Cybersecurity Analyst II jobs in United States
cer-icon
Apply on Employer Site
company-logo

Texas Health and Human Services · 1 day ago

Cybersecurity Analyst II

Texas Health and Human Services Commission (HHSC) is committed to creating a positive impact in the lives of fellow Texans. The Cybersecurity Analyst II performs advanced information security analysis work, focusing on cloud security and web application protection, while assisting in monitoring security controls for information systems and advising business partners on security compliance requirements.

Health Care
badNo H1BnoteU.S. Citizen Onlynote
Hiring Manager
Indulekha (Indu) Nair
linkedin

Responsibilities

Provides security and risk management services by performing risk identification, assessment, and remediation, as well as regulatory and internal compliance monitoring
Performs needs assessment to identify requirements of automated systems and evaluate information security standards
Advises management and users regarding enterprise security program functions, including cloud security best practices, WAF policy implementation, and secure application development standards
Supports the cybersecurity training program by providing training to agency customers within assigned specific security domains, such as cloud security or secure web practices
Other duties as assigned

Qualification

Cloud securityWeb Application Firewalls (WAF)Risk managementEnterprise Governance Risk & Compliance (eGRC)NIST Special PublicationsSecurity certificationsProject managementCommunication skillsProblem-solvingTechnical writing

Required

Graduation from an accredited four-year college or university with major coursework in information technology security, computer information systems, computer science, management information systems, or a related field is strongly preferred. Education and experience may be substituted for one another on a year for year basis
2-4 years of experience in information technology, security risk, compliance management, assessment, auditing, research, and consulting
Experience with cloud security in one or more major platforms (Azure, AWS, GCP) is required
Requires one or more of the following or comparable foundational certifications: ISC2 Security Assessment and Authorization Certification (CAP), GIAC Security Essentials (GSEC), ISACA Certified Information Systems Auditor (CISA), CompTIA Security+
As well as one of the following cloud security certifications: Google Professional Cloud Security Engineer, Microsoft Certified Azure Security Engineer Associate, AWS Certified Security – Specialty
Knowledge in analyzing, recommending, & developing enterprise-wide security policies, standards, & guidelines within appropriate organizational risk tolerances
Skill in implementing enforcement of security policy within technology solutions
Knowledge of enterprise security program management using Enterprise Governance Risk & Compliance (eGRC) solutions
Demonstrated experience with the implementation & development of business processes in eGRC solutions
Knowledge of effective project management practices & ability to effectively manage multiple priorities
Excellent written and verbal communication skills
Knowledge of the limitations and capabilities of computer systems; of technology across all network layers and platforms; of operational support of networks, operating systems, cloud platforms (Azure, AWS, GCP), databases, and security applications; and information security practices, procedures, and regulations
Skill in operating computers and applicable software and configuring, deploying, tuning, and monitoring security infrastructure, especially Web Application Firewalls (WAF) and cloud-native security tools (e.g., Microsoft Defender for Cloud, AWS Security Hub)
Ability to solve complex security issues in diverse and decentralized environments and to communicate effectively to others in non-technical terms
In-depth understanding of the NIST Special Publications (800 Series) with particular emphasis on the SP 800-53 Security and Privacy Controls and their application to cloud environments
Skill in evaluating enterprise networks/systems and cloud-hosted applications for assurance of control requirements as specified
Ability to maintain the security and integrity of critical infrastructure systems by preventing unauthorized access and ensuring compliance with laws and regulations related to national security and foreign ownership restrictions

Preferred

Experience managing, tuning, and monitoring Web Application Firewalls (WAF) is strongly preferred
Experience in researching, authoring, or supporting the development of information security policies and standards
Experience developing security and risk performance metrics and reporting for executive, business, and technical audiences

Benefits

100% paid employee health insurance for full-time eligible employees
A defined benefit pension plan
Generous time off benefits
Numerous opportunities for career advancement

Company

Texas Health and Human Services

twittertwitter
company-logo
Texas Health and Human Services is an agency that focuses on improving health, safety and well-being.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Dr. Napoleon Broughton
Chief Executive Officer: Life Enhancement Solutions
linkedin
leader-logo
John F. Palermo
CTO Strategic Analyst VI
linkedin
Company data provided by crunchbase