Job Title: Security Analyst III
Location: Remote within Wisconsin
Contract length: 9 months, possible extension
Schedule: 40 hrs; Mon-Fri
Pay: $37/hr to $42.66/hr, DOE
Position Overview:
Seeking a Level III security professional with vulnerability management knowledge, strong documentation and compliance experience, and excellent stakeholder communication skills. Success in this position depends on the ability to work cross-functionally, manage competing priorities, contribute to federal security compliance efforts, and serve as a trusted partner to both security teams and business stakeholders. This role requires understanding security concepts, technical requirements, and operational processes and communicating them effectively to non-security audiences.
Job Responsibilities:
· Integrate security into program operations
o Partner with organizational leaders to incorporate information security best practices into technical and operational development
o Provide recommendations on how to improve the information security posture of programs and reduce risk
o Communicate risks in simple and comprehensible terms. Provide options to mitigate risk considering business impact
o Draft security requirements to be included into charters, scope documents, and procurements
o Document and communicate analysis. Answer clarifying questions
o Escalate to ISS leadership if an acceptable level of risk cannot be achieved
· Act as a liaison between the program area and the Information Security Section
o Be a solutions-focused advocate
o Intake projects and other program initiatives and champion them through the appropriate ISS workstream
o Gather information as needed so that the security team can perform a thorough analysis
o Communicate workstream deliverables to the customer. Verify that the deliverable meets the customer need, and follow up on any clarifications
o Coordinate across ISS, meeting their security-focused needs
o Coordinate with other BITS staff, the Office of Legal Counsel, Bureau of Procurement and Contracting, and other program staff as needed in order to arrive at an outcome
· Support audit, assessment, incident response, and other regulatory activities
o Responsibility and authority will vary based on the use case and customer need
o Request and/or gather artifacts demonstrating compliance
o Schedule/facilitate communications between auditor/incident response, vendors, technical teams, and other program stakeholders
o In partnership with ISS, assess audit results and develop corrective action plans/plans of action and milestones
o Provide oversight to the resolution, test for compliance, and request authority to close
o Respond to regulatory inquiries and draft documents as needed
· Participate and support Program Integration related activities
o Backup other security liaison roles
o Draft and deliver status reports
o Establish and maintain positive working relationships with stakeholders
o Establish and document standard operations for job-related activities
· Support Vulnerability Management related to DMS and its vendors
o Foster transparency, accountability, and timely resolution of vulnerabilities with DMS and its vendors
o Support DMS and its vendors in adhering to state and federal regulations and Policies, Procedures, Standards and Guidelines (PPSGs) related to vulnerability management
o Draft and monitor plans of action and milestones for non-compliance
· Knowledge, Skills, and Abilities
- Well-qualified candidate will have broad knowledge of information security and experience in application development, technical architecture, contracting, audit, or vendor management
- Be familiar with NIST or another recognized framework
- Demonstrated ability to solve complex problems, convey both oral and written instruction, and handle multiple task interruptions while providing services in a professional and courteous manner
- Demonstrated attention to detail and organizational skills
- Demonstrated ability to work effectively with customers to solve business challenges while balancing the need for confidentiality, integrity, and availability
- Demonstrated commitment to fostering a diverse working environment
- Demonstrated ability to work independently, as part of a team of peers, and also to support and contribute to a multidiscipline team environment