MGT is seeking a senior-level Information Security Analyst for a long-term W2 contract engagement supporting a large municipal government client in Connecticut. The consultant will be embedded directly with the client’s Cybersecurity Officer and work cross-functionally with IT, Legal, and department leadership.
This is a hands-on GRC + Security Operations role. The selected professional will design, implement, and operationalize a structured IT risk and cybersecurity framework aligned to NIST and federal standards.
Location: On-site (Stamford area, CT)
Schedule: 35 hours per week (fully on-site)
Duration: 6–12 months with likely extension
Employment Type: W2 contract through MGT
Key Responsibilities
- Program & Framework Development
- Develop and maintain information security policies, standards, and procedures
- Align cybersecurity program to NIST CSF 2.0, NIST RMF, FISMA, FedRAMP
- Build and maintain enterprise IT risk register and control inventory
- Design and implement annual Risk & Control Self-Assessment (RCSA) framework
- Conduct application and infrastructure risk assessments
- Perform SOC testing and support SOC audits
- Security Operations
- Conduct vulnerability assessments and targeted risk reviews
- Monitor and respond to security events and incidents
- Lead breach investigations, containment, and remediation
- Support SIEM, IDS/IPS, DLP, endpoint protection, and vulnerability management tools
- Develop POA&M tracking and remediation reporting
- Governance & Advisory
- Participate in audits and compliance assessments
- Develop threat intelligence monitoring processes
- Deliver security awareness training
- Serve as security risk advisory lead across departments
Required Experience
- 8–10 years progressive experience in information security, IT risk, or security operations
- Strong experience with NIST frameworks, ISO 27001, CIS Controls
- Hands-on experience with SIEM, IDS/IPS, firewalls, endpoint security, vulnerability management
- SOC testing and audit support experience
- Familiarity with Zero Trust architecture
- Experience with AWS, Azure, or GovCloud
- Government or regulated environment experience preferred
- Strong documentation and stakeholder communication skills
Additional Requirements
- Ability to commute daily and work fully on-site
- Available for full 35-hour schedule
- Commitment to 6–12 months
- Comfortable with public-sector budget parameters
- Background screening required
This is not an advisory-only role. The client needs a senior professional who can both design the framework and operationalize it.
If interested, please message directly or apply via LinkedIn.