Lumen Solutions Group Inc. · 3 months ago
Security Analyst - Consultant
Lumen Solutions Group Inc. is seeking an experienced Senior Information Systems Security Officer to lead and support security and compliance initiatives. The role involves implementing and enhancing security programs aligned with regulatory frameworks and managing day-to-day security requirements across complex information systems.
Information Technology & Services
Responsibilities
Lead and manage security and compliance initiatives across information systems
Develop, maintain, and review System Security Plans (SSPs), PIAs, ISAs, CMAs, and related RMF/A&A artifacts
Perform architectural reviews and risk assessments of:
Network design and data flow
System and data access models
Firewall rule requests (ports, protocols, services)
Vulnerability management
Audit internal systems and vendor environments for compliance with agency standards
Review and provide recommendations on contracts, agreements, and compliance documentation
Act as the primary contact for third-party audits and assessments
Collaborate with leadership, vendors, and business partners to provide security recommendations and risk mitigation strategies
Document findings, reports, and recommendations using tools such as Microsoft Office, Archer eGRC, Bizagi, and Atlassian
Qualification
Required
5+ years of IT security experience auditing/working with IBM System 390/zSeries, Windows, Linux, databases (relational & non-relational), networking, and web applications
Strong working knowledge of FISMA, NIST, CMS MARS-E, and HIPAA standards
Proven experience within a FISMA-compliant security program
Hands-on experience with eGRC systems (Archer preferred)
Prior healthcare IT security experience
Professional security certification required: ISC(2), ISACA, SANS GIAC, or equivalent
Strong communication and collaboration skills, with the ability to engage both technical and non-technical stakeholders
Proficiency in Microsoft Office (Word, Excel, PowerPoint, Visio)
Preferred
Prior ITIL experience in Information Security Management
Experience integrating RMF/A&A processes into the SDLC
Familiarity with cloud security and vendor risk management
BS in Computer Science or related discipline (or 10+ years equivalent experience)