Security Analyst III
TECHNOVIZ LLC · Madison, WI · Yesterday
On-siteInformation TechnologyFull-time
Position Summary
The Department of Health Services (DHS) is one of the largest and most diverse state agencies in Wisconsin. DHS employs more than 7,000 staff spanning ten divisions and offices and seven 24/7 institutions located throughout Wisconsin. Programs and services administered by DHS include Medicaid and other human service programs, alcohol and other drug abuse prevention services, mental health, public health, and long-term care. The Information Security Section (ISS) serves the Department by creating an information security culture and enabling the business. We are metrics minded, employee focused, and view security as a service.
Responsibilities
- Integrate security into program operations
- Partner with organizational leaders to incorporate information security best-practices into technical and operational development
- Provide recommendations on how to improve the information security posture of programs and reduce risk
- Communicate risks in simple and comprehensible terms
- Provide options to mitigate risk considering business impact
- Draft security requirements to be included into charters, scope documents, procurements
- Document and communicate analysis
- Answer clarifying questions
- Escalate to ISS leadership if an acceptable level of risk cannot be achieved
- Act as a liaison between the program area and the Information Security Section
- Be a solutions-focused advocate
- Intake projects and other program initiatives and champion them through the appropriate ISS workstream
- Gather information as needed so that security team can perform thorough analysis
- Communicate workstream deliverables to the customer
- Verify that the deliverable meets the customer need, follow-up on any clarifications
- Clock with other BITS staff, Office of Legal Counsel, Bureau of Procurement and Contracting, and other program staff as needed in order to arrive to an outcome
- Support audit, assessment, incident response, and other regulatory activities
Qualifications
- Well qualified candidate will have broad knowledge of information security and experience application development, technical architecture, contracting, audit, or vendor management
- Be familiar with NIST or another recognized framework
- Demonstrated ability to solve complex problems, convey both oral and written instruction, and handle multiple task interruptions while providing services in a professional and courteous manner
- Demonstrated attention to detail and organizational skills
- Demonstrated ability to work effectively with customers to solve business challenges while balancing the need for confidentiality, integrity, and availability
- Demonstrated commitment to fostering a diverse working environment
- Demonstrated ability to work independently, as part of a team of peers, and also to support and contribute to a multidiscipline team environment
- Knowledge of vulnerability management knowledge, strong documentation and compliance experience, and excellent stakeholder communication skills