- Company Name
- Core Technology Solutions
- Job Title
- IS Security Analyst
- Job Description
-
**Job Title:** IS Security Analyst
**Role Summary:**
Lead and execute security, risk, and compliance activities for a FISMA‑compliant agency. Conduct architectural reviews, risk analyses, and security assessments of agency and partner systems. Drive the design, implementation, and maturity of security controls and eGRC processes, ensuring alignment with NIST, CMS MARS‑E, HIPAA, and other regulatory frameworks.
**Expectations:**
- Must reside within commuting distance of the office or be local; onsite work required.
- US work status only; direct hire W2 long‑term contract assignment.
- Ability to work independently and collaboratively across multiple teams and vendors.
**Key Responsibilities:**
- Perform detailed architectural reviews of network design, information flow, and system data access models.
- Analyze security‑related requests (firewall rules, baseline configuration deviations, vulnerability management).
- Develop, implement, and mature SCDHHS security and compliance programs.
- Audit and assess internal agency systems and business partner/service provider information system controls.
- Utilize Microsoft Office, System Center Service Manager, Archer eGRC, Bizagi, Atlassian, and related tools for documentation and reporting.
- Conduct security and compliance reviews of contracts, Business Associate Agreements, and data usage/sharing agreements.
- Engage and coordinate with diverse audiences to translate technical requirements into business outcomes.
**Required Skills:**
- Certified in ISC2 (CISSP, Security+), ISACA (CISA, CRISC), or SANS GIAC (e.g., GCIA, GCIH).
- Deep knowledge of FISMA, NIST SP 800 series, CMS MARS‑E, and HIPAA Security/Privacy Rules.
- 5+ years of IT experience working with and/or auditing Windows, Linux, relational/non‑relational databases, networking infrastructure, and web‑based applications.
- Prior experience in a FISMA‑compliant program and with eGRC systems.
- Health Information Technology experience is preferred.
- Strong analytical, independent, and multitasking abilities.
- Excellent communication skills for stakeholder engagement.
**Required Education & Certifications:**
- ISC² credential (CISSP, Security+, etc.) or ISACA credential (CISA, CRISC).
- SANS GIAC certification(s) relevant to security operations.
- (No specific degree required unless stated.)