Senior Security & Compliance Analyst - Advanced

TechArmy

  • Tallahassee, FL
  • Today
  • Autofill and Review
Want to know if you’re a fit?
Upload your resume and let our AI show you.

Skills

  • Access Controlunmatched
  • Auditingunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Computer Systemsunmatched
  • Contract Approvalunmatched
  • Contract Managementunmatched
  • Database Administrationunmatched
  • Database Designunmatched
  • External Auditunmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internal Auditunmatched
  • Internet Securityunmatched
  • Machine Toolunmatched
  • Microsoft Product Familyunmatched
  • Policy Developmentunmatched
  • Policy Implementationunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Scripting (Scripting Languages)unmatched
  • Security Analysisunmatched
  • Security Monitoringunmatched
  • Security Policyunmatched
  • Software Designunmatched
  • Software Developmentunmatched
  • State Governmentunmatched
  • Systems Analysisunmatched
  • Travel Planningunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Windows PowerShellunmatched
  • Work From Homeunmatched

Description

The Senior Security & Compliance Analyst will provide, but not be limited to, the following activities and tasks.

  1. Minimum Qualifications. The candidate must possess the minimum qualifications and experience of the STC Job Family cited in Section 2 (Security Management, Job #6810, Security Analyst (C. Advanced)), together with the following Department minimum qualifications and experience:
    1. Per the STC Job Family description: a minimum of four (4) years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, and database design and administration, including one to two (1–2) years of experience with information security, and knowledge of security issues, techniques, and implications across all existing computer platforms.
    2. Minimum of seven (7) years across information security disciplines, with demonstrated experience in both security governance/compliance (GRC) and hands-on security operations.
    3. Demonstrated experience drafting information security policy and standards and implementing NIST SP 800-53 and/or NIST CSF controls.
    4. Demonstrated experience performing security risk assessments and supporting internal or external audits.
    5. On-site availability at the Department's location, 4040 Esplanade Way, Tallahassee, Florida. Remote work may be considered on an occasional, ad-hoc basis with prior written approval of the Contract Manager; this is not a hybrid or permanent remote arrangement. Travel costs will not be reimbursed.
  1. Education and Certification. The candidate must possess, at a minimum, a Bachelor's degree in computer science, information systems, cybersecurity, or a related field, or equivalent work experience; and at least one current industry certification from the following (others may be considered):
    1. CISA — Certified Information Systems Auditor (strongly aligned to the GRC/audit core).
    2. CRISC — Certified in Risk and Information Systems Control.
    3. CGRC — Certified in Governance, Risk and Compliance (formerly CAP).
    4. CISM — Certified Information Security Manager.
    5. CISSP — Certified Information Systems Security Professional.
  2. Preferred Qualifications. The following are preferred and will strengthen a candidate's evaluation:
    1. Florida state government or public-sector information security experience.
    2. Working knowledge of Rule 60GG-2, F.A.C., and Section 282.318, Florida Statutes.
    3. CJIS Security Policy implementation or audit experience.
    4. HIPAA Security Rule and PHI-handling experience.
    5. Hands-on Microsoft 365 G5, Microsoft Defender (Endpoint, Vulnerability Management), and Microsoft Purview experience.
    6. Vulnerability management tooling and remediation-coordination experience.
    7. Experience developing IAM / access-control standards and provisioning-integrity controls.
    8. PowerShell or comparable scripting for security automation and reporting.

Numbers & Facts

LocationTallahassee, FL

Similar Jobs