Abacus Service Corporation ยท 20 hours ago
IT - SCDHHS - Security Analyst - Consultant
Abacus Service Corporation is looking for a Security Analyst - Consultant to support the South Carolina Department of Health and Human Services (SCDHHS). The Senior Information System Security Officer (ISSO) will lead Security, Risk, and Compliance activities, ensuring adherence to regulatory standards such as FISMA and NIST while collaborating with various stakeholders.
Health CareInformation Technology
Responsibilities
Perform detailed architectural reviews and risk analysis of security related requests in order to make sound decision making recommendations, such as:
Network Design and Information Flow
System and Data Access Models
Review Firewall Rule Requests (Ports, Protocols, and Services)
Baseline Configuration Management Deviation Requests
Vulnerability Management
Champion the design, development, implementation, and/or ongoing maturation of SCDHHS security and compliance efforts
Audit and assess internal agency systems as well as business partner/service provider information system security controls
Utilize Microsoft Office software suite, System Center Service Manager (Ticketing system), Archer eGRC system, Bizagi, Atlassian and other products to document and report on information gathered during Audit and Assessment activities or other OCS efforts
Perform security and compliance reviews of Contracts, Business Associate Agreements, Data Usage/Sharing Agreements, and other types of documents and artifacts
Serve as primary point of contact for third-party audits and/or assessments of agency and business partner systems
Collaborate with agency leadership, business partners, and other parties/ stakeholders to provide recommendations for security and compliance risk mitigation efforts
Qualification
Required
ISC(2), ISACA, SANS GIAC and/or other Information Security Certification is required
5+ years of experience in IT working with and/or auditing IBM System 390/zSeries, Windows, Linux, Databases (Relational and Non-Relational), Networking Infrastructure and Web-based Applications
Prior experience working within a FISMA or NIST compliant program
Prior experience in working with any eGRC systems
Preferred
Bachelor's in a related area or 10+ years of experience in the field or in a related area
Prior ITIL experience in the area of Information Security Management