IT Security Compliance and Audit Analyst

CYNET SYSTEMS

  • Frankfort, KY
  • 3 days ago
  • $25–$35 Per Hour
  • Temporary
  • Contractor
  • Part-time

Highlights

The position provides information security and Governance, Risk, and Compliance (GRC) support, including security control assessments, risk assessments, compliance monitoring, security documentation, audit and evidence management, and continuous monitoring activities. As a nationally and locally certified Minority Business Enterprise (MBE), Cynet Systems is committed to helping organizations build high-performing teams while empowering professionals to grow rewarding careers.

Numbers & Facts

LocationFrankfort, KY
Job TypeTemporary, Contractor, Part-time
Salary$25–$35 Per Hour
HeadquartersFrankfort, KY, US

Description

Pay Range: $25.00hr - $35.00hr

Job Overview:

Our client supports state highways, roads, bridges, vehicle licensing, driver licensing, and highway safety operations. The primary focus of this position is to support technology, information security, compliance, and driver licensing operations. The successful candidate will support driver licensing systems, issuance technology, REAL ID requirements, and related applications. The position provides information security and Governance, Risk, and Compliance (GRC) support, including security control assessments, risk assessments, compliance monitoring, security documentation, audit and evidence management, and continuous monitoring activities. The successful candidate will work with System Administrators, IT staff, management, vendors, and other stakeholders to identify security and operational risks, support compliance requirements, improve system processes, and maintain appropriate security controls. The candidate may be required to review and analyze sensitive and confidential information and must maintain a high level of professionalism, accountability, confidentiality, and security awareness, and pass required fingerprint and background checks.

Primary Responsibilities:

  • Support information security and Governance, Risk, and Compliance (GRC) activities.
  • Assist with the development, review, and maintenance of security policies, procedures, standards, and compliance documentation.
  • Support compliance activities related to federal information security requirements, state requirements, and protection of Personally Identifiable Information (PII).
  • Assist with NIST Special Publication (SP) 800-53 security controls and related control implementation requirements.
  • Assist with security control assessments and documentation of control effectiveness.
  • Participate in risk assessments, risk identification, risk analysis, and risk mitigation activities.
  • Assist with the development and maintenance of System Security Plans (SSPs) and supporting security documentation.
  • Assist with Plans of Action and Milestones (POA&Ms), including documenting identified weaknesses, corrective actions, responsible parties, milestones, and remediation status.
  • Support continuous monitoring activities to identify changes in security posture, system risks, vulnerabilities, and compliance status.
  • Assist with security audits, assessments, reviews, and security audit/evidence management.
  • Collect, organize, validate, and maintain evidence required to demonstrate compliance with security controls and regulatory requirements.
  • Support the assessment and documentation of hybrid controls, including controls involving cloud services, provided services, enterprise controls, external systems, and other shared responsibilities.
  • Coordinate with system owners, System Administrators, IT staff, vendors, and other stakeholders to obtain security documentation and evidence.
  • Monitor identified security findings and assist with tracking remediation activities through completion.
  • Assist with documenting security risks and providing recommendations to management regarding risk treatment and remediation.
  • Support the review of system changes to determine potential security and compliance impacts.
  • Assist with maintaining accurate security records, assessment documentation, and compliance artifacts.

Compliance, Policy, and Training:

  • Assist with continual compliance monitoring to ensure applicable policies, procedures, security controls, and regulatory requirements remain current and effective.
  • Support the review and updating of policies and procedures when security, technology, regulatory, or operational requirements change.
  • Assist with updating policy and training language to reflect current compliance and security requirements.
  • Monitor security and compliance training completion and maintain appropriate documentation and records.
  • Assist management with identifying training requirements based on security findings, policy changes, audit results, or regulatory requirements.
  • Help communicate security and compliance requirements to employees and stakeholders.
  • Support awareness activities designed to promote proper handling of sensitive information, PII, system credentials, and security-related information.

IT and Application Support:

  • Provide IT and application troubleshooting support to Central and Regional Offices.
  • Work closely with IT staff on system performance, application issues, goals, and conflict resolution.
  • Assist System Administrators with system credentials, access requests, role assignments, and other technology-related duties.
  • Help identify recurring application and system issues and recommend process or technical improvements.
  • Assist with testing system changes, security configurations, application functionality, and access controls.
  • Work with vendors and developers when necessary to investigate and resolve system issues.
  • Document technical issues, resolutions, security concerns, and recommended improvements.

Communication, Leadership, and Customer Service:

  • Strong written and verbal communication skills.
  • Task-oriented, organized, dependable, and able to work independently.
  • Ability to work effectively in a team environment and assist others as needed.
  • Serve in a lead role when called upon.
  • Demonstrate strong interpersonal skills and the ability to work professionally with employees, management, vendors, and external stakeholders.
  • Professional, supportive, diplomatic, flexible, and responsible posture.
  • Maintain a high level of accountability and confidentiality.
  • Ability to communicate technical, security, and compliance information to both technical and non-technical audiences.
  • Ability to make recommendations to management regarding security, compliance, system, and process improvements.

Recommended Security/GRC Credentials and Experience:

Recommended credentials for this position include certifications demonstrating knowledge of information security, governance, risk, compliance, auditing, and security controls, such as:

Certification alone should not be considered a substitute for practical GRC experience. Candidates with demonstrated experience performing security, risk, compliance, assessment, audit, or control-related responsibilities should be considered.

  • ISC2 CGRC Certified in Governance, Risk and Compliance.
  • ISACA CISA Certified Information Systems Auditor.
  • ISACA CRISC Certified in Risk and Information Systems Control.
  • ISC2 CISSP Certified Information Systems Security Professional, particularly when combined with strong hands-on GRC experience.

Preferred GRC / Information Security Experience:

The most important experience includes:

  • NIST SP 800-53.
  • Security Control Assessments.
  • Risk Assessments.
  • System Security Plans (SSPs).
  • Plans of Action and Milestones (POA&Ms).
  • Continuous Monitoring.
  • Security Audit and Evidence Management.
  • Hybrid Controls, including cloud services, provided services, enterprise controls, external systems, and shared responsibilities.
  • Federal information security requirements and regulatory compliance.
  • PII protection and data security.
  • Security policy and procedure development.
  • Compliance monitoring and reporting.
  • Security awareness and compliance training.
  • Security findings and remediation tracking.
  • Risk documentation and mitigation.
  • Audit preparation and response.
  • Security control documentation and evidence collection.

Education and Experience:

The candidate should possess a Bachelor's Degree from an accredited college or university. An Associate's Degree or relevant administrative, business, research, technical, information technology, cybersecurity, or clerical experience may substitute for the required education on a year-for-year basis, as permitted by applicable requirements.

Candidates should have relevant experience in information technology, cybersecurity, information security, GRC, compliance, auditing, risk management, application support, or driver licensing technology.

Experience working with government, federal information security requirements, regulated environments, sensitive information, or enterprise technology systems is preferred.

Additional Requirements:

  • Must be able to pass required fingerprint and background checks.
  • Must maintain confidentiality when handling PII and other sensitive information.
  • Must be willing to travel when required, including occasional overnight stays.
  • Evening or Saturday hours may occasionally be required.
  • Overtime may be necessary, up to 10 hours per week.
  • Ability to learn and apply driver licensing laws, policies, procedures, and technology requirements.
  • Ability to learn and utilize driver licensing systems and related applications.
  • Ability to work effectively with System Administrators, IT staff, management, vendors, developers, and Regional and Central Office personnel.
  • Ability to perform other duties as assigned.

Benefits:

Our Benefits Include:

  • Medical, Dental, and Vision Insurance
  • 401(k) Retirement Plan
  • Health Savings Account (HSA)
  • Disability Insurance (Short-Term and Long-Term)
  • Life and AD&D Insurance
  • Paid Sick Leave (where required by applicable state or local law)
  • Supplemental Insurance Plans
  • Identity Theft Protection
  • Pet Insurance
  • Employee Wellness Programs
  • Employee Assistance Program (EAP)
  • Career Growth and Professional Development Opportunities

Disclaimer: Benefits eligibility, accrual rates, and usage limits may vary based on employment status, length of service, and work location. Paid Sick Leave is provided in strict accordance with applicable state and municipal mandates. Cynet Systems Inc. reserves the right to modify, amend, or terminate any benefit plans at any time in accordance with applicable laws.


About Cynet Systems


Founded in 2010 and headquartered in the Washington, DC metro area, Cynet Systems Inc. is a leading technology staffing and workforce solutions company serving Fortune 500 companies, government agencies, and enterprise organizations across the United States and Canada. We deliver agile, scalable talent solutions across IT, engineering, life sciences, clinical, and professional staffing, powered by a high-performing recruitment engine operating across North America and Asia.

As a nationally and locally certified Minority Business Enterprise (MBE), Cynet Systems is committed to helping organizations build high-performing teams while empowering professionals to grow rewarding careers. Our organization is certified to ISO 9001, ISO 14001, ISO 27001, and SOC 2 Type II standards, reflecting our commitment to quality, security, operational excellence, and customer success.

Similar Jobs

See more jobs