Job Title: IT Security Analyst
End Client: Onsite Columbus
Location: Ohio Department of Medicaid, 50 W. Town Street, Columbus, Ohio 43215 (Onsite, 5 Days/Week)
About the Role:
seeking an IT Security Analyst 3 to support the agency's enterprise cybersecurity, governance, risk management, compliance, and security operations program. The consultant will provide technical expertise in evaluating security risks, supporting regulatory compliance, conducting security assessments, coordinating audit activities, and assisting with the implementation and maintenance of security controls across ODM applications, infrastructure, cloud services, and third-party environments.
The consultant will work closely with the IT Risk & Security Manager, Agency Information Security Officer (AISO), Privacy Officer, Infrastructure Services, application teams, project managers, business stakeholders, and external vendors to support ODM's cybersecurity strategy and ensure compliance with applicable federal, state, and agency security requirements.
Key Responsibilities:
- Support ODM cybersecurity, governance, risk management, compliance, and security operations initiatives across agency applications, infrastructure, cloud services, and third-party environments
- Perform security risk assessments, security reviews, and technical evaluations of new and existing systems, applications, and technology initiatives
- Conduct vendor security reviews and evaluate SOC reports, security questionnaires, architecture diagrams, and compliance documentation
- Support compliance activities related to CMS, HIPAA, NIST, ARC-AMP-E/MARS-E, IRS Publication 1075, and other applicable federal and state security requirements
- Participate in audit preparation, evidence collection, audit response activities, remediation tracking, and corrective action planning
- Identify cybersecurity risks and collaborate with business units, ITS teams, vendors, and project teams to develop mitigation strategies
- Support Governance, Risk, and Compliance (GRC) activities, including policies, standards, procedures, and documentation
- Participate in security monitoring, incident response coordination, vulnerability management, and security operations supporting ODM enterprise systems
- Review system architecture, cloud solutions, infrastructure changes, and third-party integrations for compliance with ODM security requirements
- Coordinate with the Agency CISO, Risk Manager, Privacy Officer, Infrastructure teams, project managers, business units, and vendors
- Track security findings, vulnerabilities, POA&Ms, and remediation activities
- Assist with implementation and maintenance of NIST-aligned security controls and ODM security standards
- Develop executive security reports, compliance documentation, risk summaries, and security metrics
- Participate in SDLC activities to ensure security requirements are incorporated throughout project implementation
- Provide security consultation for cloud services, enterprise applications, third-party integrations, and emerging technologies
Required Qualifications:
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems, or related field preferred
- Minimum 5 years of professional experience in cybersecurity, information security, governance, risk management, or compliance
- Minimum 3 years conducting security risk assessments, vendor security reviews, or compliance evaluations
- Experience supporting NIST, CMS, HIPAA, ARC-AMP-E/MARS-E, IRS Publication 1075, or comparable frameworks
- Experience supporting Governance, Risk, and Compliance (GRC) programs
- Experience with vulnerability management, audit readiness, evidence collection, remediation tracking, and continuous monitoring
- Experience reviewing cloud technologies, enterprise architecture, and third-party integrations
- Strong analytical, documentation, communication, and organizational skills
Desired Skills:
- CISSP, CISM, CISA, Security+, CGRC, or equivalent certification preferred
- Experience with Azure, AWS, or Google Cloud security
- Experience with SIEM technologies and security monitoring
- Experience performing vendor security assessments and third-party risk management
- Knowledge of Medicaid systems or state government security practices preferred
- Experience supporting Agile project environments
Special Requirements: Onsite All 5 Days
eye