Senior Security Compliance Analyst

Tallahassee, FL, US • Posted 13 hours ago • Updated 1 hour ago
Contract W2
On-site
USD65 - USD85/hr
Fitment

Dice Job Match Score™

🤯 Applying directly to the forehead...

Job Details

Skills

  • Senior Security Compliance Analyst

Summary

job summary:

SCOPE OF WORK



The candidate will work closely with the Office of Information Technology, the Office of General Counsel, and Department program areas, and may serve as a liaison with the Florida Digital Service and with solution providers/suppliers on security matters. All work products are subject to ISM review and approval as described in Section 4.6.



The candidate must demonstrate the following abilities for consideration:



Broad mastery of information security across governance and operations - able to both author policy and standards and perform the hands-on technical work to implement and validate controls. Fluency in security control frameworks (NIST SP 800-53, NIST CSF) and the ability to map and crosswalk controls to the Florida Cybersecurity Standards (Rule 60GG-2, F.A.C.). Risk-based judgment - able to assess control gaps, prioritize remediation, and document risk decisions for management review. Clear technical writing - able to produce audit-ready policy, procedure, assessment, and management-response documentation. Operational competence in a Microsoft 365 / Microsoft Defender environment, including endpoint security, vulnerability management, identity and access controls, and incident response support. Ability to explain security risks, trade-offs, and remediation options to non-security stakeholders, including executives and counsel.



The Senior Security & Compliance Analyst will provide, but not be limited to, the following activities and tasks.



Governance, Policy & Standards.



The candidate will:



Draft, revise, and maintain Department information security policies and standards (including the 420-series), and establish and operate periodic review cycles.



Develop procedures supporting Department security policies consistent with Rule 60GG-2.002 and 60GG-2.003, F.A.C. Develop and maintain control mappings and crosswalks among NIST SP 800-53, NIST CSF, and Rule 60GG-2, F.A.C.



Maintain documentation, version control, and review evidence sufficient to satisfy internal and external audit.



Risk Management & Assessment.



The candidate will:



Conduct security risk assessments and control gap analyses against applicable frameworks.



Develop, track, and maintain Plans of Action and Milestones (POA&Ms) and corrective action plans.



Perform third-party / vendor security risk reviews, including review of vendor security documentation, contract security terms, and integration security (identity federation, per-transaction attribution, and audit logging).



Security Operations & Engineering Support.



The candidate will:



Support configuration, hardening, and monitoring within Microsoft 365 and Microsoft Defender (Defender for Endpoint, Defender Vulnerability Management, Microsoft Purview) consistent with Department standards.



Support vulnerability management: triage, tracking, and coordination of remediation. Support incident response consistent with the Department's Cybersecurity Incident Response Policy (420.01), including documentation and post-incident analysis.



Support identity and access management activities, including access reviews and provisioning-integrity controls.



Audit, Compliance & Reporting.



The candidate will:



Support response to Office of Inspector General (IG) and external audit findings, including evidence collection, control testing, and development of management responses.



Support compliance with the CJIS Security Policy and protection of PHI and other confidential information.



Develop security metrics, status reporting, and security awareness materials; support security governance meetings and working groups.



Contract Deliverables:



The candidate shall provide evidence of performance through documentation including, but not limited to:



Drafted and revised security policies and standards, with documented periodic-review cycles.



Control mapping crosswalks (NIST SP 800-53 / NIST CSF / Rule 60GG-2, F.A.C.). Security risk assessment reports and control gap analyses.



Plans of Action and Milestones (POA&Ms) and corrective action plans.



Third-party / vendor security review memoranda and diagnostic question sets.



Vulnerability management tracking and remediation status reports.



Incident documentation and post-incident (Root Cause Analysis) reports.



Audit evidence packages and draft management responses to IG / external findings.



Security metrics and periodic status reports.



Education and Certification:



The candidate must possess, at a minimum, a Bachelor's degree in computer science, information systems, cybersecurity, or a related field, or equivalent work experience; and at least one current industry certification from the following (others may be considered): CISA - Certified Information Systems Auditor (strongly aligned to the GRC/audit core). CRISC - Certified in Risk and Information Systems Control. CGRC - Certified in Governance, Risk and Compliance (formerly CAP). CISM - Certified Information Security Manager. CISSP - Certified Information Systems Security Professional.



QUALIFICATION REQUIREMENTS FOR SENIOR SECURITY & COMPLIANCE ANALYST



Minimum Qualifications:



The candidate must possess the minimum qualifications and experience:



a minimum of four (4) years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, and database design and administration, including one to two (1-2) years of experience with information security, and knowledge of security issues, techniques, and implications across all existing computer platforms.



Minimum of seven (7) years across information security disciplines, with demonstrated experience in both security governance/compliance (GRC) and hands-on security operations.



Demonstrated experience drafting information security policy and standards and implementing NIST SP 800-53 and/or NIST CSF controls.



Demonstrated experience performing security risk assessments and supporting internal or external audits.



Preferred Qualifications:



The following are preferred and will strengthen a candidate's evaluation:



Florida state government or public-sector information security experience.



Working knowledge of Rule 60GG-2, F.A.C., and Section 282.318, Florida Statutes. CJIS Security Policy implementation or audit experience.



HIPAA Security Rule and PHI-handling experience.



Hands-on Microsoft 365 G5, Microsoft Defender (Endpoint, Vulnerability Management), and Microsoft Purview experience.



Vulnerability management tooling and remediation-coordination experience.



Experience developing IAM / access-control standards and provisioning-integrity controls.



PowerShell or comparable scripting for security automation and reporting.







location: Tallahassee, Florida

job type: Contract

salary: $65 - 85 per hour

work hours: 8am to 5pm

education: Bachelors



responsibilities:

The Senior Security & Compliance Analyst will provide, but not be limited to, the following activities and tasks.



Governance, Policy & Standards.



The candidate will:



Draft, revise, and maintain Department information security policies and standards (including the 420-series), and establish and operate periodic review cycles.



Develop procedures supporting Department security policies consistent with Rule 60GG-2.002 and 60GG-2.003, F.A.C.



Develop and maintain control mappings and crosswalks among NIST SP 800-53, NIST CSF, and Rule 60GG-2, F.A.C.



Maintain documentation, version control, and review evidence sufficient to satisfy internal and external audit.



Risk Management & Assessment.



The candidate will:



Conduct security risk assessments and control gap analyses against applicable frameworks.



Develop, track, and maintain Plans of Action and Milestones (POA&Ms) and corrective action plans.



Perform third-party / vendor security risk reviews, including review of vendor security documentation, contract security terms, and integration security (identity federation, per-transaction attribution, and audit logging).



Security Operations & Engineering Support.



The candidate will:



Support configuration, hardening, and monitoring within Microsoft 365 and Microsoft Defender (Defender for Endpoint, Defender Vulnerability Management, Microsoft Purview) consistent with Department standards.



Support vulnerability management: triage, tracking, and coordination of remediation.



Support incident response consistent with the Department's Cybersecurity Incident Response Policy (420.01), including documentation and post-incident analysis.



Support identity and access management activities, including access reviews and provisioning-integrity controls.



Audit, Compliance & Reporting.



The candidate will:



Support response to Office of Inspector General (IG) and external audit findings, including evidence collection, control testing, and development of management responses.



Support compliance with the CJIS Security Policy and protection of PHI and other


Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: cxsapwma1
  • Position Id: 1341519
  • Posted 13 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Tallahassee, Florida

6d ago

Easy Apply

Contract

Depends on Experience

Tallahassee, Florida

Today

Easy Apply

Full-time, Contract

Remote

Today

Full-time

Remote

Today

Easy Apply

Contract

$80 - $110

Search all similar jobs