Overview
Skills
Job Details
Position: Cybersecurity Analyst
Duration: 2 months then extended after fiscal year
Location: Montgomery, Alabama (Onsite from Day 1)
Position Description:
The Security Control Assessor (SCA or SCAR) resource will assist the Medicaid ISO in the assessment of security policies, procedures, templates, standards, guidelines, etc The SCAR Resource will perform third-party security assessments of Security and Privacy control implementations per Agency Security policy, Federal Regulations, and industry standards. This resource will also interface with external audit teams as audits are performed against Medicaid systems.
Skills Required:
- Cybersecurity Principles and Practices - understanding of cybersecurity frameworks such as NIST SP 800-53, and knowledge of or ability to understand applicable legislation and regulatory landscape.
- Technical Proficiency basic understanding/knowledge of operating systems and familiarity with virtual machine (VM) environments, best practice, system and component hardening, as well as basic network concepts, including firewalls, routers, and switches, VPNs, and other security protocols.
- Risk Management Knowledge and abilities to of risk assessment tools and methodologies, as well as experience in identifying vulnerabilities and threats to Information Resources.
- Procedure Development to include development and documentation of agency security procedures in alignment with agency requirements through coordination with agency process owners.
Experience Required:
2-3 years Systems and/or Network Support or Administration experience (with various operating systems, network configurations, and virtual and/or cloud environments) 1-2 years Information/Cyber Security experience, in some capacity, implementing, and supporting security measures for protecting networks, systems, and data (including direct or indirect experience with firewalls, intrusion detection systems, encryption, endpoint protection solutions, log aggregation/SIEM tools, or other security products and solutions.)
Experience Preferred:
- 1-2 years Governance,
- Risk Compliance Management experience with regulatory compliance such as HIPAA, CMS, IRS, and SSA requirements, along with practical application/implementation of security frameworks like NIST SP 800-53.
Education Required:
- Bachelor's Degree with a major or minor in Information Technology or Cyber Security fields
Education Preferred:
- Certifications at least one Cyber Security Industry certification, such as ISC2 Certified Information Systems Security Professional, EC-Council Certified Ethical Hacker, etc