Senior IT Security Analyst (HCA/ITD #7261)

New Mexico Department of Justice

Albuquerque (NM)

On-site

USD 90,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

The New Mexico Health Care Authority seeks a Senior IT Security Analyst to lead governance, risk, and compliance efforts, ensuring adherence to federal and state IT security laws and policies. The role collaborates with staff, vendors, and auditors to drive security, audits, and remediation across enterprise systems.

Ideal candidates have MIS/IT education, 2+ years in IT security/compliance, and industry certifications (CISSP preferred; CISA/CISM/CASP+).

Qualifications

  • Bachelor's degree in MIS, IT, CS, Engineering, or a related technical field.
  • Two years of IT security or compliance validation experience.
  • CISSP certification (required); CISA, CISM, or CASP+ preferred.

Responsibilities

  • Develop cybersecurity governance policies, procedures, standards, and guidelines.
  • Perform audits and monitor compliance with security policies, standards, and procedures.
  • Coordinate with internal teams, regulatory auditors, and third-party security assessors.
  • Provide input into enterprise-wide security policies and standards.
  • Participate in defining project requirements and secure infrastructure designs.
  • Support risk analysis, risk management processes, and remediation activities.
  • Create, updating, and maintaining documentation for risks, controls, and remediation.
  • Check user accounts and access requests against authorized permissions.

Skills

IT security
Compliance validation
Auditing
Regulatory awareness

Education

Bachelor's degree in MIS/IT/CS/Engineering
Bachelor's degree in CS/MIS/IT
IT security/cforensics certs

Job description

Press Control+M to start dragging object

Job Title Senior IT Security Analyst (HCA/ITD #7261)

For more Job Requirements & Classification Description:

Interviews are anticipated to be conducted within two weeks of closing date.

This posting may be used to fill multiple vacancies.

The Health Care Authority (HCA) participates in E-Verify and will verify employment eligibility upon hire.

Our Vision

  • Every New Mexican has access to affordable health care coverage through a coordinated and seamless health care system.

Our Mission

  • We ensure that New Mexicans attain their highest level of health by providing whole-person, cost-effective, accessible, and high-quality health care and safety-net services.

Our Goals

  • Leverage purchasing power and partnerships to create innovative policies and models of comprehensive health care coverage that improve the health and well-being of New Mexicans and the workforce.
  • Achieve health equity by addressing poverty, discrimination, and lack of resources, building a New Mexico where everyone thrives.
  • Implement innovative technology and data-driven decision-making to provide unparalleled, convenient access to services and information.
  • Build the best team in state government by supporting employees' continuous growth and wellness.
Why does the job exist?

The Senior IT Security Analyst will:

  • Serve as the Governance and Compliance Analyst for the New Mexico Health Care Authority (HCA);
  • Work with staff, technical teams, and vendors to ensure HCA complies with federal and state IT security laws, regulations, policies, and procedures;
  • Lead all IT related audits, including drafting, reviewing, and submitting audit correspondence, plans, and required documentation;
  • Develop security and compliance policies and procedures for review by the Chief Information Security Officer (CISO) and Chief Information Officer (CIO);
  • Coordinate and manage workflow tasks associated with cybersecurity compliance and training initiatives, including:
  • Coordinating tasks for ongoing audits;
  • Cybersecurity policy development and lifecycle management;
  • Co-administering the Governance, Risk & Compliance (GRC) program.
How does it get done?

The Senior IT Security Analyst is responsible for:

  • Developing cybersecurity governance policies, procedures, standards, and guidelines;
  • Performing audits and monitoring compliance with security policies, standards, and procedures;
  • Coordinating and collaborating with internal teams, regulatory auditors, and third-party security assessors;
  • Providing input into developing, reviewing, and implementing enterprise wide security policies and standards;
  • Participating in defining project requirements and designing secure infrastructure solutions;
  • Supporting risk analysis, risk management processes, and identifying acceptable residual risk;
  • Conducting impact analysis and analyzing security reports to recommend mitigation strategies;
  • Creating, updating, and maintaining documentation for security risks, controls, and remediation activities;
  • Checking user accounts and access requests against authorized permissions;
  • Assisting with data classification, disaster recovery planning, and forensic investigations;
  • Reviewing and reporting security procedure violations and monitoring emerging security threats;
  • Assisting in developing safeguards to protect system configurations and prevent unauthorized changes;
  • Providing expertise for security awareness training to ensure continued compliance;
  • Developing and reporting on Corrective Action Plans (CAP) and maintaining Plans of Actions and Milestones (POAM).
Who are the customers?
  • Health Care Authority (HCA);
  • Other State Agencies.
Ideal Candidate

The Ideal Candidate has:

  • Bachelor's degree in Management Information Systems (MIS), Information Technology (IT), or a related technical field;
  • Two years of experience in IT security or compliance validation.
  • Cybersecurity certifications, such as:
  • CISSP;
  • CISA (preferred);
  • CISM;
  • CASP+.

Bachelor's degree in Computer Science, Management Information Systems (MIS), Information Technology, Engineering, or similar technical degree and three (3) years of experience in IT security or compliance validation (e.g., HIPAA, PCI). Any combination of education from an accredited college or university in a related field and/or direct experience in this occupation totaling seven (7) years may substitute for the required education and experience. A certificate in IT security/forensics (e.g., CISSP, CEH, CCFP, CCSP, HCISPP, SSCP) or regulated compliance (e.g., PCIP, ASV, ISA, QSA) can be used to substitute one (1) year of experience.

Employment Requirements

Must possess and maintain a valid Driver's License.

Must obtain a Defensive Driving Certificate.

Employment is subject to a pre-employment criminal background investigation and is conditional pending results.

Working Conditions

Work will be performed in an office environment. Many requests will arrive by phone or in-person and the person must be able to speak and respond to the requester clearly. The person will work extended periods seated in front of a computer. Position requires occasional 1) travel, 2) night/weekend/holiday work, and 3) call-back work.

Bargaining Unit Position

This position is not covered by a collective bargaining agreement.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior IT Security Analyst
Senior IT Security Analyst

Cybersecurity Jobs • Santa Fe (NM)

On-site
USD 50,000 - 74,000
Senior IT Security & Compliance Analyst
Senior IT Security & Compliance Analyst

New Mexico Department of Justice • Albuquerque (NM)

On-site
USD 90,000 - 120,000
Business Operations Analyst (HCA/DDSD#12836)
Business Operations Analyst (HCA/DDSD#12836)

New Mexico Department of Justice • Albuquerque (NM)

On-site
USD 52,000 - 70,000
Senior IT Security & GRC Analyst — Onsite Santa Fe
Senior IT Security & GRC Analyst — Onsite Santa Fe

Cybersecurity Jobs • Santa Fe (NM)

On-site
USD 50,000 - 74,000
Training Bureau Financial Analysis Specialist (HCA/ASD #10110358)
Training Bureau Financial Analysis Specialist (HCA/ASD #10110358)

New Mexico Department of Justice • Santa Fe (NM)

On-site
USD 42,000 - 70,000
HCS Info Security Analyst Sr
HCS Info Security Analyst Sr

UNC Health Care • Morrisville (NC)

On-site
USD 61,000 - 88,000
Cybersecurity Analyst II
Cybersecurity Analyst II

Texas Health and Human Services • Austin (TX)

On-site
USD 65,000 - 84,000
100% paid employee health insurance
Defined benefit pension plan
Generous time off benefits
+1
Senior Registered Nurse (HCA/DHI #74626)
Senior Registered Nurse (HCA/DHI #74626)

New Mexico Department of Justice • Las Cruces (NM)

On-site
USD 70,000 - 90,000
HCS Info Security Analyst Sr
HCS Info Security Analyst Sr

UNC Health • North Carolina

On-site
USD 93,000 - 133,000
Associate IT Systems Administrator (DOH/ITSD#32642)
Associate IT Systems Administrator (DOH/ITSD#32642)

New Mexico Department of Health • Santa Fe (NM)

On-site
USD 63,000 - 94,000