PA - Technical Security Risk & Governance Analyst - 795990 (Hybrid)
• Posted 13 hours ago • Updated 20 minutes ago

SR International Inc.
Dice Job Match Score™
🫥 Flibbertigibetting...
Job Details
Skills
- including API Manager
- Data Analysis
- Procurement
- Network Security
- Metrics
- Google Cloud
- Governance
- Microsoft Azure
- Power Bi
- Microsoft Excel
- Incident Response
- Risk Assessment
- Cloud services
- Communication Skills
- Coordination Skills
- DevOps
- Dashboards
- Data Logging
- Information Technology
- Leadership
- Regulatory Compliance
- Amazon Web Services
- Infrastructure as a Service (IaaS)
- Platform as a Service (PAAS)
- Identity and Access Management
- Information Systems
- Risk Analysis
- Safety Principles
- Confidentiality
- Data Protection
- Cyber Security
- Carrying out Assessments
- Demonstration Skills
- Auditing Skills
- Consulting
- Negotiation Skills
- Cryptography
- Corrective and Preventive Action
- Health Insurance Portability and Accountability Act Compliance
- Data Centers
- National Institute of Standards and Technology
- Data Systems
- ISO/IEC 27001
- Treatment Plans
- Change Advisory
- Cloud Computing Security
- Continuous Monitoring
- Criminal Investigation
- External Audits
- Family Educational Rights and Privacy Act
- Governance Risk Management and Compliance
- Management by Exception
- Network Segmentation
- PCI Data Security Standards
- Public Key Infrastructure
Summary
-Technical Security Risk & Governance Analyst 795990 (Hybrid)
Closing Date: 2/20/2026
Full-time position (40 hr week)
Hybrid schedule - 2 days on-site per week in Harrisburg
Local candidates within 2 hours of office strongly preferred
Required Qualifications
Bachelor's degree in Information Security,Computer Science, Information Systems, or related field; OR equivalent experience.
1 3 years in information security, risk management, audit, or related technical role.
Preferred Qualifications(not required)
CISSP, CISM, CRISC, CGRC (CAP), Security+, CCSK/CCSP,CISA
Vendor/cloud certs (AWS/Azure/Google Cloud Platform security specialty) are a plus.
Knowledge
Security frameworks and regulations: NIST CSF/800 53, CIS Controls, ISO 27001; familiarity with CJIS, IRS Pub 1075,HIPAA, FERPA, PCI DSS, and state policy.
Core security domains: identity and access management (IAM), network security, endpoint security, vulnerability management, logging/SIEM, encryption/PKI, secure DevOps.
Cloud security concepts (shared responsibility, CSPM, workload protection, KMS/CMKs, conditional access, zero trust).
Skills
Technical assessment and control testing;ability to validate configurations and interpret scan results
Risk analysis and documentation; creating practical risk treatment plans and exceptions with compensating controls.
Using GRC platforms; building workflows, control libraries, and risk registers.
Data analysis and dashboarding (Excel/Power BI),concise report writing, and presentation to executives.
Abilities
Translate technical findings into business risk terms and prioritized actions.
Collaborate across IT, operations, legal,procurement, and program areas; influence without authority.
Handle multiple assessments and deadlines;maintain confidentiality and sound judgment.
Continuous learning and adapting to new threats,technologies, and mandates.
Work Conditions & Requirements
Background check per state policy; may require CJIS/IRS Pub 1075 clearance depending on data systems.
Occasional travel to agency sites or data centers.
Participation in after hours change windows or incident support as needed.
Hybrid/telework eligibility per agency policy.
Performance Measures
On time completion of risk assessments and control tests.
Reduction in high/critical findings; SLA adherence for remediation.
Audit outcomes (deficiency reduction, timely corrective actions).
Governance deliverables (policy refresh cycle,control library currency).
Stakeholder satisfaction and effectiveness of risk communications.
Job Description
The Technical Security Risk & Governance Analyst supports the state's cybersecurity program by performing risk assessments,control testing, and governance activities across enterprise systems,applications, networks, and cloud services. This role partners with IT,business owners, and audit teams to ensure security controls are designed,implemented, and operating effectively in alignment with state policy, NIST CSF/800-53, and other regulatory frameworks (e.g., CJIS, IRS Pub 1075, HIPAA, PCI DSS). The Analyst develops pragmatic recommendations, tracks remediation,and produces metrics for leadership and regulatory reporting.
Key Responsibilities
Risk Assessment & Control Assurance
Conduct technical security risk assessments for on prem, cloud (IaaS/PaaS/SaaS), and hybrid solutions; document risks,likelihood/impact, and recommended mitigations.
Perform control design/operating effectiveness testing against NIST CSF/800 53, CIS Controls, ISO/IEC 27001, and agency security standards.
Support Authority to Operate (ATO) processes,security attestations, and continuous monitoring.
Facilitate threat modeling and security architecture reviews; advise on secure patterns (network segmentation, IAM,least privilege, encryption, logging).
Governance& Compliance
Maintain security policies, standards,procedures, and control libraries; align updates with legislative or regulatory changes.
Map agency controls to relevant mandates (e.g.,CJIS, IRS 1075, HIPAA, FERPA, PCI DSS, state statutes/policies) and track compliance gaps.
Coordinate internal/external audits; lead evidence collection, responses, and remediation plans.
Administer or contribute to GRC tooling for issues, exceptions, and risk registers.
Vulnerability& Third Party Risk
Establish governance for vulnerability management (SLAs, exception management, risk acceptance); monitor patching and remediation progress.
Perform vendor/security reviews (SaaS, MSPs,cloud providers), evaluate SOC 2/ISO certifications, and negotiate security clauses with procurement/legal.
Review data protection, encryption, and privacy risks in new procurements and major system changes.
Metrics,Reporting & Communication
Develop and maintain dashboards and performance indicators (risk posture, control maturity, vulnerability closure rates); brief leadership on trends and priorities.
Produce clear, actionable reports for technical teams and non technical stakeholders.
Promote security awareness and targeted training(e.g., secure configuration, privacy by design, third party onboarding).
Incident& Change Advisory Support
Provide risk-informed guidance during incident response (root cause, control gaps, corrective actions).
Review change requests for security impacts;ensure appropriate testing, logging, and rollback plans.
- Dice Id: 10117029
- Position Id: 2026-630
- Posted 13 hours ago
Company Info
About SR International Inc.
SR International has been a leading name among the IT consulting companies with offices in US and India. For the past 20+ years, our industry experience and domain knowledge have enabled us to provide innovative solutions to our customers.
We Are Leading IT Based Solution Providers
Today, the world of business information represents the realization of our collective efforts toward improving the future. Held only by the limits of our imagination, the business world is accelerating at an ever-increasing pace. Imagine a better way of doing business, of implementing the perfect software, of refining practice or business integration. All it takes are benchmark standards in service, support, and technical know-how, which have been our bread and butter.
Our Vision.
Established in 2002, SR International Inc is one of the fastest growing and reputed provider of Information Technology Services and Solutions in the USA. Since our inception, we have been a trusted IT partner for our clients. We take pride in our highly skilled IT Resources and unique engagement model. We have been consistently delivering on our promises as a high-performance team. Our expertise in Cloud Computing, Mobility, Web Technologies, ERP and CRM are second to none. Our industry-leading flagship product iMathSmart is re-defining math learning experience for school students.


Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs