Job summary:


Title:
Security Analyst with NIST and FISMA - 20% Remote

Location:
Columbia, SC, United States

Length and terms:
Long term - W2 Only


Position created on 09/23/2016 07:53 pm

Job description:


*** W2 Only; no c2c; H1B Transfer OK ***

General Duties and Responsibilities:


  • 1. Assist in the development, implementation, and/or ongoing maturation of SCDHHS security and compliance initiatives.
  • 2. Audit and assess internal agency systems as well as business partner, service provider, and vendor information system security controls.
  • 3. Utilize the Microsoft Office software suite, eGRC system, Bizagi, Atlassian, and other products to document and report on information gathered during audit and assessment activities or other OIA efforts.
  • 4. Participate in third-party audits and/or assessments of agency and business partner systems.
  • 5. Collaborate with agency leadership, business partners, and other parties/stakeholders to provide recommendations for security and compliance risk mitigation efforts.

REQUIRED CERTIFICATION: ISC(2), ISACA, SANS GIAC, or other similar Information Security Certification is required.

EDUCATION PREFERRED: Bachelor’s degree in computer science or similar discipline is preferred.


Required Knowledge/Skills:


  • 1. Strong working knowledge of FISMA, NIST, and HIPAA Security and Privacy requirements, standards, and guidelines.
  • 2. 5+ years of experience working in the Information Technology field or auditing Information Technology systems or programs.
  • 3. ISC(2), ISACA, SANS GIAC, or other similar Information Security Certification is required.
  • 4. Documented experience in the creation and maintenance of Risk Management Framework (RMF) and Assessment and Authorization (A&A) artifacts such as System Security Plans, Privacy Impact Assessments, Interconnection Security Agreements, Computer Matching Agreements, and Plans of Action and Milestones.
  • 5. Ability to work independently and as a member of a team.
  • 6. Ability to multitask and prioritize tasks effectively in order to meet deadlines.
  • 7. Ability to engage diverse audiences of varying technical and non-technical skill-levels to ensure effective alignment of technical requirements to business objectives.
  • 8. Ability to collaborate and coordinate efforts among multiple teams and vendors.
  • 9. Must have intermediate to advanced skills in Microsoft Office products (Word, Excel, PowerPoint, Visio) to include working with templates and style guidelines for branding consistency.
  • 10. Keen attention to detail while maintaining the ability to see the big picture.
  • 11. Ability to absorb, retain, and communicate complex processes.
  • 12. Strong English language skills.
  • 13. Demonstrable understanding of the rules of English grammar and usage.
  • 14. Ability to accept changes and constructive criticism and to remain flexible in dealing with leadership and teams of varying technical and business knowledge.

Preferred Requirements/Skills:

  • 1. Bachelor’s degree in computer science or similar discipline.
  • 2. Strong working knowledge of CMS MARS-E compliance requirements.
  • 3. Prior experience working with an organization subject to CMS MARS-E requirements.
  • 4. Experience and training with eGRC solutions.
  • 5. Prior Health Information Technology experience.
  • 6. Previous Medicaid experience.
  • 7. Understanding of LEAN and Agile development practices.





Contact the recruiter working on this position:



The recruiter working on this position is Sohail Khan
His/her contact number is +(1) (315) 7504424
His/her contact email is sohail.khacxvvcvn@msysinc.com

Our recruiters will be more than happy to help you to get this contract.