Technical Cybersecurity Risk Analyst - Hybrid - Contract - Harrisburg, PA - B4098B
Hybrid in Harrisburg, PA, US • Posted 1 day ago • Updated 14 hours ago
Technovision, Inc.
Dice Job Match Score™
✨ Finding the perfect fit...
Job Details
Skills
- risk management
- audit
- NIST CSF/800-53
- CIS Controls
- ISO 27001
- state polices
- AWS/Azure cloud
- CISSP
- CISM
- CRISC
- CGRC (CAP)
- Security+
- CCSK/CCSP
- CISA certification
Summary
Our direct client is looking for a Technical Cybersecurity Risk Analyst for a Hybrid (2 days/week) Contract in Harrisburg, PA
Note:
- Full-time position (40 hr week)
- Hybrid schedule - 2 days on-site per week in Harrisburg
- Local candidates within 2 hours of office strongly preferred
J0B DESCRIPTION:
- The Technical Security Risk & Governance Analyst supports the state s cybersecurity program by performing risk assessments, control testing, and governance activities across enterprise systems, applications, networks, and cloud services. This role partners with IT, business owners, and audit teams to ensure security controls are designed,implemented, and operating effectively in alignment with state policy, NIST CSF/800-53, and other regulatory frameworks (e.g., CJIS, IRS Pub 1075, HIPAA, PCI DSS).
- The Analyst develops pragmatic recommendations, tracks remediation, and produces metrics for leadership and regulatory reporting.
Key Responsibilities:
- Risk Assessment & Control Assurance
-- Conduct technical security risk assessments for on?prem, cloud (IaaS/PaaS/SaaS), and hybrid solutions; document risks,likelihood/impact, and recommended mitigations.
-- Perform control design/operating?effectiveness testing against NIST CSF/800?53, CIS Controls, ISO/IEC 27001, and agency security standards.
-- Support Authority to Operate (ATO) processes, security attestations, and continuous monitoring.
-- Facilitate threat modeling and security architecture reviews; advise on secure patterns (network segmentation, IAM, least privilege, encryption, logging).
- Governance& Compliance
-- Maintain security policies, standards, procedures, and control libraries; align updates with legislative or regulatory changes.
-- Map agency controls to relevant mandates (e.g., CJIS, IRS 1075, HIPAA, FERPA, PCI DSS, state statutes/policies) and track compliance gaps.
-- Coordinate internal/external audits; lead evidence collection, responses, and remediation plans.
-- Administer or contribute to GRC tooling for issues, exceptions, and risk registers.
- Vulnerability& Third?Party Risk
-- Establish governance for vulnerability management (SLAs, exception management, risk acceptance); monitor patching and remediation progress.
-- Perform vendor/security reviews (SaaS, MSPs, cloud providers), evaluate SOC 2/ISO certifications, and negotiate security clauses with procurement/legal.
-- Review data protection, encryption, and privacy risks in new procurements and major system changes.
- Metrics, Reporting & Communication
-- Develop and maintain dashboards and performance indicators (risk posture, control maturity, vulnerability closure rates); brief leadership on trends and priorities.
-- Produce clear, actionable reports for technical teams and non?technical stakeholders.
-- Promote security awareness and targeted training(e.g., secure configuration, privacy by design, third?party onboarding).
- Incident& Change Advisory Support
-- Provide risk-informed guidance during incident response (root cause, control gaps, corrective actions).
-- Review change requests for security impacts; ensure appropriate testing, logging, and rollback plans.
Required Qualifications
- Bachelor s degree in Information Security, Computer Science, Information Systems, or related field; OR equivalent experience.
Knowledge
- Security frameworks and regulations: NIST CSF/800?53, CIS Controls, ISO 27001; familiarity with CJIS, IRS Pub 1075,HIPAA, FERPA, PCI DSS, and state policy.
- Core security domains: identity and access management (IAM), network security, endpoint security, vulnerability management, logging/SIEM, encryption/PKI, secure DevOps.
- Cloud security concepts (shared responsibility, CSPM, workload protection, KMS/CMKs, conditional access, zero trust).
Abilities
- Translate technical findings into business risk terms and prioritized actions.
- Collaborate across IT, operations, legal, procurement, and program areas; influence without authority.
- Handle multiple assessments and deadlines; maintain confidentiality and sound judgment.
- Continuous learning and adapting to new threats, technologies, and mandates.
Work Conditions & Requirements
- Background check per state policy; may require CJIS/IRS Pub 1075 clearance depending on data systems.
- Occasional travel to agency sites or data centers.
- Participation in after?hours change windows or incident support as needed.
- Hybrid/telework eligibility per agency policy.
Performance Measures
- On?time completion of risk assessments and control tests.
- Reduction in high/critical findings; SLA adherence for remediation.
- Audit outcomes (deficiency reduction, timely corrective actions).
- Governance deliverables (policy refresh cycle, control library currency).
- Stakeholder satisfaction and effectiveness of risk communications.
SKILL MATRIX:
- Experience in info security, risk management, audit or related technical role - Required
- Knowledge of NIST CSF/800-53, CIS Controls, ISO 27001 and state polices - Required
- Experience conducting technical assessments and control testing; proven ability to validate configs and interpret scan results - Required
- Experience with data analysis and dashboarding (Excel/Power BI), concise report writing, and ability to present to senior leadership - Required
- Experience using GRC platforms; building workflows, control libraries, and risk registers - Required
- Experience with risk analysis and documentation; creating practical risk treatment plans and exceptions with compensating controls - Required
- CISSP, CISM, CRISC, CGRC (CAP), Security+, CCSK/CCSP, or CISA certification - Strong Plus to have
- AWS/Azure cloud certifications are a plus - Strong Plus to have
Question 1: Position requires a hybrid schedule (estimated 2 days per week on-site). Is your candidate willing and able to report on-site in Harrisburg?
Question 2: Position could require occasional travel to a data center and/or agency site (although right now it is not expected). Would your candidate be willing and able to travel if required?
Location: Hybrid (2 days/week), Harrisburg PA
Type: Contract
Please send resume to "jobs at etechnovision dot com" with 4098B in Subject for immediate consideration.
- Dice Id: tecvis
- Position Id: B4098B
- Posted 1 day ago
Company Info
About Technovision, Inc.
TechnoVision's IT Services approach the customer with a 50-45-5 percent rule. We develop and offer 50 percent of our services by drawing upon our extensive industry experience and knowledge of trends we have tracked over time.
The next 45 percent of the solution is tailored to your precise needs. This level of importance is generated based on the aspect of customer differentiation. Every customer of ours is unique and extremely important. Hence we consider your organizational culture, your distinct business processes and operations, the needs of your customers, your risk tolerance, your competitors, and the dynamics of your markets. We concentrate on your organization's unique characteristics, such as tasks, workflow, business processes, finances and technology.
The last 5 percent is allocated to Contingency, and attributed to your anticipated needs or the uncertainties you face. This 5 percent solution enables your enterprise in change management, keeping your options open in case of contingency, and bracing yourself as changes occur around you.
Career Website
http://www.etechnovision.com
Careers
Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs