Direct Client-Security Analyst-W2-Onsite role
6 days ago
DAILY DUTIES / RESPONSIBILITIES:
The Senior ISSO will report to the ISSO Team Lead in OCS and operate as an
experienced cybersecurity consultant to SCDHHS leadership, business units, business
partners and vendors.
Security Program Experience:
Leadership experience with CMS MARS-E, ARC-AMPE, or other FISMA Risk
Management Framework (RMF) compliant programs is strongly desired and will be
given the highest weight. Experience should include well documented success in the
development and maintenance of System Security Plans (SSPs), Privacy Impact
Assessments (PIAs), Interconnection Security Agreements (ISAs), Computer Matching
Agreements (CMAs), and related interviews and audit/assessment activities to complete
and verify these and other RMF/Assessment and Authorization (A&A) tasks and
artifacts.
Experience with development and integration of RMF/A&A tasks and artifacts in RMF
type roles such as; ISSO, Information Security Architect, Security Control Assessor, etc.,
into the System Development Life Cycle (SDLC) is ideal.
Experience in security as related to Cloud services and vendor management is considered
desirable for this position.
Technical Knowledge:
Hands on experience with any or all the following technologies would be considered a
desirable for this position:
Archer (eGRC)
Linux and Windows servers
Network Firewalls, Intrusion Prevention Systems (IPS), Switching and Routing
Infrastructure
Security Information and Event Management (SIEM) solutions
Identity and Access Management (IAM) solutions
General Duties and Responsibilities:
- Perform detailed architectural reviews and risk analysis of security related
requests in order to make sound decision making recommendations, such as:
a. Network Design and Information Flow
b. System and Data Access Models
c. Review Firewall Rule Requests (Ports, Protocols, and Services)
d. Baseline Configuration Management Deviation Requests
e. Vulnerability Management
- Champion the design, development, implementation, and/or ongoing maturation
of SCDHHS security and compliance efforts.
- Audit and assess internal agency systems as well as business partner/service
provider information system security controls.
- Utilize Microsoft Office software suite, System Center Service Manager
(Ticketing system), Archer eGRC system, Bizagi, Atlassian and other products to
document and report on information gathered during Audit and Assessment
activities or other OCS efforts.
- Perform security and compliance reviews of Contracts, Business Associate
Agreements, Data Usage/Sharing Agreements, and other types of documents
and artifacts.
- Serve as primary point of contact for third-party audits and/or assessments
of agency and business partner systems
- Collaborate with agency leadership, business partners, and other parties/
stakeholders to provide recommendations for security and compliance risk
mitigation efforts.
Required Knowledge/Skills:
- Must have a strong working knowledge of FISMA, NIST, CMS MARS-E and
HIPAA Security and Privacy.
- 5+ years of experience in IT working with and/or auditing Windows, Linux,
Databases (Relational and Non-Relational), Networking Infrastructure, and Web-
based Applications.
Prior experience working within a FISMA compliant program.
Prior experience in working with any eGRC systems.
Prior Health Information Technology experience.
ISC(2), ISACA, SANS GIAC and/or other Information Security Certification is
required.
Ability to work independently and as a member of a team.
Ability to collaborate and coordinate with multiple teams and vendors.
Ability to multitask and prioritize tasks effectively in order to meet deadlines.
Experience and training with eGRC solutions.
Ability to engage diverse audiences of varying technical and non-technical skill-
levels to ensure effective alignment of technical requirements to business
objectives.
- Ability to collaborate and coordinate efforts amongst multiple teams and vendors
in fulfillment of SCDHHS OCS initiatives.
- Ability to multitask and prioritize tasks effectively in order to meet deadlines in a
results-oriented environment.
- Must have intermediate to advanced skills in Microsoft Office products (Word,
Excel, PowerPoint, Visio) to include working with templates and style guidelines
for branding consistency.
Keen attention to detail while maintaining the ability to see the big picture.
Ability to absorb, retain and communicate complex processes.
Ability to accept changes and constructive criticism and remain flexible in dealing
with leadership and teams of varying technical and business knowledge.
Preferred Requirements/Skills:
- BS degree in computer science or similar discipline or 10+ years of experience in
the field or a in a related area.
- Prior ITIL experience in the area of Information Security Management.
REQUIRED SKILLS (RANK IN ORDER OF
IMPORTANCE):
- 5+ years of experience in IT
working with and/or auditing
Windows, Linux, Databases
(Relational and Non-Relational),
PREFERRED SKILLS (RANK IN ORDER OF
IMPORTANCE):
- Prior ITIL experience in the area of
Information Security Management.
Networking Infrastructure and
Web-based Applications.
- Prior experience working within a
FISMA compliant program.
- Prior experience in working with
any eGRC systems.
- Prior Health Information
Technology experience.
REQUIRED EDUCATION/CERTIFICATIONS:
- ISC(2), ISACA, SANS GIAC
and/or other Information Security
Certification is required.
PREFERRED EDUCATION/CERTIFICATIONS:
- Bachelor's in a related area or 10+
years of experience in the field or in
a related area.
-
Columbia, South Carolina, United States Devfi Full time $80,000 - $140,000 per yearW2 Role Local or Nearby to South CarolinaOnly US Citizen and Green Card HolderTitle: Senior Cloud Security EngineerLocation: Columbia SCDuration: 12 MonthsRole is hybrid (3 days onsite per week)Job SummaryWe are seeking an experienced Cloud Security Engineer with a strong background in cloud infrastructure, network security, and automation. The ideal...
-
Security Analyst
6 days ago
Columbia, South Carolina, United States IT Resource Hunter Full time $336,000 - $338,400 per yearTitle:Security Analyst - Consultant(W2 OR 1099)Pay Rate:$65.00-$80.00/hr.Interview Process:1 round, Virtual/OnlineDuration of the Contract:12 monthsPossibility for Extension:YesWork Location:Onsite - 5 days/week (Columbia, SC)Candidate Must Be Located In:SC, NC, GA, TNDAILY DUTIES / RESPONSIBILITIES:The Senior ISSO will report to the ISSO Team Lead in OCS...
-
Security Analyst
12 hours ago
Columbia, South Carolina, United States ZIRLEN TECHNOLOGIES INCORPORATED Full timeSecurity Analyst – Project LeadHybrid (3 days onsite per week) 1201 Main Street, Suite 600, Columbia, SC 29201Candidates must be South Carolina residentsRequired:5+ years expert-level security analyst experience3+ years' Participation in preparation for at least one IRS Safeguard Review at a state agencyIRS SCSEM technical expertise and experience3+ years...
-
Technical Business Analyst
4 days ago
Columbia, South Carolina, United States LanceSoft, Inc. Full time $62,400 per yearJob Title: Technical Business Analyst (W2 only)Job Location: Columbia, SC Hybrid (4 days onsite and 1 day remote)Job Duration: 12+ Months ContractPay Range: $60/hrs. on W2Job Responsibilities:Required Skills (rank in order of Importance):Ability to analyze, document, and improve business and system processes using various tools and methodologies.Experience...
-
Sr. Cloud Security Engineer
7 days ago
Columbia, South Carolina, United States DatamanUSA Full time $80,000 - $140,000 per yearDatamanUSA has an exciting opportunity for a talented Sr. Cloud Security Engineer to work with one of our direct Clients SC Department of Health & Human Services (SCDHHS), to work in Columbia, SC (Hybrid- 3 days remote & 2 days onsite). We love referrals Please refer us to your friends, family and colleagues for this opportunity. DatamanUSA gives referral...
-
W2- SAP Junior Technical Support Engineer
5 days ago
Columbia, South Carolina, United States Kanak Elite Services Full time $60,000 - $120,000 per year**Role :: SAP Junior Technical Support EngineerLocation ::**Columbia, South Carolina(Onsite)Duration :: Contract (W2 Only)Role OverviewWe are seeking a SAP Junior Technical Support Engineer tosupport HR systemsmodernization and ongoing operations. This role focuses onconfiguring, maintaining, and enhancing SAP ECC HR modules (SCEIS platform) and related HR...
-
Columbia, South Carolina, United States Devfi Full time $80,000 - $140,000 per yearW2 Position Local Candidates to South Carolina OnlyTitle: Network ArchitectLocation: Columbia SCDuration: 12 MonthsRole is hybrid (3 days onsite per week)Job SummaryWe are seeking an experienced Network Security Engineer with a strong background in Cisco technologies, network infrastructure, and cloud integration. The ideal candidate will have proven...
-
Business Analyst – HRIS
6 days ago
Columbia, South Carolina, United States COREHIRE Full time $80,000 - $120,000 per yearBusiness Analyst – HRIS / SAP Project LeadType: Contract W2Duration: 12 months (with possible extension)Location: Hybrid, 4 days onsite (Columbia, SC) per week (must be SC resident or relocate at own expense)Hours: 40 per week, with flexibility for occasional off‑hours workInterview: 1 round, virtual (video required)OverviewThe Business Analyst – HRIS...
-
Plant Cyber Security Analyst
2 days ago
Columbia, South Carolina, United States Energy Northwest Full time $122,681 - $184,021It's fun to work in a company where people truly BELIEVE in what they are doingWe're committed to bringing passion and customer focus to the business.This position is posted at multiple levels. Please see the job description below for more information.Be part of a high-impact team protecting the digital systems that power one of the most tightly regulated...
-
Senior Cloud Security Engineer
5 days ago
Columbia, South Carolina, United States 3B Staffing LLC Full time $120,000 - $180,000 per yearTitle: Senior Cloud Security EngineerLocation: Hybrid – 3 days remote, 2 days onsite in Columbia, South CarolinaDuration: 1 yearOnly W2……………………………..Job Description:a Senior Cloud Security Engineer to design, implement, and secure large-scale cloud infrastructure and applications. This is a hands-on engineering role (not development)...