Security Analyst
Santcore Technologies · Madison, WI · Yesterday
HybridContract
Position Summary
The Security Analyst position serves the Division of Medicaid Services (DMS) and acts as a champion for integrating information security into program operations. This role involves collaborating with security teams, communicating risk, and developing mitigation strategies while maintaining strong relationships with business stakeholders.
Responsibilities
- Integrate Security into Program Operations
- Partner with organizational leaders to incorporate information security best practices into technical and operational initiatives
- Recommend improvements to strengthen security posture and reduce risk
- Communicate risks in clear, business-friendly language
- Provide mitigation options while considering business impact
- Draft security requirements for: Project charters, Scope documents, Procurement activities
- Document analysis and communicate recommendations
- Escalate risks to ISS leadership when acceptable risk levels cannot be achieved
- Serve as a Liaison Between Program Areas and ISS
- Act as a solutions-focused advocate
- Intake projects and business initiatives and guide them through appropriate ISS workstreams
- Gather information necessary for thorough security analysis
- Communicate security deliverables to stakeholders
- Ensure deliverables meet customer requirements
- Collaborate across ISS teams to meet security requirements
- Work with: BITS staff, Office of Legal Counsel, Bureau of Procurement and Contracting, Program stakeholders
- Support Audit, Assessment, Incident Response, and Regulatory Activities
- Request and gather compliance-related artifacts
- Facilitate communication among: Auditors, Incident response teams, Vendors, Technical teams, Business stakeholders
- Assess audit results in partnership with ISS
- Develop: Corrective Action Plans (CAPs), Plans of Action and Milestones (POA&Ms)
- Provide oversight through remediation and validation
- Verify compliance before closure
- Respond to regulatory inquiries
- Draft supporting documentation
- Support Program Integration Activities
- Provide backup support to other security personnel
- Develop: Concept papers, Proposals, Briefing materials, Security documentation, Reports and recommendations
Qualifications
- A federally recognized ANSI-accredited Information Security Certification must be obtained within six (6) months of the start date and maintained throughout employment.
- The Department of Defence (DoD) 8570 Baseline Certifications, as defined by the Defense Information Systems Agency (DISA), should be used as a reference for acceptable certifications.
Skills and Abilities
- Security Knowledge: Broad information security knowledge, experience in one or more of the following: Application development, Technical architecture, Contracting, Audit and compliance, Vendor management
- Compliance & Framework Expertise: Familiarity with NIST or other recognized security frameworks, Understanding of security governance and regulatory requirements
- Communication Skills: Strong verbal communication skills, Strong written communication skills, Ability to explain complex security concepts to technical and non-technical audiences
- Problem Solving: Ability to solve complex business and security challenges, Ability to manage multiple priorities and interruptions effectively
- Organizational Skills: Strong attention to detail, Excellent documentation capabilities, Effective project and task management skills
- Customer Focus: Ability to balance Confidentiality, Integrity, Availability, Strong customer service orientation
- Teamwork: Ability to work independently, Ability to collaborate with peers, Ability to contribute effectively within multidisciplinary teams