Job summary:
Title:
Security Analyst with PCI/DSS
Location:
Raleigh, NC, United States
Length and terms:
Long term - W2 or C2C
Position created on 04/04/2022 04:18 pm
Job description:
Interview Type: Skype *** Very long term project; initial PO for 1 year, expect to go for 4+ years *** Remote during covid then onsite
Job Description:
The NCDIT Transportation Information Security Office (ISO) requires a senior information security architect analyst specializing in risk assessment and business technical consultation, focused on PCI DSS compliance.
This architect resource will consult on multiple projects to recommend security best practices, develop architectures and hardening guides, and review and evaluate solutions against relevant risk frameworks and regulations. This resource will provide information security policy, process, procedure and application consulting to the NCDIT Transportation Information Security Office and project support. This position will be an NCDIT Transportation Information Security Business Architect (ISBA) supporting project consulting. This resource will lead PCI DSS compliance activities for NCDOT. This resource should possess senior information security technical skillsets as well as senior soft skills as this resource will interface with IT and business leaders across the Agency. This resource should possess senior skillsets in preparing reports and presentations to senior management, program/project management and related staff on the recommendations, issues and status of any given IT information security aspect of a project or initiative. This resource must have extensive advanced information security practitioner experience with hands on experience implementing and operating a suite of standard information security technologies such as but not limited to firewalls, IDS/IPS, SIEM and network traffic capture and analysis. The position will require extensive experience and knowledge of information security frameworks such as ISO 27001, NIST 800 53 and other standards such as PCI DSS, FISMA, OWASP, FedRAMP, and federal law and NC General Statute. This position will benefit from current or prior experience as a PCI DSS QSA (Qualified Security Assessor) or ISA (Internal Security Assessor) role. This position will benefit from familiarity and experience with IT architecture frameworks and methodologies such as SABSA and TOGAF.
Required skills:
- Experience leading or directly supporting PCI DSS annual assessment for a L1 or L2 merchant, familiarity with PCI DSS 3.2 or higher. 3 Years
- Strong knowledge and experience architecting/designing implementations, configuring, and risk assessing AWS and/or Azure cloud computing environments. 3 Years
- Progressive advanced experience as an IT information security professional working within an enterprise environment. 5 Years
- Hands on experience implementing, administrating and operating technologies such as firewalls, IDS/IPS, SIEM, antivirus, network traffic analyzers 5 Years
- Detailed technical experience with network security, security protocols, access control, cryptography, application security, and data protection. 5 Years
- Extensive experience with data classification, handling, assessment, and enforcement. 5 Years
- Experience implementing and supporting systems within enterprise class data center environments. 5 Years
- Advanced knowledge of regulatory compliance including, but not limited to: OWASP, ISO, NIST, FISMA, PCI DSS, HIPAA and IRS 1075. 5 Years
- Experience leading risk assessments using industry standard frameworks such as ISO or NIST for complex IT projects and technologies. 5 Years
- Experience developing, leading and executing information security incident response plans. 5 Years
- Experience developing and implementing information security policy, standards and procedures. 5 Years
- Experience providing research and evidence in support of audits. 3 Years
Highly desired skills:
- CISSP information security certification.
- Specific experience implementing, administrating, or operating Tenable Nessus. 2 Years
- Specific experience implementing, administrating, operating or utilizing IBM Qradar SIEM 2 Years
- Experience consulting on information security solutions for a state or federal agency. 2 Years
- Experience implementing and operating enterprise class data networking solutions 5 Years
- Experience implementing and operating enterprise class server and storage systems 5 Years
- Detailed expert knowledge of NIST 800 53, and performing risk assessments utilizing NIST 800 53. 5 Years
- Detailed expert knowledge of ISO 27001, and performing risk assessments utilizing ISO 27001 2 Years
- Detailed expert knowledge of the NIST Cyber Security Framework (CSF), and performing risk assessments utilizing the NIST CSF. 2 Years
- Familiarity and experience with the Department of Homeland Security (DHS) Cyber Security Evaluation Tool (CSET). 2 Years
- Experience consulting on information security and IT solutions for a state motor vehicles agency or department of transportation.
- Experience performing risk assessments, documenting and driving compliance with the North Carolina DIT Statewide Information Security Manual.
- Experience completing NC Department of Information Technology Privacy Threshold Analysis (PTA) documentation.
- Experience completing NC Department of Information Technology Vendor Readiness Assessment Report (VRAR) documentation.
- Trained and experience implementing and operating with ITIL (formerly Information Technology Infrastructure Library) concepts.
- Familiarity and practical experience with SABSA or TOGAF enterprise architecture frameworks and methodologies.
Nice to have:
- SABSA or TOGAF certification.
- ITIL (formerly Information Technology Infrastructure Library) certification.
Contact the recruiter working on this position:
The recruiter working on this position is Hima Teja(Shaji Team)
His/her contact number is +(1) (202) 6290353
His/her contact email is teja@msysinc.com
Our recruiters will be more than happy to help you to get this contract.