We are looking for Information Security Analyst & Administrator for our client in Frankfort, KY.
Job Title: Information Security Analyst & Administrator
Job Location: Frankfort, KY
Job Type: Contract
Job Overview:
Pay Range: $45.00hr - $50.00hr
Requirement/Must Have:
- Deep technical expertise in Microsoft Active Directory and Microsoft Entra ID.
- Experience designing and implementing IAM integrations, provisioning workflows, and access controls.
- Proven experience implementing and maintaining role-based access control frameworks.
- Proven ability to lead and mentor technical engineering teams.
- Strong understanding of identity security principles and enterprise authentication models.
- Previous experience with NIST CSF, ISO 27001, or CIS Controls frameworks.
- Bachelor s degree, preferably in Computer Science, Information Technology, Computer Engineering, or related IT discipline; or equivalent experience.
Responsibilities:
- Serve as primary IT Security Subject Matter Expert (SME) for the organization.
- Manage user authentication, authorization, and access control policies to prevent unauthorized access.
- Support the design and build of role-based access control security frameworks for the department.
- Perform vulnerability scans, penetration tests, and risk assessments to identify and mitigate threats.
- Monitor security alerts, investigate breaches, and respond to incidents promptly.
- Develop, enforce, and update security policies; ensure compliance with legal and regulatory requirements.
- Educate staff on security best practices and protocols.
- Support the creation and maintenance of business continuity and disaster recovery plans.
- Administer identity and access management (IAM) systems including OKTA, Active Directory, Azure AD, and privileged access workstations.
- Monitor SIEM platforms (Splunk, Microsoft Sentinel, QRadar) for security events, tune alert rules, and escalate confirmed incidents.
- Implement and enforce multi-factor authentication, certificate management, and single sign-on configurations across enterprise applications.
- Develop and maintain security policies, standards, and procedures aligned with NIST CSF, ISO 27001, or CIS Controls frameworks.
- Support security audits and compliance assessments for SOC 2, HIPAA, PCI-DSS, or FedRAMP by gathering evidence and remediating findings.
- Perform security reviews on new systems, applications, and vendors as part of the change management and third-party risk process.
- Investigate phishing incidents, malware infections, and unauthorized access events; document findings and implement corrective controls.
- Identify and mitigate security-related project risks, issues, and dependencies, and develop contingency plans to ensure project success.
Nice to Have:
- Strong understanding of identity security principles and enterprise authentication models (SAML, OIDC, SCIM) and access control models like Fine-Grained Authorization (FGA).
- Experience with public sector modernization programs.
- Experience with firewalls and network security: Palo Alto Networks, Fortinet FortiGate, Cisco ASA/FTD rule writing, NAT, VPN configuration.
- Experience with SIEM: Splunk (SPL queries), Microsoft Sentinel (KQL), IBM QRadar correlation rule tuning, dashboard creation.
- Experience with endpoint security: CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black alert triage, isolation, policy management.
- Experience with IAM: Active Directory, Azure Active Directory, Okta, CyberArk for PAM.
- Scripting skills: PowerShell and Python for automation of repetitive security tasks (log parsing, alert enrichment, AD queries).
- Experience with ServiceNow and integration with prevalent identity access management platforms.
- Knowledge of tools and platforms: ServiceNow, Active Directory, Okta, Ping Identity, Azure AD, Cisco ASA, Fortinet FortiGate, Palo Alto PA-OS, Check Point, Splunk, IBM QRadar, Microsoft Sentinel, eSet, Proofpoint Nessus, Qualys, N-Discovery, OpenVAS, ISO 27001 compliance checklists, CJIS compliance tools, SSAE 16 audit frameworks, NIST & FedRAMP frameworks.
- Certifications: CompTIA Security+, CISSP (Certified Information Systems Security Professional), Microsoft Azure Security Engineer Associate (AZ-500), Microsoft Applied Skills.
- Ability to administer Active Directory Domain Services.
Skills:
- Information Security.
- Identity and Access Management (IAM).
- OKTA.
- Azure platform.
- Active Directory.
- Microsoft Entra ID.
- Role-based access control (RBAC).
- NIST CSF.
- ISO 27001.
- CIS Controls.
- SIEM (Splunk, Microsoft Sentinel, QRadar).
- Vulnerability scanning.
- Penetration testing.
- Risk assessment.
- Multi-factor authentication.
- PowerShell.
- Python.
Qualification And Education:
- Bachelor s degree in Computer Science, Information Technology, Computer Engineering, or related IT discipline; or equivalent experience.
===
Benefits
Our Benefits Include:
- Medical, Dental, and Vision Insurance
- 401(k) Retirement Plan
- Health Savings Account (HSA)
- Disability Insurance (Short-Term and Long-Term)
- Life and AD&D Insurance
- Paid Sick Leave (where required by applicable state or local law)
- Supplemental Insurance Plans
- Identity Theft Protection
- Pet Insurance
- Employee Wellness Programs
- Employee Assistance Program (EAP)
- Career Growth and Professional Development Opportunities
Disclaimer: Benefits eligibility, accrual rates, and usage limits may vary based on employment status, length of service, and work location. Paid Sick Leave is provided in strict accordance with applicable state and municipal mandates. Cynet Systems Inc. reserves the right to modify, amend, or terminate any benefit plans at any time in accordance with applicable laws.
About Cynet Systems
Founded in 2010 and headquartered in the Washington, DC metro area, Cynet Systems Inc. is a leading technology staffing and workforce solutions company serving Fortune 500 companies, government agencies, and enterprise organizations across the United States and Canada. We deliver agile, scalable talent solutions across IT, engineering, life sciences, clinical, and professional staffing, powered by a high-performing recruitment engine operating across North America and Asia.
As a nationally and locally certified Minority Business Enterprise (MBE), Cynet Systems is committed to helping organizations build high-performing teams while empowering professionals to grow rewarding careers. Our organization is certified to ISO 9001, ISO 14001, ISO 27001, and SOC 2 Type II standards, reflecting our commitment to quality, security, operational excellence, and customer success.