IT Security ANALYST - GRC

S-R-International-Inc

Phoenix (AZ)

On-site

USD 90,000 - 110,000

Part time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible work from home options

Job summary

The Department of Economic Security, Division of Technology Services is seeking an IT Security Analyst (GRC) contractor to support the Governance, Risk and Compliance team and collaborate with business units to understand reporting, data, and product needs. The role involves developing data models, data flows, and enterprise information policies, and guiding users through adoption and training.

The team will work across departments to deliver high-quality artifacts, with flexible work-from-home

Qualifications

  • Knowledge of security principles, policies, and procedures, and be able to develop effective security policies.
  • Knowledge of Information Security Risk Management.
  • Knowledge of RMF, NIST 800-53 R5, and privacy/compliance standards (CJIS, HITRUST, IPAA).

Responsibilities

  • Perform risk assessments, audit reviews, generate findings and recommendations for DES reporting.
  • Review and manage security audit plans and risk plan documentation for accuracy and consistency.
  • Evaluate data and generate reports detailing findings, non-compliance, and action plans.
  • Prepare audit documentation supporting results and drafts in accordance with agency standards.
  • Research agency and industry IT security practices, standards, and regulations to ensure compliance.

Skills

NIST 800-53R5
RMF
Windows/Unix experience

Job description

THIS IS CTH ROLE ON W2 ONLY AND FOR CURRENT ARIZONA RESIDENTS.

THIS POSITION IS NOT FOR VISA HOLDERS.

This posting will be closed on 8/18/26 @ 3:00pm. This is a 4-month contract to hire. All candidates must be eligible to convert to an FTE. The State is unable to sponsor any visas. This has to be local to Phoenix meaning 1 hour drive max. Please do not submit resources if they were submitted to posting 10482 and 11481.

Only W2 no C2C

Job Title: IT Security ANALYST (GRC)

Job ID: 13235

Client: State of Arizona - AZDES - DTS

(contract to hire)

Closing: 8/18/2026

This posting will be closed on 8/18/26 @ 3:00pm. This is a 4-month contract to hire. All candidates must be eligible to convert to an FTE. The State is unable to sponsor any visas. This has to be local to Phoenix meaning 1 hour drive max. Please do not submit resources if they were submitted to posting 10482 and 11481.

Required Skills
  • NIST 800-53R5 (Must have)
  • Risk Management Framework (RMF)
  • Windows/Unix experience
Preferred Skills
  • Project Management experience
  • CISSP, CCSP, GSTRT, GSNA, or CAP certification
Job Summary

The Department of Economic Security, Division of Technology Services is seeking an experienced and highly motivated individual to join our team as a Information Security Analyst, (ISA) contractor. This position will work on the Governance Risk and Compliance (GRC) Team to communicate and engage with business units to develop a strong understanding of their reporting, data, and product needs. The team member will work with other personnel across departments to define requirements for projects, identify data dependencies and relationships to develop logical and physical data models, data flows and system activity diagrams, and write specifications for managing enterprise information policies. The team member will help develop plans and materials to support user adoption, training, and customer service, working through direct and regular contact with users from other divisions, programs, and service units to provide regular insight and guidance in prioritizing enhancements for the data systems. The team member will also support technical project managers to ensure that all aspects of the information analysis and requirements gathering process are completed with the highest degree of accuracy and quality, which includes developing and socializing key project artifacts.

The state of Arizona strives for a work culture that affords employees flexibility, autonomy, and trust. Across our many agencies, boards, commissions, many State employees participate in the State's Remote Work Program and are able to work remotely in their homes, in offices, and in hoteling spaces. All work, including remote work, should be performed within Arizona unless an exception is properly authorized in advance.

Job Duties
  • Perform risk assessments, audit reviews, generate findings reports, and make appropriate recommendations for improvement and track outcomes from those activities for DES reporting requirements. Develop and formulate comprehensive reports detailing the findings, areas of non-compliance, required POA&M (Plan of Action and Milestones), environmental observations, and incident reports.
  • Review, update, and manage security related audit plans, security plans and risk plan documentation for accuracy and consistency, proactively solves problems.
  • Evaluate data and formulate comprehensive reports detailing the findings, areas of non-compliance, required action plans, and environmental observations. Generates incident reports and investigates suspicious network activity.
  • Preparing audit documentation that supports audit results, drafting and editing audit findings to adhere to the standards and the agency's writing style.
  • Research agency and industry IT security practices standards, best practices, laws and regulations, and other applicable resources, ensures compliance with standards
Knowledge, Skills & Abilities (Not incompassing)
  • Knowledge of security principles, policies, and procedures, and be able to develop effective security policies.
  • Knowledge of Information Security Risk Management.
  • Knowledge of laws, regulations, policies, principles, and ethics as they relate to cybersecurity and privacy. (Required: NIST 800-53 R5, IRS Pub1075, IPAA/HITRUST, CJIS and MARS-E)
  • Expert knowledge of internal auditing, internal controls, and risk management practices and methods.
  • Knowledge of Selection/Approval, Implementation, and Assessment/Audit of Security and Privacy Controls.
  • Knowledge of Risk Management Framework (RMF) requirements.
  • Knowledge of Authorization/Approval of Information Systems.
  • Knowledge in conducting audits or reviews of technical systems.
  • Knowledge in comprehensive understanding of internal control environments within the IT function.
  • Knowledge in multiple technology domains including aspects of Windows, Unix and/or database administration, software development and networking.
  • Knowledge in identifying cybersecurity and privacy issues that stem from connections with internal and external customers and partner organizations.
  • Ability to produce high quality work products for both the IT groups and Senior Management.
  • Ability to perform excellent interpersonal, written and oral communication skills.
  • Ability to assess, manage, and improve security policies and procedures.
  • Ability to work collaboratively in teams and across organizations.
  • Ability to synthesize feedback and adjust plans accordingly, build strong relationships inside and outside the organization and manage large teams.
  • Ability to ensure security practices are followed throughout all phases of the life cycle of every aspect of business and IT processes.
  • Ability to develop policy, plans, and strategy in compliance with laws, regulations, policies, and standards in support of organizational cyber activities.
  • Ability to exercise judgment when policies are not well-defined.
  • Ability to ensure information security management processes are integrated with strategic and operational planning processes.
  • Ability to ensure that senior officials within the organization provide information security for the information and systems that support the operations and assets under their control.
  • Ability to understand technology, management, and leadership issues related to organization processes and problem solving.
  • Ability to understand the basic concepts and issues related to cyber and its organizational impact.Develop plans and materials to support user adoption, training, and customer service.
  • Ability to work collaboratively in teams and across organizations.
  • Develop plans and materials to support user adoption, training, and customer service.
  • Work directly with users from other divisions, programs, and service units to provide insight and guidance.
  • Identify risks and suggest improvements to information systems and processes.
  • Support technical project managers to fulfill information analysis requirements with the highest degree of accuracy and quality.
  • Develop and maintain key project artifacts.

Flexible work from home options available.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Analyst
IT Security Analyst

S R INTERNATIONAL INC • Phoenix (AZ)

Hybrid
USD 90,000 - 130,000
IT Security Analyst
IT Security Analyst

S-R-International-Inc • Phoenix (AZ)

Hybrid
USD 85,000 - 105,000
Senior Manager, Information Technology
Senior Manager, Information Technology

IAT Insurance Group • Scottsdale (AZ)

Hybrid
USD 14,000 - 19,000
25B Information Technology Specialist
25B Information Technology Specialist

Army National Guard • Phoenix (AZ)

Hybrid
USD 70,000 - 110,000
Analyst - GOVERNANCE, RISK, AND COMPLIANCE ANALYST
Analyst - GOVERNANCE, RISK, AND COMPLIANCE ANALYST

Idealforce LLC • Phoenix (AZ)

Hybrid
USD 90,000 - 120,000
Sr. Information Security Engg.
Sr. Information Security Engg.

SA Technology • Phoenix (AZ)

On-site
USD 95,000 - 120,000
GRC Analyst / Onsite in Downtown Phoenix
GRC Analyst / Onsite in Downtown Phoenix

Motion Recruitment Partners LLC • Phoenix (AZ)

On-site
USD 80,000 - 100,000
Governance, Risk & Compliance Analyst, Information Security
Governance, Risk & Compliance Analyst, Information Security

Jobtailor • Phoenix (AZ)

On-site
USD 90,000 - 120,000
GRC Information Security Analyst - Contract-to-Hire (Hybrid Phoenix)
GRC Information Security Analyst - Contract-to-Hire (Hybrid Phoenix)

Army National Guard • Phoenix (AZ)

Hybrid
USD 70,000 - 110,000
Technical Security Risk & Governance Analyst
Technical Security Risk & Governance Analyst

Mbi Llc • Harrisburg

Hybrid
USD 80,000 - 100,000
Hybrid/telework eligibility
Participation in after-hours change windows or incident support