Senior Security Compliance Analyst
Randstad Digital Americas · Tallahassee, FL · Yesterday
Legal$65–$85/hrContract
Scope of Work
The candidate will work closely with the Office of Information Technology, the Office of General Counsel, and Department program areas, and may serve as a liaison with the Florida Digital Service and with solution providers/suppliers on security matters. All work products are subject to ISM review and approval as described in Section 4.6.
Required Abilities
- Broad mastery of information security across governance and operations - able to both author policy and standards and perform the hands-on technical work to implement and validate controls.
- Fluency in security control frameworks (NIST SP 800-53, NIST CSF) and the ability to map and crosswalk controls to the Florida Cybersecurity Standards (Rule 60GG-2, F.A.C.).
- Risk-based judgment - able to assess control gaps, prioritize remediation, and document risk decisions for management review.
- Clear technical writing - able to produce audit-ready policy, procedure, assessment, and management-response documentation.
- Operational competence in a Microsoft 365 / Microsoft Defender environment, including endpoint security, vulnerability management, identity and access controls, and incident response support.
- Ability to explain security risks, trade-offs, and remediation options to non-security stakeholders, including executives and counsel.
Responsibilities
Governance, Policy & Standards. The Candidate Will:
- Draft, revise, and maintain Department information security policies and standards (including the 420-series), and establish and operate periodic review cycles.
- Develop procedures supporting Department security policies consistent with Rule 60GG-2.002 and 60GG-2.003, F.A.C.
- Develop and maintain control mappings and crosswalks among NIST SP 800-53, NIST CSF, and Rule 60GG-2, F.A.C.
- Maintain documentation, version control, and review evidence sufficient to satisfy internal and external audit.
Risk Management & Assessment. The Candidate Will:
- Conduct security risk assessments and control gap analyses against applicable frameworks.
- Develop, track, and maintain Plans of Action and Milestones (POA&Ms) and corrective action plans.
- Perform third-party / vendor security risk reviews, including review of vendor security documentation, contract security terms, and integration security (identity federation, per-transaction attribution, and audit logging).
Security Operations & Engineering Support. The Candidate Will:
- Support configuration, hardening, and monitoring within Microsoft 365 and Microsoft Defender (Defender for Endpoint, Defender Vulnerability Management, Microsoft Purview) consistent with Department standards.
- Support vulnerability management: triage, tracking, and coordination of remediation.
- Support incident response consistent with the Department's Cybersecurity Incident Response Policy (420.01), including documentation and post-incident analysis.
- Support identity and access management activities, including access reviews and provisioning-integrity controls.
Audit, Compliance & Reporting. The Candidate Will:
- Support response to Office of Inspector General (IG) and external audit findings, including evidence collection, control testing, and development of management responses.
- Support compliance with the CJIS Security Policy and protection of PHI and other confidential information.
- Develop security metrics, status reporting, and security awareness materials; support security governance meetings and working groups.
Contract Deliverables
The candidate shall provide evidence of performance through documentation including, but not limited to:
- Drafted and revised security policies and standards, with documented periodic-review cycles.
- Control mapping crosswalks (NIST SP 800-53 / NIST CSF / Rule 60GG-2, F.A.C.).
- Security risk assessment reports and control gap analyses.
- Plans of Action and Milestones (POA&Ms) and corrective action plans.
- Third-party / vendor security review memoranda and diagnostic question sets.
- Vulnerability management tracking and remediation status reports.
- Incident documentation and post-incident (Root Cause Analysis) reports.
- Audit evidence packages and draft management responses to IG / external findings.
- Security metrics and periodic status reports.
Minimum Qualifications
- Bachelor's degree in computer science, information systems, cybersecurity, or a related field, or equivalent work experience.
- At least one current industry certification from the following (others may be considered): CISA, CRISC, CGRC, CISM, or CISSP.
- Minimum of four (4) years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, and database design and administration, including one to two (1-2) years of experience with information security, and knowledge of security issues, techniques, and implications across all existing computer platforms.
- Minimum of seven (7) years across information security disciplines, with demonstrated experience in both security governance/compliance (GRC) and hands-on security operations.
- Demonstrated experience drafting information security policy and standards and implementing NIST SP 800-53 and/or NIST CSF controls.
- Demonstrated experience performing security risk assessments and supporting internal or external audits.
Preferred Qualifications
- Florida state government or public-sector information security experience.
- Working knowledge of Rule 60GG-2, F.A.C., and Section 282.318, Florida Statutes.
- CJIS Security Policy implementation or audit experience.
- HIPAA Security Rule and PHI-handling experience.
- Hands-on Microsoft 365 G5, Microsoft Defender (Endpoint, Vulnerability Management), and Microsoft Purview experience.
- Vulnerability management tooling and remediation-coordination experience.
- Experience developing IAM / access-control standards and provisioning-integrity controls.
- PowerShell or comparable scripting for security automation and reporting.
Pay & Schedule
- Location: Tallahassee, Florida
- Job type: Contract
- Salary: $65 - 85 per hour
- Work hours: 8am to 5pm