Request ID: IN-8789-1 (910090614)
Security Analyst (ISC(2)/SANS GIAC/CISA) with FISMA, NIST, CMS MARS-E, HIPAA, zSeries, networking, Linux and eGRC experience
Location: Columbia SC
Resume: 5 pages max
Duration: 12 Months
Required Skills (rank in order of Importance):
1. Must have a strong working knowledge of FISMA, NIST, CMS MARS-E and HIPAA Security and Privacy.
2. Must have deep technical knowledge of secure systems architecture principles, security and compliance tools, data protection and access models.
3. 5+ years of experience in I.T. working with and/or auditing IBM System 390/zSeries, Windows, Linux, networking infrastructure and web-based applications.
4. ISC(2), ISACA, SANS GIAC and/or other Information Security Certification is required.
5. Ability to work independently and as a member of a team.
6. Ability to collaborate and coordinate with multiple teams and vendors.
7. Ability to multitask and prioritize tasks effectively in order to meet deadlines.
8. Experience and training with eGRC solutions.
9. Ability to engage diverse audiences of varying technical and non-technical skill-levels to ensure effective alignment of technical requirements to business objectives.
10. Ability to collaborate and coordinate efforts amongst multiple teams and vendors in fulfillment of Client OIA initiatives.
11. Ability to multitask and prioritize tasks effectively in order to meet deadlines in a results-oriented environment.
12. Must have intermediate to advanced skills in Microsoft Office products (Word, Excel, PowerPoint, Visio) to include working with templates and style guidelines for branding consistency.
13. Keen attention to detail while maintaining the ability to see the big picture.
14. Ability to absorb, retain and communicate complex processes.
16. Ability to accept changes and constructive criticism and remain flexible in dealing with leadership and teams of varying technical and business knowledge.
Preferred Skills (rank in order of Importance):
1. Prior experience working within a FISMA compliant program.
2. Prior experience in working with any eGRC systems.
3. Prior Health Information Technology experience.
ANY ONE OR COMBINATION OF:
• ISC(2), ISACA, SANS GIAC and/or other Information Security Certification
• OR SIMILAR WITH VALID EXPERIENCE
Daily Duties / Responsibilities:
The Information Security Architect will report to the Office of Information Assurance and operate as an experienced consultant to Client leadership, business units, business partners and vendors.
Security Program Experience:
• Experience with CMS MARS-E or other FISMA Risk Management Framework (RMF) compliant programs is
strongly desired and will be given the highest weight. Experience should include well documented success
in the performance of security focused processes and procedures supportive of a secure, compliant
• Experience with development and integration of RMF tasks and artifacts into the System Development Life
Cycle (SDLC) is ideal.
• Experience in security as related to multi-tenant, cloud services and vendor interface management would
be considered desirable for this position.
Hands on experience with any or all of the following technologies would be considered a desirable for this position:
• IBM System 390/zSeries
• Linux and Windows servers
• Network Firewalls, Intrusion Prevention Systems (IPS), Switching and Routing Infrastructure
• Security Information and Event Management (SIEM) solutions
• Identity and Access Management (IAM) solutions
1. Assist in the design, development, implementation and/or ongoing maturation of Client security and
2. Provide hands-on support of Client Systems and Software
3. Participate in audit and assessment of internal agency systems as well as business partner/service provider
4. Utilize Microsoft Office software suite, eGRC system, Bizagi, Atlassian and other products to document and
report on information gathered during Audit and Assessment activities or other OIA efforts.
5. Participate in third-party audits and/or assessments of agency and business partner systems
6. Collaborate with agency leadership, business partners and other parties/stakeholders to provide
recommendations for security and compliance risk mitigation efforts.
Documentation/Language Ability to write, edit, and prepare graphic presentations of technical information for both technical and business personnel Yes 1 Advanced Currently Using 6 + Years
Miscellaneous Ability to deal effectively with the needs of technical peers, technical and user management, users, vendors, and staff members, and to communicate clearly and effectively in spoken and written form Yes 1 Advanced Currently Using 6 + Years
Network Security Security Information Architecture Yes 1 Advanced Currently Using 4 – 6 Years
Network Security SECURITY TOOLS – Ability to install and use various security tools Yes 1 Advanced Currently Using 4 – 6 Years
Network Security Federal Information Security Management Act (FISMA) No 1 Advanced Within 6 Months 4 – 6 Years
Network Security OWASP Top 10 remediation techniques No 1 Advanced Within 6 Months 4 – 6 Years
Network Security risk/vulnerability assessments No 1 Advanced Within 6 Months 4 – 6 Years
Networking & Directories Experience with UNIX, Windows, Linux, MacOS, Cisco, Juniper, web apps, databases, strong authentication, operating systems and network security protocols and procedures. Yes 1 Lead Currently Using 6 + Years
Networking & Directories Identity Access Management (IAM) Yes 1 Advanced Currently Using 4 – 6 Years
Networking & Directories Local Area Network (LAN) Yes 1 Lead Currently Using 6 + Years
Networking & Directories Virtual LAN (VLAN) Yes 1 Advanced Currently Using 6 + Years
Operating Systems/APIs MAINFRAME OPERATIONS No 1 Advanced Currently Using 6 + Years
Packaged Applications MS Office (Word, Excel, PowerPoint, Visio) Yes 2 Intermediate Currently Using 6 + Years
Specialties eGRC solutions Yes 1 Advanced Within 6 Months 1 – 2 Years