Security Analyst

The Planet Group

Wisconsin

On-site

USD 80,000 - 120,000

Full time

38 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Planet Group is seeking an Information Security Liaison to embed security into program operations and work with organizational leaders to adopt information security best practices across development and procurement processes.

You will translate risks into actionable options, draft security requirements, and coordinate with ISS and program staff to ensure security needs are met while maintaining business priorities.

Qualifications

  • Broad knowledge of information security and experience in application development, technical architecture, contracting, audit, or vendor management.
  • Familiar with NIST or another recognized framework.
  • Demonstrated ability to solve complex problems, convey both oral and written instruction, and handle multiple task interruptions.
  • Demonstrated attention to detail and organizational skills.

Responsibilities

  • Integrate security into program operations and develop secure approaches.
  • Partner with organizational leaders to incorporate information security best practices into development and procurements.
  • Provide recommendations to improve the information security posture of programs and reduce risk.
  • Communicate risks in simple terms and provide mitigation options considering business impact.
  • Draft security requirements to be included into charters, scope documents, and procurements.
  • Coordinate across ISS and with program stakeholders to meet security needs and perspectives.

Skills

Information security concepts
Risk assessment
Regulatory compliance
Stakeholder communication
Vendor management
NIST framework knowledge

Job description

  • Integrate security into program operations
  • Partner with organizational leaders to incorporate information security best practices into technical and operational development
  • Provide recommendations on how to improve the information security posture of programs and reduce risk
  • Communicate risks in simple and comprehensible terms. Provide options to mitigate risk considering business impact
  • Draft security requirements to be included into charters, scope documents, and procurements
  • Document and communicate analysis. Answer clarifying questions
  • Escalate to ISS leadership if an acceptable level of risk cannot be achieved
  • Act as a liaison between the program area and the Information Security Section
  • Be a solutions-focused advocate
  • Intake projects and other program initiatives and champion them through the appropriate ISS workstream
  • Gather information as needed so that the security team can perform a thorough analysis
  • Communicate workstream deliverables to the customer. Verify that the deliverable meets the customer need, and follow up on any clarifications
  • Coordinate across ISS, meeting their security-focused needs
  • Coordinate with other BITS staff, the Office of Legal Counsel, Bureau of Procurement and Contracting, and other program staff as needed in order to arrive at an outcome
  • Support audit, assessment, incident response, and other regulatory activities
  • Responsibility and authority will vary based on the use case and customer need
  • Request and/or gather artifacts demonstrating compliance
  • Schedule/facilitate communications between auditor/incident response, vendors, technical teams, and other program stakeholders
  • In partnership with ISS, assess audit results and develop corrective action plans/plans of action and milestones
  • Provide oversight to the resolution, test for compliance, and request authority to close
  • Respond to regulatory inquiries and draft documents as needed
  • Participate and support Program Integration related activities
  • Backup other security liaison roles
  • Draft and deliver status reports
  • Establish and maintain positive working relationships with stakeholders
  • Establish and document standard operations for job-related activities
  • Support Vulnerability Management related to DMS and its vendors
  • Foster transparency, accountability, and timely resolution of vulnerabilities with DMS and its vendors
  • Support DMS and its vendors in adhering to state and federal regulations and Policies, Procedures, Standards and Guidelines (PPSGs) related to vulnerability management
  • Draft and monitor plans of action and milestones for non-compliance
  • Support DHS’s transition from the Center for Medicare and Medicaid Services (CMS) compliance requirements known as the Minimum Acceptable Risk Standards for Exchanges (MARS-E) to the new requirements known as Acceptable Risk Controls for ACA, Medicaid, and Partner Entities (ARC-AMPE)
  • In partnership with Deloitte, DET, and ISS conduct GAP analysis to support transition, implementation, and maturation of DHS’s
  • Draft the ARC-AMPE System Security and Privacy Plan (SSPP) and keep it current
  • Draft and monitor plans of action and milestones for non-compliance
  • Support DHS in completing software reviews, cloud brokerage reviews, and AI Use Case reviews
  • Other duties as assigned
  • Backup other security staff
  • Write concept papers, proposals, briefs, and other documentation
Knowledge, Skills, and Abilities
  • Well-qualified candidate will have broad knowledge of information security and experience in application development, technical architecture, contracting, audit, or vendor management
  • Be familiar with NIST or another recognized framework
  • Demonstrated ability to solve complex problems, convey both oral and written instruction, and handle multiple task interruptions while providing services in a professional and courteous manner
  • Demonstrated attention to detail and organizational skills
  • Demonstrated ability to work effectively with customers to solve business challenges while balancing the need for confidentiality, integrity, and availability
  • Demonstrated commitment to fostering a diverse working environment
  • Demonstrated ability to work independently, as part of a team of peers, and also to support and contribute to a multidiscipline team environment
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

Novalink Solutions LLC • Madison (WI)

On-site
USD 95,000 - 125,000
Security Analyst III
Security Analyst III

Technoviz LLC • Madison (WI)

Hybrid
USD 80,000 - 110,000
Competitive salary
Opportunity for advancement
Training & development
Information Systems Security Officer
Information Systems Security Officer

Modern Technology Solutions, Inc. (MTSI) • Patterson (OH)

On-site
USD 80,000 - 100,000
Cybersecurity Vulnerability Management & Compliance Analyst - $54 CTC - HYBRID (Must be WI resident)
Cybersecurity Vulnerability Management & Compliance Analyst - $54 CTC - HYBRID (Must be WI resident)

Chandra Technologies, Inc • Madison (WI)

Hybrid
USD 90,000 - 120,000
Information System Security Manager (Skill Level 2-3)
Information System Security Manager (Skill Level 2-3)

Strategic Analytix • Fort Meade (MD)

On-site
USD 100,000 - 140,000
Information Security Liaison - DHS
Information Security Liaison - DHS

I O DATASPHERE • Madison (WI)

Hybrid
USD 90,000 - 125,000
Information Assurance Engineer
Information Assurance Engineer

Agile IT Synergy, LLC • Tampa (FL)

On-site
USD 90,000 - 130,000
Information Security Liaison
Information Security Liaison

IO Datasphere • Madison (WI)

Hybrid
USD 90,000 - 120,000
Senior Security Analyst
Senior Security Analyst

ACL Digital • Atlanta (GA)

On-site
USD 100,000 - 150,000
Information Assurance / Security Specialist
Information Assurance / Security Specialist

Diverse Systems Group, LLC • Bethesda (MD)

On-site
USD 110,000 - 150,000