Position: Information Security Analyst & Administrator
Agency/Program: KY OAG – Child Support Services
Work Location: Frankfort, KY (Hybrid preferred, but Remote acceptable)
Reports To: Executive Director (Office of Information Services
Engagement Type: Contract (Full-time)
Position Summary
About The Role: We are seeking an experienced Information Security Analyst and Administrator to support the Department of Child Support Services’ security related technologies, processes, and implementations. This position will serve as the primary IT Security subject matter expert especially with the deployment of a new Identity Access Management solution and case management system. The ideal candidate will have demonstrated experience serving in both project and IT operation capacities within the security domain. They will have knowledge and experience with both on-premises and cloud environments especially within OKTA, Azure platform, and Active Directory. Candidates must possess strong communication and organization skills, and a deep understanding of Identity and Access Management solutions. This position will work closely with the OIS, COT, and other technical team stakeholders.
Duties and Responsibilities
• Server as primary IT Security Subject Matter Expert (SME) for the Department of Child Support Services.
• Manage user authentication, authorization, and access control policies to prevent unauthorized access
• Support the design and build of role-based access control security frameworks for the department,
• Perform vulnerability scans, penetration tests, and risk assessments to identify and mitigate threats
• Monitor security alerts, investigate breaches, and respond to incidents promptly
• Develop, enforce, and update security policies; ensure compliance with legal and regulatory requirements
• Educate staff on security best practices and protocols
• Support the creation and maintenance of business continuity and disaster recovery plans
• Administer identity and access management (IAM) systems including OKTA, Active Directory, Azure AD, and privileged access workstations
• Monitor SIEM platforms (Splunk, Microsoft Sentinel, QRadar) for security events, tune alert rules, and escalate confirmed incidents
• Implement and enforce multi-factor authentication, certificate management, and single sign-on configurations across enterprise applications
• Develop and maintain security policies, standards, and procedures aligned with NIST CSF, ISO 27001, or CIS Controls frameworks
• Support security audits and compliance assessments for SOC 2, HIPAA, PCI-DSS, or FedRAMP by gathering evidence and remediating findings
• Perform security reviews on new systems, applications, and vendors as part of the change management and third-party risk process
• Investigate phishing incidents, malware infections, and unauthorized access events; document findings and implement corrective controls
• Identify and mitigate security replated project risks, issues, and dependencies, and develop contingency plans to ensure project success.
MUST-HAVE Requirements (non-negotiable)
• Deep technical expertise in Microsoft Active Directory and Microsoft Entra ID.
• Experience designing and implementing IAM integrations, provisioning workflows, and access controls.
• Proven experience implementation & maintaining role based access control frameworks.
• Proven ability to lead and mentor technical engineering teams.
• Strong understanding of identity security principles and enterprise authentication models.
• Previous experience with NIST CSF, ISO 27001, or CIS Controls frameworks
• Bachelor's degree, preferably in Computer Science, Information Technology, Computer Engineering, or related IT discipline; or equivalent experience
Preferred Qualifications
• Strong understanding of identity security principles and enterprise authentication models. (SAML, OIDC, SCIM) and access control models like Fine-Grained Authorization (FGA)
• Public sector child support/HHS; modernization programs.
• Firewalls and network security: Palo Alto Networks, Fortinet FortiGate, Cisco ASA/FTD — rule writing, NAT, VPN configuration
• SIEM: Splunk (SPL queries), Microsoft Sentinel (KQL), IBM QRadar — correlation rule tuning, dashboard creation
• Endpoint security: CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black — alert triage, isolation, policy management
• IAM: Active Directory, Azure Active Directory, Okta, CyberArk for PAM
• Scripting: PowerShell and Python for automation of repetitive security tasks (log parsing, alert enrichment, AD queries)
• Experience with ServiceNow and integration with prevalent identity access management platforms.
Tools and Platforms
ServiceNow, Active Directory, Okta, Ping Identity, Azure AD, Cisco ASA, Fortinet FortiGate, Palo Alto PA-OS, Check Point, FortiGate, Splunk, IBM QRadar, Microsoft Sentinel, eSet, Proofpoint Nessus, Qualys, NDiscovery, OpenVAS, ISO 27001 compliance checklists, CJIS compliance tools, SSAE 16 audit frameworks, NIST & Fed Ramp frameworks.
Certifications:
CompTIA Security+, CISSP (Certified Information Systems Security Professional), Microsoft Azure Security Engineer Associate (AZ-500) , Microsoft Applied Skills: Administer Active Directory Domain Services