Senior Security & Compliance Analyst (onsite)

Vitaver & Associates

Tallahassee, Florida

JOB DETAILS
SKILLS
Access Control, Analysis Skills, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Computer Science, Computer Security, Computer Systems, Corrective Action, Criminal Justice, Database Administration, Database Design, Documentation, Editing, External Audit, Gap Analysis, HIPAA (Health Insurance Portability and Accountability Act), Identity Data Management, Identity Federation, Incident Response, Information Technology & Information Systems, Information/Data Security (InfoSec), Internal Audit, Internet Security, Loss Prevention, Machine Tool, Microsoft Access Database, Microsoft Product Family, Microsoft Windows Azure, Policy Development, Policy Implementation, Procedure Development, Publications, Risk, Risk Analysis, Risk Management, Root Cause Analysis, Scripting (Scripting Languages), Security Analysis, Security Information and Event Management (SIEM), Security Policy, ServiceNow, Software Design, Software Development, Source Code/Configuration Management (SCM), State Government, Systems Analysis, Testing, U.S. National Institute of Standards and Technology (NIST), Windows PowerShell, Work From Home
LOCATION
Tallahassee, Florida
POSTED
2 days ago
14812 - Senior Security & Compliance Analyst (Onsite) - Tallahassee, FL

Start Date: ASAP
Type: Temporary Project.
Estimated Duration: 12 months with possible extensions
Work Setting: 100% of the time at the Client's site. No telecommuting or remote work. This is a non-negotiable requirement from the client.
Only candidates able to relocate as required should apply to avoid removal from future consideration.
Our client is filling this contract position exclusively through approved staffing partners, so this opportunity is not available by applying directly with the client. If you're interested, we'd be happy to represent you throughout the hiring process.

Required:
• Availability to work 100% of the time at the Client's site in Tallahassee, FL.
• Experience with Information security disciplines, with demonstrated background in both security governance/compliance (GRC) and hands-on security operations (7+ years).
• Experience with Combined Information Technology (IT) and security work with a broad range of exposure to systems analysis, applications development, and database design and administration (4+ years).
• Experience with Information security, including knowledge of security issues, techniques, and implications across all existing computer platforms (1+ years).
• Experience drafting information security policy and standards.
• Experience implementing NIST Special Publication (SP) 800-53 and/or NIST Cybersecurity Framework (CSF) controls.
• Experience performing security risk assessments and supporting internal or external audits.
• Experience with Security policy and standards lifecycle, including periodic review cycles.
• Experience creating, editing, and maintaining security documentation including policies, procedures, standards, runbooks, and audit evidence.
• Experience with Rule 60GG-2, Florida Administrative Code (F.A.C.) and Section 282.318, Florida Statutes (F.S.).
• Experience with Control mapping crosswalks among NIST SP 800-53, NIST CSF, and Rule 60GG-2, F.A.C.
• Experience with Risk assessment and Plans of Action and Milestones (POA&M) / corrective-action development.
• Experience with Office of Inspector General (IG) and external audit evidence, control testing, and management responses.
• Experience with Vendor security review, including integration identity, attribution, and logging.
• Experience with Microsoft Defender for Endpoint configuration and monitoring, Vulnerability Management, including triage and remediation coordination.
• Experience with Microsoft 365 (M365) identity, Conditional Access, Role-Based Access Control (RBAC), and access reviews.
• Experience with Incident response handling and post-incident Root Cause Analysis (RCA).
• At least one current industry certification from the following: Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified in Governance, Risk and Compliance (CGRC), Certified Information Security Manager (CISM), or Certified Information Systems Security Professional (CISSP).
• Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent work experience.

Preferred:
• Experience with Florida state government or public-sector information security.
• Experience with Rule 60GG-2, F.A.C., and Section 282.318, Florida Statutes.
• Experience with Criminal Justice Information Services (CJIS) Security Policy implementation or audit.
• Experience with Health Insurance Portability and Accountability Act (HIPAA) Security Rule and Protected Health Information (PHI) handling.
• Experience with Microsoft 365 G5, Microsoft Defender (Endpoint, Vulnerability Management), and Microsoft Purview.
• Experience with Vulnerability management tooling and remediation-coordination.
• Experience with Developing Identity and Access Management (IAM) / access-control standards and provisioning-integrity controls.
• Experience with PowerShell or comparable scripting for security automation and reporting.
• Experience with Governance, Risk, and Compliance (GRC) tooling such as ServiceNow GRC, RSA Archer, or Microsoft Purview Compliance.
• Experience with Microsoft Purview - Data Loss Prevention (DLP), retention, sensitivity labels.
• Experience with Microsoft 365 / Azure security configuration and hardening.
• Experience with Audit log review, log analysis, and Security Information and Event Management (SIEM) concepts.

Responsibilities:
• Draft, revise, and maintain Department information security policies and standards (including the 420-series), and establish and operate periodic review cycles.
• Develop procedures supporting Department security policies consistent with Rule 60GG-2.002 and 60GG-2.003, F.A.C.
• Develop and maintain control mappings and crosswalks among NIST SP 800-53, NIST CSF, and Rule 60GG-2, F.A.C.
• Maintain documentation, version control, and review evidence sufficient to satisfy internal and external audit.
• Conduct security risk assessments and control gap analyses against applicable frameworks.
• Develop, track, and maintain Plans of Action and Milestones (POA&Ms) and corrective action plans.
• Perform third-party / vendor security risk reviews, including review of vendor security documentation, contract security terms, and integration security (identity federation, per-transaction attribution, and audit logging).

About the Company

V

Vitaver & Associates