IT Security & Compliance Specialist II

State of North Carolina - Health & Human Services

North Carolina

Hybrid

USD 88,000 - 117,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

North Carolina Department of Health and Human Services (DHHS) seeks an IT Security & Compliance Specialist II (NS) to perform in-depth security testing of applications and APIs. You will work with development and DevOps teams to embed secure coding practices from design through deployment.

The role emphasizes manual and automated assessments, vulnerability chain analysis, and threat modeling, with a hybrid onsite requirement in Raleigh, NC.

Qualifications

  • The candidate should have at least a bachelor’s degree in CS or a related IT field with two years of progressive IT security experience, or an equivalent combination.
  • Hands-on experience testing web apps, REST/GraphQL APIs, and mobile apps using SAST/DAST and threat modeling.
  • Ability to identify, exploit, and document vulnerabilities and communicate remediation to DevOps teams.

Responsibilities

  • Perform deep manual and automated security assessments of NC DHHS applications, APIs, and mobile apps.
  • Chain vulnerabilities, bypass controls, and emulate adversary behavior across web apps, APIs, and mobile platforms.

Skills

Manual penetration testing
REST APIs
GraphQL APIs
Mobile applications
SAST
DAST
Threat modeling
SQL Injection
XSS
SSRF
Authentication/Authorization
Burp Suite
OWASP ZAP
Nmap
Metasploit
Nessus
Snyk
Veracode
Checkmarx
DevSecOps

Education

Bachelor's degree in computer science or related IT field
Associate degree in computer science or related IT field
Equivalent combination of education and experience

Tools

Burp Suite
OWASP ZAP
Nmap
Metasploit
Nessus
Snyk
Veracode
Checkmarx

Job description

IT Security & Compliance Specialist II (NS)

Agency Division Job Classification Title IT Security & Compliance Specialist II (NS) Position Number Grade DT10

About Us

North Carolina State Government is one of the state’s largest employers, with over 76,000 employees all working toward a common goal: a safer and stronger North Carolina. We are a large organization comprised of various agencies, offices, and universities, each providing important public services. Eligible state employees are entitled to comprehensive benefits, including a variety of leave options, professional development opportunities, insurance, and more. To learn more about the benefits of being a North Carolina state employee, visit the N.C. Office of State Human Resources’ website. Permanent, temporary, and time-limited state government jobs can be found from the mountains to the coast. Find your next opportunity today!

Description of Work

The Application Security Penetration tester is responsible for identifying, analyzing, and mitigating vulnerabilities in software applications and APIs throughout the development lifecycle. This role collaborates closely with development and infrastructure teams to integrate secure coding practices and ensure the security of application from design through deployment. The Application Penetration Tester is responsible to perform deep, manual and automated security assessments of NCDHHS applications. This role goes Beyond automated scanning- you will chain vulnerabilities, bypass controls, and emulate real adversary behavior across web apps, APIs, and mobile platforms.

Knowledge, Skills and Abilities / Management Preferences

Salary Grade Range: $87,617.00 - $117,000.00 Recruitment Range: $87,617.00 - $117,000.00 Candidates now meet the minimum qualifications of a position if they meet the minimum education and experience listed on the vacancy announcement. The Knowledge, Skills, and Abilities (KSAs)/ Management Preferences are not required. Applicants who possess the following skills are preferred: Hands-on experience performing manual penetration testing of web applications, REST and GraphQL APIs, and mobile applications, including static application security testing (SAST), dynamic application security testing (DAST), and threat modeling. Skilled in identifying, exploiting, validating, and documenting security vulnerabilities, including SQL Injection (SQLi), Cross-Site Scripting (XSS), Server Side Request Forgery (SSRF), authentication and authorization flaws. Proficient in conduction both manual and automated security assessment using industry-standard tools such as burp suite, OWASP ZAP, Nmap, Metasploit, Nessus, Snyk, Veracode and Checkmarx. Experience in collaborating with software developers to triage, prioritize, and remediate security findings, while working closely with DevOps and engineering teams to ensure secure application design, configuration, and deployment. Assisted in integrating security controls, automated testing, and vulnerability scanning into CI/CD pipelines to secure software development practices and DevSecOps initiatives. Produced Comprehensive Technical assessment reports containing detailed proof- of-concept (PoC) Exploits, reproducible attack scenarios.

Posting Deadline

The Posting Will Close At 11:59 P.M. The Night Before The End Date.

Funding and Hybrid Work

This Position Is Funded In Part Through Federal Funds. This Role Is Eligible To Be Hybrid And Requires Onsite Reporting Located Within Raleigh, NC.

About the NC DHHS Information Technology Division

In collaboration with our partners, the North Carolina Department of Health and Human Services (DHHS) protects the health and safety of all North Carolinians and provides essential health and human services. The IT division (ITD) is one of the divisions that report to the Operational Excellence portfolio. The ITD division comprises four sections: Implementation and Operations, Strategy and Workforce, Enterprise Technology, and Vendor and Finance. ITD offers the following services but not limited to implementations, operations, project/portfolio management, infrastructure, consulting, business division liaison, digital transformation, IT strategy, enterprise technology, IT contract and vendor management, and data office services.

Compensation and Benefits
  • Employees can participate in health insurance options, standard and supplemental retirement plans, and the NCFlex program (numerous high-quality, low-cost benefits on a pre-tax basis).
  • Employees also receive paid vacation, sick, and community service leave.
  • In addition, paid parental leave is available to eligible employees.
Equal Opportunity Statement

The North Carolina Department of Health and Human Services (DHHS) is an Equal Opportunity Employer that embraces an Employment First philosophy, which consists of complying with all federal laws, state laws, and Executive Orders. We are committed to reviewing requests for reasonable accommodation at any time during the hiring process or while on the job. For more information about DHHS: https://www.ncdhhs.gov/. DHHS uses the Merit-Based Recruitment and Selection Plan to fill positions subject to the State Human Resources Act with the most qualified individuals. Hiring salary will be based on relevant qualifications, internal equity, and budgetary considerations pertinent to the advertised position. In accordance with the Governor’s Executive Order 303, our agency supports second-chance employment for individuals who were previously incarcerated or justice-involved. We invite all potential applicants to apply for positions for which they may be qualified.

EEO Statement

The State of North Carolina is an Equal Employment Opportunity Employer and dedicated to providing employees with a work environment free from all forms of unlawful employment discrimination, harassment, or retaliation. The state provides reasonable accommodation to employees and applicants with disabilities; known limitations related to pregnancy, childbirth, or related medical conditions; and for religious beliefs, observances, and practices.

Eligibility and Additional Preferences

Applicants may be subject to a criminal background check. All candidates selected for positions considered "Positions of Trust" will be subject to a criminal background check.

Veteran's Preference Applicants seeking Veteran's Preference must attach a DD-214 Member-4 Form (Certificate of Release or Discharge from Active Duty) to their applications.

National Guard Preference Applicants seeking National Guard Preference must attach an NGB 23A (RPAS), along with the state application, if they are a current member of the NC National Guard in good standing. Applicants who are former members of either the NC Army National Guard or the NC Air National Guard, with honorable discharge and six years of creditable service, must attach a copy of the DD 256 or NGB 22, along with the state application.

ADA Accommodations Consistent with the Americans with Disabilities Act (ADA) and the Pregnant Workers Fairness Act (PWFA), DHHS is committed to the full inclusion of all qualified individuals. As part of this commitment, DHHS will ensure that people with disabilities, or known limitations covered by the PWFA, are provided with reasonable accommodation. If reasonable accommodation is needed to participate in the job application or interview process, please contact the person indicated below.

Minimum Education and Experience

Some state job postings say you can qualify by an "equivalent combination of education and experience". If that language appears below, then you may qualify through EITHER years of education OR years of directly related experience, OR a combination of both. See the Education and Experience Equivalency Guide for details. Bachelor's degree in computer science or a related IT field or related degree from an appropriately accredited institution and two years of progressive experience in IT Security or closely related area; OR Associate degree in computer science or a related IT field or related degree from an appropriately accredited institution and three years of progressive experience in IT Security or closely related area; OR An equivalent combination of education and experience.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Server Analyst I
Server Analyst I

State of North Carolina • Morganton (NC)

Hybrid
USD 71,000 - 106,000
Applications Systems Lead
Applications Systems Lead

State of North Carolina - Health & Human Services • North Carolina

Hybrid
USD 88,000 - 131,000
IT Security & Compliance Specialist I - EHRA - Early Career
IT Security & Compliance Specialist I - EHRA - Early Career

State of North Carolina • North Carolina

Hybrid
USD 76,000 - 90,000
Enterprise Architect
Enterprise Architect

State of North Carolina • North Carolina

Hybrid
USD 105,000 - 184,000
Business Systems Analyst I
Business Systems Analyst I

State of North Carolina • North Carolina

Hybrid
USD 58,000 - 101,000
Hybrid work option
Competitive benefits
MIH Program Specialist
MIH Program Specialist

Health & Human Services • North Carolina

On-site
USD 41,000 - 72,000
Syndromic Surveillance Epidemiologist
Syndromic Surveillance Epidemiologist

State of North Carolina - Health & Human Services • North Carolina

Hybrid
USD 61,000 - 92,000
Educational Diagnostician II
Educational Diagnostician II

Health & Human Services • North Carolina

Hybrid
USD 53,000 - 92,000
Health insurance options
Retirement plans
Paid vacation & sick leave
+1
Applications Systems Specialist I
Applications Systems Specialist I

Secretary of State • North Carolina

On-site
USD 88,000 - 110,000
Health insurance
Twelve paid holidays
Personal observance leave day
+3
Applications Systems Specialist II – EHRA
Applications Systems Specialist II – EHRA

State of North Carolina - DIT EBS • North Carolina

Hybrid
USD 92,000 - 160,000