoking access, archiving mailbox contents per WCOE policy, and recovering organizational data; (iv) Perform a basic quarterly access review to confirm that active accounts and permissions remain appropriate, and report results to the Executive Board. (b) Productivity, Collaboration, and SharePoint Administration (i) Administer the WCOE productivity suite (Microsoft 365 or Google Workspace), including domains, mail routing, shared mailboxes, distribution groups, calendars, and shared drives; (ii) Administer the WCOE SharePoint Online environment (or equivalent platform), including creating and maintaining team and committee sites, configuring document libraries and lists, managing site and library permissions, enabling version control and check-in/check-out where appropriate, applying retention and sharing policies, supporting document templates, and assisting board members and contractors with file upload, organization, and access requests; (iii) Maintain email authentication records (SPF, DKIM, DMARC) for all WCOE sending domains, in coordination with eFocus; (iv) Configure cloud file storage and SharePoint with appropriate default sharing settings, external-sharing controls, and link-expiration policies. (c) Cybersecurity and Information Security (i) Enforce multi-factor authentication (MFA) on all WCOE user accounts, administrative accounts, and any account used to access financial systems, member records, or the WCOE merchant account; verify enforcement at least quarterly; (ii) Maintain reasonable endpoint protection (modern anti-malware / Endpoint Detection and Response, or "EDR") on WCOE-managed devices, and recommend reasonable endpoint protection standards for board members and contractors using personal devices to access WCOE data; (iii) Operate a basic patch and update management process for organizational accounts, browsers, productivity software, and any WCOE-managed devices, ensuring critical security updates are applied within thirty (30) days of release; (iv) Maintain a password manager for WCOE and require its use for shared organizational credentials; (v) Conduct annual security awareness communications (phishing, password hygiene, social engineering, reporting procedures) for board members, contractors, and authorized volunteers, in coordination with the Executive Board; (vi) Maintain a basic written incident-response procedure, serve as the initial point of contact for suspected security incidents, and promptly report any suspected incident, breach, or material vulnerability to the WCOE President and Executive Board, including notification to WCOE's cyber liability insurance carrier where required. (d) Data Privacy and PCI Support (i) Support compliance with applicable state data privacy laws affecting WCOE's members (including the California Consumer Privacy Act and California Privacy Rights Act where applicable), maintain a basic inventory of systems that store member personal information, and assist the Executive Board in responding to verified member rights requests (access, deletion, opt-out, correction); (ii) Where WCOE processes payment-card transactions through a third-party merchant account, support compliance with the Payment Card Industry Data Security Standard (PCI DSS) at WCOE's applicable merchant level, in coordination with the Accounting Coordinator; recommend payment processors that minimize WCOE's PCI scope through tokenization or hosted payment pages. (e) Meeting and Event Technology (i) Administer Microsoft Teams and Zoom (or successor video-conferencing platforms), including licensing, meeting templates, recording settings, waiting-room and authentication controls, and webinar configurations; (ii) Provide first-line technical support before and during WCOE Executive Board meetings, committee meetings, and member events, including audio-visual support for hybrid and on-site events as requested; (iii) Coordinate with the Management & Admin Services Coordinator on event technology requirements for the Annual DC Conference, Mid-Year Retreat, Fall Conference, and other WCOE events. (f) Vendor and SaaS Management (i) Maintain a current inventory of WCOE software subscriptions, license counts, renewal dates, primary contacts, and annual costs; (ii) Notify the Accounting Coordinator of upcoming software renewals not less than thirty (30) days in advance to allow timely budget review and payment processing; (iii) Recommend cost-effective technology improvements, consolidations, and renewals to the Executive Board. (g) Membership Platform and Integrations (i) Administer technical access, account provisioning, and integrations for the WCOE membership platform used by the Management & Admin Services Coordinator; (ii) Support the technical setup and maintenance of WCOE's merchant account and payment processor integrations, in coordination with the Accounting Coordinator; (iii) Coordinate with eFocus on shared services (domain DNS, email authentication, integrations between the website and the membership platform). (h) Backup and Business Continuity (i) Ensure that critical organizational data — including email, shared drive and SharePoint contents, and the membership platform — is protected by appropriate backups, leveraging vendor-native backup features and third-party backup tools as appropriate; (ii) Verify, at least quarterly, that backups are running successfully and that representative data can be restored; (iii) Maintain a basic, documented continuity playbook addressing the loss of access to email, file storage, SharePoint, the website, the membership platform, and key contractor accounts. (i) End-User Support and Help Desk (i) Provide first-line technical support to board members, committee chairs, and authorized volunteers for email, video conferencing, shared documents, SharePoint, and other WCOE systems, with reasonable response times consistent with the monthly hours target; (ii) Assist users with password resets, account recovery, and multi-factor authentication setup for WCOE accounts; (iii) Provide guidance on basic hardware troubleshooting for personal devices used to access WCOE systems (laptop, tablet, smartphone), including connectivity, peripherals, and printer/scanner setup, recognizing that WCOE does not own end-user hardware and that device-level repairs remain the responsibility of the device owner; (iv) Assist with installation and configuration guidance for WCOE-licensed software on user devices, including productivity applications, video conferencing clients, and the password manager; (v) Assist with mobile device setup for WCOE email, calendar, and collaboration applications, including basic security configurations (screen lock, MFA app); (vi) Provide brief user training and reference materials for WCOE systems and tools, including new-user orientation upon onboarding and refresher guidance as systems change; (vii) Track support requests, common issues, and recurring problems, and use that information to recommend documentation and process improvements. (j) Cyber Liability Insurance Compliance (i) Support WCOE's compliance with the security-control requirements of WCOE's cyber liability insurance policy and the underwriting attestations made by WCOE to its carrier; (ii) Assist the Executive Board in completing cyber insurance applications, renewal questionnaires, and ransomware supplemental questionnaires, providing accurate information regarding WCOE's information-security posture; (iii) Implement, maintain, and document the security controls typically required by cyber insurance carriers (e.g., MFA, endpoint protection, patch management, backups, security awareness, email security, and a documented incident-response plan); (iv) In the event of a security incident, support timely notification to the cyber insurance carrier and engagement of carrier-approved incident response resources in accordance with the policy. (k) Documentation and Confidentiality (i) Maintain basic IT documentation, including system inventories, standard operating procedures for common tasks (onboarding, offboarding, password resets, account recovery), and the incident-response and continuity playbooks; (ii) Maintain confidentiality of all non-public WCOE information at all times, with particular care for member personal information, payment information, and any information governed by an applicable confidentiality obligation. Section 6. Qualifications. The IT Coordinator shall possess: (a) Not less than five (5) years of hands-on experience in information technology support, systems administration, or help-desk roles, including administration of cloud productivity platforms; (b) Strong hands-on familiarity with Microsoft 365 administration (including SharePoint Online and Microsoft Teams) and/or Google Workspace administration, Zoom administration, cloud-based file storage, and a password manager for organizational use; (c) Working knowledge of cybersecurity fundamentals, including identity and access management, multi-factor authentication, endpoint protection, phishing awareness, account recovery, and basic incident response; (d) General familiarity with commercial information-security frameworks (e.g., ISO/IEC 27001/27002) and the ability to apply security practices proportionately to a small for-profit organization; (e) Awareness of applicable state data privacy laws affecting member personal information (e.g., CCPA/CPRA) and the ability to support compliance proportionately; (f) Basic familiarity with PCI DSS as it applies to a small merchant using a third-party payment processor with tokenization or hosted payment pages; (g) Familiarity with the security controls and attestations typically required by cyber liability insurance carriers, and the ability to support WCOE's insurance application, renewal, and claims processes; (h) Working familiarity with email authentication (SPF, DKIM, DMARC), domain and DNS basics, and standard help-desk tasks (password resets, MFA setup, mobile device email/calendar setup, software installation guidance, printer/scanner connectivity); (i) Demonstrated ability to troubleshoot common end-user issues remotely with non-technical users, with patience and clarity; (j) Strong written and verbal communication skills and the ability to document procedures clearly; (k) Ability to perform services independently in a remote environment with a high standard of confidentiality and professional integrity. Industry credentials such as ISO/IEC 27001 Lead Implementer or Lead Auditor, ISACA CISA or CISM, (ISC)2 SSCP, CompTIA A+, ITIL Foundation, Google Workspace Administrator, or Microsoft 365 Certified: Administrator Expert (MS-102 or equivalent) are preferred but not required. Section 7. Performance Standards. Performance of the IT Coordinator shall be reviewed quarterly during the first year of appointment and semi-annually thereafter by the Executive Board or its designee. The evaluation shall assess the IT Coordinator's overall effectiveness in supporting the organization's technology needs, implementing Board directives, and maintaining secure and reliable information systems. Standards of satisfactory performance include: (a) Multi-factor authentication is enabled on one hundred percent (100%) of WCOE user accounts and administrative accounts; (b) Onboarding and offboarding requests are completed within two (2) business days of notification; (c) Quarterly access reviews and quarterly backup verifications are completed and documented; (d) Help-desk requests (password resets, account access, meeting support, software guidance) receive an initial response within one (1) business day, recognizing the monthly hours target; (e) Suspected security incidents are reported to the WCOE President and Executive Board within twenty-four (24) hours of discovery, and an incident-response action is initiated promptly thereafter, including notification to WCOE's cyber liability insurance carrier where required; (f) Cyber liability insurance security questionnaires and renewal attestations are completed accurately and on time, and the security controls represented therein are verifiably in place and documented; (g) Software renewal notifications are provided to the Accounting Coordinator not less than thirty (30) days in advance of renewal; (h) IT documentation (system inventory, SOPs, incident-response and continuity playbooks) is reviewed and updated at least annually.
Company Description:
WCOE advocates for women who own construction companies and