Role Overview:
This role will support the Governance, Risk, and Compliance (GRC) Team within the Arizona Department of Economic Security – Division of Technology Services. The position will focus on information security risk assessments, audits, compliance, security controls, documentation, and working closely with business and IT teams to identify risks and improve security processes.
Key Responsibilities:
- Perform security risk assessments, audit reviews, and compliance activities
- Generate findings reports and provide recommendations for improvement
- Develop and maintain POA&Ms (Plan of Action and Milestones), security plans, and risk documentation
- Evaluate IT environments for areas of non-compliance, risks, and security gaps
- Prepare and maintain audit documentation and security-related reports
- Investigate and document security incidents and suspicious network activity
- Research cybersecurity laws, regulations, industry standards, and best practices
- Support security and privacy control selection, implementation, assessment, and auditing
- Work with business units and IT teams to identify requirements, risks, and opportunities for improvement
- Develop and maintain key project artifacts and documentation
- Collaborate with technical project managers, senior management, and cross-functional teams
Required Qualifications & Skills:
- Strong experience with NIST 800-53 Revision 5 (Must Have)
- Experience with Risk Management Framework (RMF)
- Experience with Windows/Unix environments
- Strong knowledge of information security principles, policies, and procedures
- Experience with IT security risk management, auditing, and internal controls
- Knowledge of cybersecurity and privacy regulations, standards, and compliance requirements
- Ability to conduct technical system audits and security assessments
- Strong analytical, documentation, written, and verbal communication skills
- Ability to work effectively with business, technical, and senior management teams
Preferred Skills:
- Project Management experience
- CISSP, CCSP, GSTRT, GSNA, or CAP certification
- Experience with IRS Publication 1075, HIPAA/HITRUST, CJIS, or MARS-E
- Experience developing security policies, plans, and compliance documentation
- Experience working within government or public-sector environments
Pay: $44.00 - $46.00 per hour
Experience:
- IRS Publication 1075, HIPAA/HITRUST, CJIS, or MARS-E: 3 years (Preferred)
- NIST 800-53 Revision 5: 3 years (Required)
- Risk Management Framework (RMF): 3 years (Required)
- Project management: 3 years (Preferred)
Location:
- Phoenix, AZ 85007 (Required)
Work Location: Hybrid remote in Phoenix, AZ 85007