Job summary:
Title:
Security Analyst with NIST and FISMA - 20% Remote
Location:
Columbia, SC, United States
Length and terms:
Long term - W2 Only
Position created on 09/23/2016 07:53 pm
Job description:
*** W2 Only; no c2c; H1B Transfer OK ***
General Duties and Responsibilities:
- 1. Assist in the development, implementation, and/or ongoing maturation of SCDHHS security and compliance initiatives.
- 2. Audit and assess internal agency systems as well as business partner, service provider, and vendor information system security controls.
- 3. Utilize the Microsoft Office software suite, eGRC system, Bizagi, Atlassian, and other products to document and report on information gathered during audit and assessment activities or other OIA efforts.
- 4. Participate in third-party audits and/or assessments of agency and business partner systems.
- 5. Collaborate with agency leadership, business partners, and other parties/stakeholders to provide recommendations for security and compliance risk mitigation efforts.
REQUIRED CERTIFICATION: ISC(2), ISACA, SANS GIAC, or other similar Information Security Certification is required.
EDUCATION PREFERRED: Bachelor’s degree in computer science or similar discipline is preferred.
Required Knowledge/Skills:
- 1. Strong working knowledge of FISMA, NIST, and HIPAA Security and Privacy requirements, standards, and guidelines.
- 2. 5+ years of experience working in the Information Technology field or auditing Information Technology systems or programs.
- 3. ISC(2), ISACA, SANS GIAC, or other similar Information Security Certification is required.
- 4. Documented experience in the creation and maintenance of Risk Management Framework (RMF) and Assessment and Authorization (A&A) artifacts such as System Security Plans, Privacy Impact Assessments, Interconnection Security Agreements, Computer Matching Agreements, and Plans of Action and Milestones.
- 5. Ability to work independently and as a member of a team.
- 6. Ability to multitask and prioritize tasks effectively in order to meet deadlines.
- 7. Ability to engage diverse audiences of varying technical and non-technical skill-levels to ensure effective alignment of technical requirements to business objectives.
- 8. Ability to collaborate and coordinate efforts among multiple teams and vendors.
- 9. Must have intermediate to advanced skills in Microsoft Office products (Word, Excel, PowerPoint, Visio) to include working with templates and style guidelines for branding consistency.
- 10. Keen attention to detail while maintaining the ability to see the big picture.
- 11. Ability to absorb, retain, and communicate complex processes.
- 12. Strong English language skills.
- 13. Demonstrable understanding of the rules of English grammar and usage.
- 14. Ability to accept changes and constructive criticism and to remain flexible in dealing with leadership and teams of varying technical and business knowledge.
Preferred Requirements/Skills:
- 1. Bachelor’s degree in computer science or similar discipline.
- 2. Strong working knowledge of CMS MARS-E compliance requirements.
- 3. Prior experience working with an organization subject to CMS MARS-E requirements.
- 4. Experience and training with eGRC solutions.
- 5. Prior Health Information Technology experience.
- 6. Previous Medicaid experience.
- 7. Understanding of LEAN and Agile development practices.
Contact the recruiter working on this position:
The recruiter working on this position is Sohail Khan
His/her contact number is +(1) (315) 7504424
His/her contact email is sohail.khacxvvcvn@msysinc.com
Our recruiters will be more than happy to help you to get this contract.