One of our clients in the government domain is seeking an IT Security Analyst to support the agency//'s enterprise cybersecurity, governance, risk management, compliance, and security operations program. The consultant will provide technical expertise in evaluating security risks, supporting regulatory compliance, conducting security assessments, coordinating audit activities, and assisting with the implementation and maintenance of security controls across ODM applications, infrastructure, cloud services, and third-party environments.
IT Security Analyst
Onsite
Columbus, OH
Long Term
Responsibilities
- Support ODM cybersecurity, governance, risk management, compliance, and security operations initiatives across agency applications, infrastructure, cloud services, and third-party environments.
- Perform security risk assessments, security reviews, and technical evaluations of new and existing systems, applications, and technology initiatives.
- Conduct vendor security reviews and evaluate SOC reports, security questionnaires, architecture diagrams, and compliance documentation.
- Support compliance activities related to CMS, HIPAA, NIST, ARC-AMP-E/MARS-E, IRS Publication 1075, and other applicable federal and state security requirements.
- Participate in audit preparation, evidence collection, audit response activities, remediation tracking, and corrective action planning.
- Identify cybersecurity risks and collaborate with business units, ITS teams, vendors, and project teams to develop mitigation strategies.
- Support Governance, Risk, and Compliance (GRC) activities, including policies, standards, procedures, and documentation.
- Participate in security monitoring, incident response coordination, vulnerability management, and security operations supporting ODM enterprise systems.
- Review system architecture, cloud solutions, infrastructure changes, and third-party integrations to ensure compliance with ODM security requirements.
- Coordinate with the Agency CISO, Risk Manager, Privacy Officer, Infrastructure teams, Project Managers, business units, and vendors.
- Track security findings, vulnerabilities, POA&Ms, and remediation activities.
- Assist with implementation and maintenance of NIST-aligned security controls and ODM security standards.
- Support continuous monitoring, vulnerability remediation, and operational security improvements.
- Develop executive security reports, compliance documentation, risk summaries, and security metrics.
- Participate in SDLC activities to ensure security requirements are incorporated throughout project implementation.
- Provide security consultation for cloud services, enterprise applications, third-party integrations, and emerging technologies.
- Develop and maintain security documentation, procedures, standards, and compliance artifacts.
- Communicate technical security risks and recommendations to technical and non-technical stakeholders.
- Perform additional cybersecurity, governance, risk management, compliance, and security operations duties as assigned.
Essential Requirements
- Bachelor//'s degree in Cybersecurity, Information Security, Computer Science, Information Systems, or related field preferred.
- Minimum 5 Years of professional experience in cybersecurity, information security, governance, risk management, or compliance.
- Minimum 3 Years conducting security risk assessments, vendor security reviews, or compliance evaluations.
- Experience supporting NIST, CMS, HIPAA, ARC-AMP-E/MARS-E, IRS Publication 1075, or comparable frameworks.
- Experience supporting Governance, Risk, and Compliance (GRC) programs.
- Experience with vulnerability management, audit readiness, evidence collection, remediation tracking, and continuous monitoring.
- Experience reviewing cloud technologies, enterprise architecture, and third-party integrations.
- Strong analytical, documentation, communication, and organizational skills.
- Ability to work independently while collaborating effectively with technical teams, business stakeholders, executive leadership, vendors, and external partners in a fast-paced government environment.
Desired Skills
- CISSP, CISM, CISA, Security+, CGRC, or equivalent certification preferred.
- Experience with Azure, AWS, or Google Cloud security.
- Experience with SIEM technologies and security monitoring.
- Experience performing vendor security assessments and third-party risk management.
- Knowledge of Medicaid systems or state government security practices preferred.
- Experience supporting Agile project environments.
- Excellent written and verbal communication skills.
- Strong leadership, analytical thinking, and problem-solving abilities.
Required Skills
- Bachelor//'s degree in Cybersecurity, Information Security, Computer Science, Information Systems, or related field preferred.
- Experience in cybersecurity, information security, governance, risk management, or compliance - Required | 5 Years
- Conducting security risk assessments, vendor security reviews, or compliance evaluations - Required | 3 Years
- Supporting NIST, CMS, HIPAA, ARC-AMP-E/MARS-E, IRS Publication 1075, or comparable frameworks - Required
- Governance, Risk, and Compliance (GRC) programs - Required
- Experience with vulnerability management, audit readiness, evidence collection, remediation tracking, and continuous monitoring - Required
- Experience reviewing cloud technologies, enterprise architecture, and third-party integrations - Required
Highly Desired Skills
- CISSP, CISM, CISA, Security+, CGRC, or equivalent certification preferred.
- Experience with Azure, AWS, or Google Cloud security.
- Experience with SIEM technologies and security monitoring.
- Knowledge of Medicaid systems or State Government security practices preferred.