CCS Global Tech is a rapidly growing Information Technology company with a diverse portfolio of technology products and services and a large network of industry partnerships. With over 22 years of being a successful business with a global talent pool and presence, CCS is a certified Microsoft Gold Partner and specializes in delivering expert Microsoft based solutions for technical and business needs. We have been recognized by Inc. 500 Magazine as one of the fastest growing small companies in the Unites States.
we are a Tier 1 vendor for the City and County of San Francisco for Cloud Services, Staffing Services and Training Services. For this multi-year opportunity with a diverse set of needs to address, we are currently focusing on establishing partnerships with individuals as well as companies who can help us enhance our overall service portfolio, cut lead times, and ultimately help us deliver successfully. We currently hold sizable Government accounts in the San Francisco bay area including City and County of San Francisco, San Mateo County, and Santa Clara County.
We take great pride in our global reach and local influence. Your experience alongside our highly skilled and talented internal team who guide you along the way, offers key insights into what helps you stand out in a competitive job market.
If you are a partner company, please submit resumes with contact information of your own W2 Consultants only. Submitted consultants are expected to have excellent communication skills.
Roles/Responsibilities:
A network security analyst ensures that information systems and computer networks are secure. This includes protecting the company against hackers and cyber-attacks, as well as monitoring network traffic and server logs for activity that seems unusual. Additionally, these analysts are responsible for finding vulnerabilities in the computer networks and creating recommendations for how to minimize these vulnerabilities. The network security analyst investigates security breaches, develops strategies for any security issues that arise, and utilizes the help of firewalls and antivirus software to maintain security. DISCLAIMER: Candidates for this position will be subject to a pre-employment security review to determine employment eligibility.
- Develop, update, and maintain System Security Plans for HHSC applications and systems.
- Work with program teams, Information Owners, and Custodians to gather control implementation evidence.
- Ensure System Security Plans align with NIST, DIR, and HHSC CISO Office standards.
Security Assessments (SA)
- Plan and conduct Security Assessments to validate implementation and effectiveness of security controls.
- Review technical, administrative, and operational evidence.
- Document assessment results and track remediation activities.
Risk Assessments (RA)
- Facilitate Risk Assessment workshops with Information Owners and Custodians.
- Identify threats, vulnerabilities, likelihood, and impact.
- Document risks, mitigation plans, and Risk-Based Decisions in RSA Archer.
GRC & Compliance Operations
- Maintain security artifacts, risks, and remediation plans in RSA Archer GRC.
- Support system authorization (ATO) activities and continuous monitoring.
- Prepare audit and oversight evidence.
- Produce leadership reports and security posture metrics.
Stakeholder Engagement
- Serve as liaison between program areas, technical teams, and CISO Office leadership.
- Provide guidance and training on System Security Plans, Security Assessments, and Risk Assessment processes.
Deliverables
- Completed and updated System Security Plans (SSPs)
- Documented Security Assessment reports and findings
- Completed Risk Assessments and Risk-Based Decisions
- RSA Archer risk and compliance records
- Remediation tracking and status reports
- Audit-ready security documentation packages
Mandatory Skills:
- 4+ years of experience in cybersecurity GRC, system security planning, or information assurance.
- 4+ years Hands-on experience developing System Security Plans (SSPs), conducting Security Assessments, and facilitating Risk Assessments.
- 4+ years- Knowledge of NIST SP 800-53 and NIST NIST Risk Management Framework.
- 4+ years- Experience using GRC platforms (RSA Archer preferred).
- 4+ years- Experience working with Information Owners and Custodians.
- 4+ years- Strong technical writing and documentation skills.
- 4+ years- Ability to work independently on complex assignments.
Desirable Skills:
- 2 years- Experience in state or federal government cybersecurity programs.
- 3 years- Familiarity with DIR Security Control Standards.
- 3 years- Experience supporting ATO and continuous monitoring.
- 1 years- CRISC or CISA certification.