Job Summary: Senior Security & Compliance Analyst
- Serve as a liaison between IT, General Counsel, department program areas, Florida Digital Service, and solution providers on security matters.
- Demonstrate broad expertise in information security governance and operations, including both policy development and hands-on technical controls implementation.
- Draft, revise, and maintain information security policies, standards, and procedures in alignment with NIST SP 800-53, NIST CSF, and Florida Cybersecurity Standards (Rule 60GG-2, F.A.C.).
- Conduct security risk assessments, control gap analyses, and third-party/vendor risk reviews.
- Develop, track, and maintain Plans of Action and Milestones (POA&Ms) and corrective action plans.
- Support configuration, hardening, and monitoring within Microsoft 365 and Microsoft Defender environments.
- Coordinate vulnerability management, incident response, and identity/access management activities.
- Prepare clear, audit-ready documentation, including risk assessments, incident reports, and management responses.
- Support responses to audits, ensure compliance with CJIS Security Policy, HIPAA Security Rule, and protection of PHI/confidential data.
- Develop security metrics, status reports, and security awareness materials; participate in governance meetings.
- Maintain version control and documentation sufficient for internal and external audits.
- Minimum qualifications: Bachelor's degree (or equivalent experience), relevant industry certification (CISA, CRISC, CGRC, CISM, CISSP), at least 7 years' information security experience, including GRC and hands-on operations.
- Preferred: Florida state government/public sector experience, knowledge of state security statutes/rules, Microsoft 365/Defender expertise, vulnerability management, IAM, scripting (PowerShell).
- No background check or drug screening required.