DIRECT CLIENT:
Information Security Analyst
Location: Carson City, NV
Duration: 12+ months (extendable)
Rate: $doe
100% REMOTE
Position Description
Information Technology (IT) Professionals analyze, develop, implement, maintain, and modify computer operations, systems, networks, databases, applications, and/or information security. Incumbents may perform duties in one or more IT specialization areas depending on the needs of the agency. Incumbents perform supervisory duties and manage projects of varying size, scope, and impact to agency operations to include serving as the project leader; planning, organizing, and directing project activities; resolving design conflicts; data administration; resource allocation; contract negotiation; timeline development; critical path tracking; justifying the need for additional resources; and coordination with other work units within and outside the
organization as assigned.
• Support Penetration Testing
• Conduct comprehensive assessments of the management in accordance with NIST Risk Management Framework (RMF), operational, and technical security controls employed within or inherited by a system to determine the overall effectiveness of the security controls using NIST 800-53 and Center for Internet Security (CIS) Controls for OMV ON-PREM and Cloud environments including AWS, Salesforce, and Mulesoft CSPs.
• Generate and maintain required IS security documentation including Systems Security Plans (SSP), Information Assurance Standard
Operating Procedures (IA SOP), Continuous Monitoring Plans, Security Control Traceability Matrices, Risk Assessments, Plan of Action & Milestones (POA&M), equipment specifications, practices, and procedures.
• The position will perform security audits and support external agency audits to ensure compliance with state and federal rules in the following areas: investigations, security awareness training administration, security access control recommendations, badge access administration, risk assessments, approval authorization, anomalous activity detection alert notifications and incident response, and evaluation of software and hardware recommendations with related cost estimates.