Unknown Company

Information Security Analyst

augusta, me • Posted 3 days ago
Onsite Full Time General

Information Security IT Audit AnalystThe Information Security IT Audit Analyst serves as a vital member of the Information Security Office, ensuring that information security compliance requirements critical to safeguarding the client’s network are met. This position will ensure that federal, state, and nongovernmental governance bodies’ statutory and regulatory requirements for protected data types are maintained and improved. To meet these requirements, the successful candidate must be knowledgeable about information technology and generally understands information technology security concepts outlined by the National Institute of Standards and Technology (NIST).Representative tasks include:Working with state and federal agency representatives on all aspects of regulatory compliance requirements (reporting, auditing, inspections).Responsible for federal audits from pre-audit preparation through the remediation of audit findings and reporting of Corrective Action Plans and closing information to the federal agencies.Verify and update security documentation reflecting the application/system security design features.Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals.Applicant must be organized and able to manage several reporting deadlines for the State and Federal Agencies.Working with MaineIT and/or vendor project teams to ensure compliance is maintained and/or gained in the ever-changing state's network.Skills required:Regulatory ComplianceCommunication - both written and oralInformation SecurityKnowledge, skills and abilities required:Strong analytical skills.Strong facilitator skills.Familiarity with information technology and security.Familiarity with information security controls as outlined in NIST SP 800-53.Good written and verbal communication skills.Ability to work independently and with a team.A high level of attention to detail.Comfortable managing multiple tasks simultaneously.Opportunity to develop in the position by gaining:Improved understanding of information security laws, rules, regulations, policies, and procedures;A broader knowledge of specific Federal, state, and nongovernmental regulatory compliance standards that state governments contend with (e.g., IRS Pub 1075, CMS MARS-E 2.2, PCI, CJIS, Social Security Administration, NACHA); andExperience working in state government as part of a large IT enterpriseMinimum qualifications: A Bachelor of Arts degree in an appropriate field (e.g., Computer Science, Information Security).

Demonstrated experience with audit and compliance regimes. Additionally, experience with the National Institute of Standards and Technology Special Publication 800-53 (NIST SP 800-53) Security and Privacy Controls for Federal Information Systems and Organizations.

Back to Job Search