Texas Health and Human Services · 1 day ago
Cybersecurity Analyst II
Texas Health and Human Services Commission (HHSC) is committed to creating a positive impact in the lives of fellow Texans. The Cybersecurity Analyst II performs advanced information security analysis work, focusing on cloud security and web application protection, while assisting in monitoring security controls for information systems and advising business partners on security compliance requirements.
Responsibilities
Provides security and risk management services by performing risk identification, assessment, and remediation, as well as regulatory and internal compliance monitoring
Performs needs assessment to identify requirements of automated systems and evaluate information security standards
Advises management and users regarding enterprise security program functions, including cloud security best practices, WAF policy implementation, and secure application development standards
Supports the cybersecurity training program by providing training to agency customers within assigned specific security domains, such as cloud security or secure web practices
Other duties as assigned
Qualification
Required
Graduation from an accredited four-year college or university with major coursework in information technology security, computer information systems, computer science, management information systems, or a related field is strongly preferred. Education and experience may be substituted for one another on a year for year basis
2-4 years of experience in information technology, security risk, compliance management, assessment, auditing, research, and consulting
Experience with cloud security in one or more major platforms (Azure, AWS, GCP) is required
Requires one or more of the following or comparable foundational certifications: ISC2 Security Assessment and Authorization Certification (CAP), GIAC Security Essentials (GSEC), ISACA Certified Information Systems Auditor (CISA), CompTIA Security+
As well as one of the following cloud security certifications: Google Professional Cloud Security Engineer, Microsoft Certified Azure Security Engineer Associate, AWS Certified Security – Specialty
Knowledge in analyzing, recommending, & developing enterprise-wide security policies, standards, & guidelines within appropriate organizational risk tolerances
Skill in implementing enforcement of security policy within technology solutions
Knowledge of enterprise security program management using Enterprise Governance Risk & Compliance (eGRC) solutions
Demonstrated experience with the implementation & development of business processes in eGRC solutions
Knowledge of effective project management practices & ability to effectively manage multiple priorities
Excellent written and verbal communication skills
Knowledge of the limitations and capabilities of computer systems; of technology across all network layers and platforms; of operational support of networks, operating systems, cloud platforms (Azure, AWS, GCP), databases, and security applications; and information security practices, procedures, and regulations
Skill in operating computers and applicable software and configuring, deploying, tuning, and monitoring security infrastructure, especially Web Application Firewalls (WAF) and cloud-native security tools (e.g., Microsoft Defender for Cloud, AWS Security Hub)
Ability to solve complex security issues in diverse and decentralized environments and to communicate effectively to others in non-technical terms
In-depth understanding of the NIST Special Publications (800 Series) with particular emphasis on the SP 800-53 Security and Privacy Controls and their application to cloud environments
Skill in evaluating enterprise networks/systems and cloud-hosted applications for assurance of control requirements as specified
Ability to maintain the security and integrity of critical infrastructure systems by preventing unauthorized access and ensuring compliance with laws and regulations related to national security and foreign ownership restrictions
Preferred
Experience managing, tuning, and monitoring Web Application Firewalls (WAF) is strongly preferred
Experience in researching, authoring, or supporting the development of information security policies and standards
Experience developing security and risk performance metrics and reporting for executive, business, and technical audiences
Benefits
100% paid employee health insurance for full-time eligible employees
A defined benefit pension plan
Generous time off benefits
Numerous opportunities for career advancement
Company
Texas Health and Human Services
Texas Health and Human Services is an agency that focuses on improving health, safety and well-being.
Funding
Current Stage
Late StageLeadership Team
Recent News
Help Net Security
2025-04-09
Fort Worth Star-Telegram
2024-04-01
Company data provided by crunchbase