Security Analyst II

Technoviz LLC

Madison (WI)

Hybrid

USD 85,000 - 115,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary
Opportunity for advancement
Training & development

Job summary

Wisconsin Department of Corrections is seeking a Security Analyst II (Compliance) to support risk assessment and compliance across DOC's IT and security functions. The role involves audits, findings, risk reporting, and guidance to IT and non-IT staff to meet regulatory standards.

You will help detect threats, contribute to forensics, and assist in vulnerability management and cloud security initiatives. The position requires strong communication, independent problem-solving, and a proactive

Qualifications

  • 5+ years applying NIST Cybersecurity Framework, RMF and related standards.
  • 5+ years developing, approving, and implementing security documents (policies, standards).
  • 5+ years triaging and analyzing cybersecurity alerts.

Responsibilities

  • Support risk assessment and compliance for Wisconsin DOC across IT and security domains.
  • Lead or participate in audits, draft findings and track corrective actions.
  • Analyze risks and prepare risk reports with metrics charts for stakeholders.
  • Guide IT and non-IT areas to align processes with regulatory requirements.
  • Detect, analyze, and respond to cyber threats; participate in forensics.
  • Support cloud security initiatives and tabletop exercise planning.
  • Develop and maintain security response procedures and playbooks.

Skills

NIST Cybersecurity Framework
NIST RMF
Security standards (NIST, CJIS, ISO)
NIST 800-53 controls
Phishing mitigation & email threat分析
Incident Response Forensics
Technical writing & incident reports
Team collaboration (distributed teams)

Job description

Benefits
  • Competitive salary
  • Opportunity for advancement
  • Training & development
POSITION SUMMARY – Security Analyst II (Compliance)

Under the general supervision of the GRC Manager, this position serves as a Security Analyst responsible for supporting a wide range of compliance and cybersecurity functions across the Wisconsin Department of Correction (DOC). Core responsibilities include providing risk assessment and/or compliance support. Taking part in or leading audits, submitting findings, analyzing risks for specific areas, monitoring corrective actions, and drafting risk reports with metric charts and ongoing effort accountability. This position assesses, documents, and provides guidance to other IT staff and non‑IT areas on how to align IT operational and technology processes based on information technology risk assessments and/or with regulatory compliance/audit functions. This position will also provide support in detecting, analyzing, and responding to cybersecurity threats, participating in forensic investigations, and contributing to ongoing vulnerability management efforts. The role may also include supporting cloud security initiatives, assisting with tabletop exercises, and developing security response procedures.

The incumbent will work collaboratively with internal stakeholders across DOC, as well as external partners including the Department of Administration’s Division of Enterprise Technology (DOA/DET). The role will utilize a variety of enterprise security tools and platforms.

This position may be assigned to focus areas such as incident response, phishing mitigation, threat detection, security awareness, vulnerability scanning, or forensic analysis, depending on organizational needs. The analyst will represent the DOC Information Security Section (ISS) team in technical discussions, project work, and collaborative efforts to improve DOC’s cybersecurity posture.

The position requires strong communication and problem‑solving skills, the ability to work independently on complex tasks, and a commitment to upholding the security and privacy standards of DOC. Clients and collaborators include information technology (IT) staff, application developers, infrastructure teams, business units, vendor, and external governmental partners. The work environment is dynamic, requiring adaptability, initiative, and a proactive mindset.

This position shall comply with the Department’s administrative rules and the agency’s policies and procedures including those related to the Department's overall Reentry philosophy of using evidence‑based strategies, practices and programs which target an offender’s individual criminogenic needs and risk level.

Top Skills & Years of Experience (At least 5 years of experience required)
  • Understanding of NIST Cybersecurity Framework, NIST RMF, and other common security standards.
  • Experience and working knowledge of common security frameworks and control theories to include current applicable NIST, CJIS, and ISO standards.
  • Experience with creating and leading discussions around the implementation and artifact collection of NIST 800-53 controls.
  • Proficiency in triaging and analyzing cybersecurity alerts using enterprise technologies and tools.
  • Familiarity with phishing mitigation strategies and email threat analysis.
  • Incident Response Forensics and Remediation (i.e. Crowdstrike, Sandbox evaluation & detonation, Phish evaluation, Malicious Website and Malicious Intent Identification).
  • Customer service as it pertains to security incident management and communication with end user about dangerous behavior.
  • Excellent technical writing and documentation skills, including incident reports and playbook development.
  • Ability to work independently and as part of a distributed team to achieve shared objectives.
Nice to have skills
  • Capability to tune and optimize SIEM rules and detection logic to reduce noise and improve fidelity.
  • Strong interpersonal communication skills with the ability to explain complex topics to non-technical audiences.
  • Experience working as a team member on projects to improve business needs.
  • Experience supporting endpoint, network, and cloud-based security controls in large-scale environments.
  • Demonstrated ability to adapt to emerging threats, technologies, and evolving operational needs.

Hybrid Remote: Remote daily work with the ability to report to Madison Office for training or when required for emergency situations. Must be a WI resident. No relocation allowed. Position will be 100% remote after training.

Required Skills
  • 5+ years of experience applying NIST Cybersecurity Framework, NIST RMF, and other common security standards.
  • 5+ years of experience in development, approval, and implementation of security documents (policies, standards, etc.).
  • 5+ years of experience in triaging and analyzing cybersecurity alerts.
Preferred Skills
  • 5+ years of experience in technical writing and documentation skills, including incident reports and playbook development.
  • 5+ years of experience in phishing mitigation strategies and email threat analysis.
  • 5+ years of experience supporting endpoint, network, and cloud-based security controls in large-scale environments.
Time % and Goals and Worker Activities
  • 60% – Support cybersecurity policy execution, operational standards, and governance activities.
  • 20% – Monitor, detect, respond to, and investigate cybersecurity threats across DOC’s enterprise environment.
  • 15% – Contribute to the configuration, deployment, and lifecycle management of security technologies.
  • 5% – Maintain current expertise in cybersecurity tools, trends, and techniques.

Flexible work from home options available.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity & Compliance Analyst II - Remote
Cybersecurity & Compliance Analyst II - Remote

Technoviz LLC • Madison (WI)

Hybrid
USD 85,000 - 115,000
Competitive salary
Opportunity for advancement
Training & development
Technical Security Risk & Governance Analyst
Technical Security Risk & Governance Analyst

Mbi Llc • Harrisburg

Hybrid
USD 80,000 - 100,000
Hybrid/telework eligibility
Participation in after-hours change windows or incident support
LU - Security Analyst 1.19
LU - Security Analyst 1.19

Focused HR Solutions • Columbia (SC)

On-site
USD 70,000 - 90,000
Security Operation Center (SOC) Analyst II
Security Operation Center (SOC) Analyst II

General Dynamics Information Technology • Colorado Springs (CO)

On-site
USD 112,000 - 138,000
Medical plan options
Dental and Vision plan options
401(k) plan with company match
Security Compliance Analyst
Security Compliance Analyst

Managed IT & Security Provider • Alexandria (VA)

On-site
USD 75,000 - 100,000
401(k)
401(k) matching
Bonus based on performance
+3
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Security Analyst II/III
Security Analyst II/III

Gaston County Government • Gastonia (NC)

On-site
USD 47,000 - 61,000
Security Operations Center Analyst II
Security Operations Center Analyst II

GRS, Inc. • Colorado Springs (CO)

On-site
USD 75,000 - 110,000
Cybersecurity Lead
Cybersecurity Lead

Leader Communications Inc. (LCI) • Alexandria (VA)

On-site
USD 90,000 - 120,000
Information Security Analyst - GRC & Operations
Information Security Analyst - GRC & Operations

WHSmith North America • Las Vegas (NV)

Hybrid
USD 70,000 - 110,000