Security Analyst

Novalink Solutions LLC

Madison (WI)

On-site

USD 95,000 - 125,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Wisconsin Department of Health Services (DHS) information security team seeks a seasoned liaison to integrate security into program operations and to act as the primary conduit between program areas and the Information Security Section. The role emphasizes risk assessment, timely remediation, and regulatory compliance across DHS initiatives.

Ideal candidate will demonstrate cross-functional collaboration, the ability to translate risk into actionable requirements, and strong communication skills

Qualifications

  • Broad knowledge of information security and experience applying security controls.
  • Familiar with NIST or other recognized security frameworks.
  • Strong written and verbal communication, able to present to diverse audiences.
  • Proven ability to work independently and in a multidisciplinary team.

Responsibilities

  • Integrate information security into DHS program operations and procurement.
  • Act as liaison between program areas and ISS, coordinating security deliverables.
  • Support audits, assessments, incident response, and regulatory activities.
  • Draft and monitor plans of action and milestones for non-compliance.
  • Back up security liaison roles and document standard operating procedures.

Skills

Information security
NIST frameworks
Communication
Team collaboration

Job description

Madison, United States | Posted on 08/24/2026

The Department of Health Services (DHS) is one of the largest and most diverse state agencies in Wisconsin. DHS

employs more than 7,000 staff spanning ten divisions and offices and seven 24/7 institutions located throughout

Wisconsin. Programs and services administered by DHS include Medicaid and other human service programs, alcohol

and other drug abuse prevention services, mental health, public health, and long-term care.

The Information Security Section (ISS) serves the Department by creating an information security culture and enabling

the business. We are metrics minded, employee focused, and view security as a service. ISS is responsible for

  • Identifying and continuously assessing risk
  • Developing, institutionalizing, and improving strategies to mitigate risk
  • Limiting the potential effects of information security events
  • The selection, assessment, authorization, and monitoring of security controls while contributing to the overall information security plan.

The Information Security Section (ISS) is functionally organized into Security Awareness and Governance, Compliance, Architecture, and Portfolio Management. Cross-team collaboration is essential to our success.

The DHS Liaison serves the Division of Medicaid Services and is the champion for security initiatives integrating

information security into program operations. This work is completed by engaging other security staff, communicating

risk, and developing strategies to reduce risk. To successfully do this work, one must possess strong communication and

interpersonal skills capable of presenting to diverse audiences including executive and non-technical individuals.

A federally recognized (ANSI) information security certification must be obtained within 6 months of the start date and

maintained for this position. The Department of Defense (DOD) 8570 Baseline Certifications defined by Defense

Information Systems Agency (DISA) is the baseline to consider when reviewing the relevance of the certification.

Goals and Worker Activities
1. Integrate security into program operations
  • Partner with organizational leaders to incorporate information security best-practices into technical and
  • Provide recommendations on how to improve the information security posture of programs and reduce risk.
  • Communicate risks in simple and comprehensible terms. Provide options to mitigate risk considering business impact.
  • Draft security requirements to be included into charters, scope documents, procurements.
  • Document and communicate analysis. Answer clarifying questions.
  • Escalate to ISS leadership if an acceptable level of risk cannot be achieved
2. Act as a liaison between the program area and the Information Security Section
  • Be a solutions-focused advocate.
  • Intake projects and other program initiatives and champion them through the appropriate ISS workstream
  • Gather information as needed so that security team can perform thorough analysis
  • Communicate workstream deliverables to the customer. Verify that the deliverable meets the customer need, follow-up on any clarifications.
  • Coordinate across ISS meeting their security-focused needs
  • Coordinate with other BITS staff, Office of Legal Counsel, Bureau of Procurement and Contracting, and other program staff as needed in order to arrive to an outcome
3. Support audit, assessment, incident response, and other regulatory activities
  • Responsibility and authority will vary based on the use case and customer need.
  • Request and/or gather artifacts demonstrating compliance.
  • Schedule/facilitate communications between auditor/incident response, vendors, technical teams, and other program stakeholders.
  • In partnership with ISS, assess audit results and develop corrective action plans/plans of action and milestone.
  • Provide oversight to the resolution, test for compliance, and request authority to close.
  • Respond to regulatory inquiry and draft documents as needed
4. Participate and support Program Integration related activities
  • Back-up other security liaison roles
  • Draft and deliver status reports
  • Establish and maintain positive working relationships with stakeholders
  • Establish and documents standard operations for job-related activities.
5. Support Vulnerability Management related to DMS and its vendors
  • Foster transparency, accountability, and timely resolution of vulnerabilities with DMS and its vendors
  • Support DMS and its vendors in adhering to state and federal regulations and Policies, Procedures, Standards and Guidelines (PPSGs) related to vulnerability management
  • Draft and monitor plans of action and milestones for non-compliance
6. Support DHS’s transition from the Center for Medicare and Medicaid Services (CMS) compliance requirements known as the Minimum Acceptable Risk Standards for Exchanges (MARS-E) to the new requirements known as Acceptable Risk Controls for ACA, Medicaid, and Partner Entities (ARC-AMPE)
  • In partnership with Deloitte, DET, and ISS conduct GAP analysis to support transition, implementation, and maturation of DHS’s
  • Draft the ARC-AMPE System Security and Privacy Plan (SSPP) and keep it current
  • Draft and monitor plans of action and milestones for non-compliance
7. Support DHS in completing software reviews, cloud brokerage reviews, and AI Use Case reviews
8. Other duties as assigned
  • Back-up other security staff
  • Write concept papers, proposals and briefs, and other documentation
Knowledge, Skills, and Abilities
  • Well qualified candidate will have broad knowledge of information security and experience application
  • Be familiar with NIST or another recognized framework
  • Demonstrated ability to solve complex problems, convey both oral and written instruction, and handle multiple task interruptions while providing services in a professional and courteous manner.
  • Demonstrated attention to detail and organizational skills.
  • Demonstrated ability to work effectively with customers to solve business challenges while balancing the need for confidentiality, integrity, and availability.
  • Demonstrated commitment to fostering a diverse working environment.
  • Demonstrated ability to work independently, as part of a team of peers, and also to support and contribute to a multidiscipline team environment
Requirements

Position Summary

The Department of Health Services (DHS) is one of the largest and most diverse state agencies in Wisconsin. DHS employs more than 7,000 staff spanning ten divisions and offices and seven 24/7 institutions located throughout Wisconsin. Programs and services administered by DHS include Medicaid and other human service programs, alcohol and other drug abuse prevention services, mental health, public health, and long-term care.

The Information Security Section (ISS) serves the Department by creating an information security culture and enabling the business. We are metrics minded, employee focused, and view security as a service. ISS is responsible for

  • Identifying and continuously assessing risk
  • Developing, institutionalizing, and improving strategies to mitigate risk
  • Limiting the potential effects of information security events
  • The selection, assessment, authorization, and monitoring of security controls while contributing to the overall information security plan.

The Information Security Section (ISS) is functionally organized into Security Awareness and Governance, Compliance, Architecture, and Portfolio Management. Cross-team collaboration is essential to our success.

The DHS Liaison serves the Division of Medicaid Services and is the champion for security initiatives integrating information security into program operations. This work is completed by engaging other security staff, communicating risk, and developing strategies to reduce risk. To successfully do this work, one must possess strong communication and interpersonal skills capable of presenting to diverse audiences including executive and non-technical individuals.

A federally recognized (ANSI) information security certification must be obtained within 6 months of the start date and maintained for this position. The Department of Defense (DOD) 8570 Baseline Certifications defined by Defense Information Systems Agency (DISA) is the baseline to consider when reviewing the relevance of the certification.

Goals and Worker Activities
1. Integrate security into program operations
  • Partner with organizational leaders to incorporate information security best-practices into technical and
  • Provide recommendations on how to improve the information security posture of programs and reduce risk.
  • Communicate risks in simple and comprehensible terms. Provide options to mitigate risk considering business impact.
  • Draft security requirements to be included into charters, scope documents, procurements.
  • Document and communicate analysis. Answer clarifying questions.
  • Escalate to ISS leadership if an acceptable level of risk cannot be achieved
2. Act as a liaison between the program area and the Information Security Section
  • Be a solutions-focused advocate.
  • Intake projects and other program initiatives and champion them through the appropriate ISS workstream
  • Gather information as needed so that security team can perform thorough analysis
  • Communicate workstream deliverables to the customer. Verify that the deliverable meets the customer need, follow-up on any clarifications.
  • Coordinate across ISS meeting their security-focused needs
  • Coordinate with other BITS staff, Office of Legal Counsel, Bureau of Procurement and Contracting, and other program staff as needed in order to arrive to an outcome
3. Support audit, assessment, incident response, and other regulatory activities
  • Responsibility and authority will vary based on the use case and customer need.
  • Request and/or gather artifacts demonstrating compliance.
  • Schedule/facilitate communications between auditor/incident response, vendors, technical teams, and other program stakeholders.
  • In partnership with ISS, assess audit results and develop corrective action plans/plans of action and milestone.
  • Provide oversight to the resolution, test for compliance, and request authority to close.
  • Respond to regulatory inquiry and draft documents as needed
4. Participate and support Program Integration related activities
  • Back-up other security liaison roles
  • Draft and deliver status reports
  • Establish and maintain positive working relationships with stakeholders
  • Establish and documents standard operations for job-related activities.
5. Support Vulnerability Management related to DMS and its vendors
  • Foster transparency, accountability, and timely resolution of vulnerabilities with DMS and its vendors
  • Support DMS and its vendors in adhering to state and federal regulations and Policies, Procedures, Standards and Guidelines (PPSGs) related to vulnerability management
  • Draft and monitor plans of action and milestones for non-compliance
6. Support DHS’s transition from the Center for Medicare and Medicaid Services (CMS) compliance requirements known as the Minimum Acceptable Risk Standards for Exchanges (MARS-E) to the new requirements known as Acceptable Risk Controls for ACA, Medicaid, and Partner Entities (ARC-AMPE)
  • In partnership with Deloitte, DET, and ISS conduct GAP analysis to support transition, implementation, and maturation of DHS’s
  • Draft the ARC-AMPE System Security and Privacy Plan (SSPP) and keep it current
  • Draft and monitor plans of action and milestones for non-compliance
7. Support DHS in completing software reviews, cloud brokerage reviews, and AI Use Case reviews
8. Other duties as assigned
  • Back-up other security staff
  • Write concept papers, proposals and briefs, and other documentation
Knowledge, Skills, and Abilities
  • Well qualified candidate will have broad knowledge of information security and experience application
  • Be familiar with NIST or another recognized framework
  • Demonstrated ability to solve complex problems, convey both oral and written instruction, and handle multiple task interruptions while providing services in a professional and courteous manner.
  • Demonstrated attention to detail and organizational skills.
  • Demonstr
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

The Planet Group • Wisconsin

On-site
USD 80,000 - 120,000
Security Analyst III
Security Analyst III

Technoviz LLC • Madison (WI)

Hybrid
USD 80,000 - 110,000
Competitive salary
Opportunity for advancement
Training & development
Information Security Liaison - DHS
Information Security Liaison - DHS

I O DATASPHERE • Madison (WI)

Hybrid
USD 90,000 - 125,000
Cybersecurity Vulnerability Management & Compliance Analyst - $54 CTC - HYBRID (Must be WI resident)
Cybersecurity Vulnerability Management & Compliance Analyst - $54 CTC - HYBRID (Must be WI resident)

Chandra Technologies, Inc • Madison (WI)

Hybrid
USD 90,000 - 120,000
Information Security Liaison
Information Security Liaison

IO Datasphere • Madison (WI)

Hybrid
USD 90,000 - 120,000
Cyber Security Consultant at RICEFW Technologies Inc Columbia, MO
Cyber Security Consultant at RICEFW Technologies Inc Columbia, MO

RICEFW Technologies Inc • Columbia Township (MO)

On-site
USD 90,000 - 140,000
Senior ISSO & RMF Security Architect
Senior ISSO & RMF Security Architect

RICEFW Technologies Inc • Columbia Township (MO)

On-site
USD 90,000 - 140,000
Information Assurance / Security Specialist
Information Assurance / Security Specialist

Diverse Systems Group, LLC • Bethesda (MD)

On-site
USD 110,000 - 150,000
Information Systems Security Officer
Information Systems Security Officer

Modern Technology Solutions, Inc. (MTSI) • Patterson (OH)

On-site
USD 80,000 - 100,000
Information Assurance / Security Specialist
Information Assurance / Security Specialist

Vinstuen Femmeren jazzværtshus • Bethesda (MD)

On-site
USD 120,000 - 170,000