IT Security Analyst 3/ ITSA 3
Location: Columbus, OH | Work Model: Onsite 5x week
About the Role
Client is seeking an IT Security Analyst 3 to support the agency's enterprise cybersecurity, governance, risk management, compliance, and security operations program. The consultant will provide technical expertise in evaluating security risks, supporting regulatory compliance, conducting security assessments, coordinating audit activities, and assisting with the implementation and maintenance of security controls across client applications, infrastructure, cloud services, and third-party environments.
The consultant will work closely with the IT Risk & Security Manager, Agency Information Security Officer (AISO), Privacy Officer, Infrastructure Services, application teams, project managers, business stakeholders, and external vendors to support the client's cybersecurity strategy and ensure compliance with applicable federal, state, and agency security requirements.
Responsibilities
- Act as lead Salesforce CRM developer and work closely with Business Analysts, Architects, and Project Managers in planning releases.
- Translate business processes into actionable Salesforce requirements for configuration and development.
- Participate in all aspects of the project life cycle, from initial kickoff through requirements analysis, design, implementation, testing, and post-production support.
- Maintain and enhance existing Salesforce solutions using the latest features.
- Apply Salesforce.com best practices for release management and deploying changes through sandboxes to production.
- Manage user and license administration, including setup/deactivation, roles, profiles, permissions, public groups, OWD, and sharing rules.
- Improve Salesforce data quality through data management, rules, and automation.
- Provide ad hoc data extracts as needed by business areas.
- Perform proactive system maintenance, including Security Reviews, Release Updates, Health Check, and Optimizer.
- Identify unused or underutilized platform features.
- Develop dashboards and complex customized reports.
- Manage user testing, including developing test plans and creating user test cases.
- Create and maintain documentation on processes, policies, configuration, and user guides.
- Lead integrations and support MuleSoft architects in converting existing custom APIs to the MuleSoft Anypoint platform.
- Create a roadmap, define priorities, and liaise with stakeholders.
- Mentor and train development resources.
- Support cybersecurity, governance, risk management, compliance, and security operations initiatives across agency applications, infrastructure, cloud services, and third-party environments.
- Perform security risk assessments, security reviews, and technical evaluations of new and existing systems, applications, and technology initiatives.
- Conduct vendor security reviews and evaluate SOC reports, security questionnaires, architecture diagrams, and compliance documentation.
- Support compliance activities related to CMS, HIPAA, NIST, ARC-AMP-E/MARS-E, IRS Publication 1075, and other applicable federal and state security requirements.
- Participate in audit preparation, evidence collection, audit response activities, remediation tracking, and corrective action planning.
- Identify cybersecurity risks and collaborate with business units, ITS teams, vendors, and project teams to develop mitigation strategies.
- Support Governance, Risk, and Compliance (GRC) activities, including policies, standards, procedures, and documentation.
- Participate in security monitoring, incident response coordination, vulnerability management, and security operations supporting enterprise systems.
- Review system architecture, cloud solutions, infrastructure changes, and third-party integrations for compliance with security requirements.
- Coordinate with the Agency CISO, Risk Manager, Privacy Officer, Infrastructure teams, project managers, business units, and vendors.
- Track security findings, vulnerabilities, POA&Ms, and remediation activities.
- Assist with implementation and maintenance of NIST-aligned security controls and client security standards.
- Support continuous monitoring, vulnerability remediation, and operational security improvements.
- Develop executive security reports, compliance documentation, risk summaries, and security metrics.
- Participate in SDLC activities to ensure security requirements are incorporated throughout project implementation.
- Provide security consultation for cloud services, enterprise applications, third-party integrations, and emerging technologies.
- Develop and maintain security documentation, procedures, standards, and compliance artifacts.
- Communicate technical security risks and recommendations to technical and non-technical stakeholders.
- Perform additional cybersecurity, governance, risk management, compliance, and security operations duties as assigned.
Requirements
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems, or related field preferred.
- Minimum 5 years of professional experience in cybersecurity, information security, governance, risk management, or compliance.
- Minimum 3 years conducting security risk assessments, vendor security reviews, or compliance evaluations.
- Experience supporting NIST, CMS, HIPAA, ARC-AMP-E/MARS-E, IRS Publication 1075, or comparable frameworks.
- Experience supporting Governance, Risk, and Compliance (GRC) programs.
- Experience with vulnerability management, audit readiness, evidence collection, remediation tracking, and continuous monitoring.
- Experience reviewing cloud technologies, enterprise architecture, and third-party integrations.
- Strong analytical, documentation, communication, and organizational skills.
Preferred Skills
- CISSP, CISM, CISA, Security+, CGRC, or equivalent certification.
- Experience with Azure, AWS, or Google Cloud security.
- Experience with SIEM technologies and security monitoring.
- Experience performing vendor security assessments and third-party risk management.
- Knowledge of Medicaid systems or state government security practices.
- Experience supporting Agile project environments.
- Excellent written and verbal communication skills.
- Strong leadership, analytical thinking, and problem-solving abilities.
Pay
$80,000 - $85,000 per year
Benefits
- Medical, dental, and vision insurance
- 401(k)
- Other standard benefits as applicable