Jobs · Legal · Florida

Senior Security Compliance Analyst

Randstad Digital Americas · Tallahassee, FL · Yesterday
Legal$65–$85/hrContract

Scope of Work

The candidate will work closely with the Office of Information Technology, the Office of General Counsel, and Department program areas, and may serve as a liaison with the Florida Digital Service and with solution providers/suppliers on security matters. All work products are subject to ISM review and approval as described in Section 4.6.

Required Abilities

  • Broad mastery of information security across governance and operations - able to both author policy and standards and perform the hands-on technical work to implement and validate controls.
  • Fluency in security control frameworks (NIST SP 800-53, NIST CSF) and the ability to map and crosswalk controls to the Florida Cybersecurity Standards (Rule 60GG-2, F.A.C.).
  • Risk-based judgment - able to assess control gaps, prioritize remediation, and document risk decisions for management review.
  • Clear technical writing - able to produce audit-ready policy, procedure, assessment, and management-response documentation.
  • Operational competence in a Microsoft 365 / Microsoft Defender environment, including endpoint security, vulnerability management, identity and access controls, and incident response support.
  • Ability to explain security risks, trade-offs, and remediation options to non-security stakeholders, including executives and counsel.

Responsibilities

Governance, Policy & Standards. The Candidate Will:

  • Draft, revise, and maintain Department information security policies and standards (including the 420-series), and establish and operate periodic review cycles.
  • Develop procedures supporting Department security policies consistent with Rule 60GG-2.002 and 60GG-2.003, F.A.C.
  • Develop and maintain control mappings and crosswalks among NIST SP 800-53, NIST CSF, and Rule 60GG-2, F.A.C.
  • Maintain documentation, version control, and review evidence sufficient to satisfy internal and external audit.

Risk Management & Assessment. The Candidate Will:

  • Conduct security risk assessments and control gap analyses against applicable frameworks.
  • Develop, track, and maintain Plans of Action and Milestones (POA&Ms) and corrective action plans.
  • Perform third-party / vendor security risk reviews, including review of vendor security documentation, contract security terms, and integration security (identity federation, per-transaction attribution, and audit logging).

Security Operations & Engineering Support. The Candidate Will:

  • Support configuration, hardening, and monitoring within Microsoft 365 and Microsoft Defender (Defender for Endpoint, Defender Vulnerability Management, Microsoft Purview) consistent with Department standards.
  • Support vulnerability management: triage, tracking, and coordination of remediation.
  • Support incident response consistent with the Department's Cybersecurity Incident Response Policy (420.01), including documentation and post-incident analysis.
  • Support identity and access management activities, including access reviews and provisioning-integrity controls.

Audit, Compliance & Reporting. The Candidate Will:

  • Support response to Office of Inspector General (IG) and external audit findings, including evidence collection, control testing, and development of management responses.
  • Support compliance with the CJIS Security Policy and protection of PHI and other confidential information.
  • Develop security metrics, status reporting, and security awareness materials; support security governance meetings and working groups.

Contract Deliverables

The candidate shall provide evidence of performance through documentation including, but not limited to:

  • Drafted and revised security policies and standards, with documented periodic-review cycles.
  • Control mapping crosswalks (NIST SP 800-53 / NIST CSF / Rule 60GG-2, F.A.C.).
  • Security risk assessment reports and control gap analyses.
  • Plans of Action and Milestones (POA&Ms) and corrective action plans.
  • Third-party / vendor security review memoranda and diagnostic question sets.
  • Vulnerability management tracking and remediation status reports.
  • Incident documentation and post-incident (Root Cause Analysis) reports.
  • Audit evidence packages and draft management responses to IG / external findings.
  • Security metrics and periodic status reports.

Minimum Qualifications

  • Bachelor's degree in computer science, information systems, cybersecurity, or a related field, or equivalent work experience.
  • At least one current industry certification from the following (others may be considered): CISA, CRISC, CGRC, CISM, or CISSP.
  • Minimum of four (4) years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, and database design and administration, including one to two (1-2) years of experience with information security, and knowledge of security issues, techniques, and implications across all existing computer platforms.
  • Minimum of seven (7) years across information security disciplines, with demonstrated experience in both security governance/compliance (GRC) and hands-on security operations.
  • Demonstrated experience drafting information security policy and standards and implementing NIST SP 800-53 and/or NIST CSF controls.
  • Demonstrated experience performing security risk assessments and supporting internal or external audits.

Preferred Qualifications

  • Florida state government or public-sector information security experience.
  • Working knowledge of Rule 60GG-2, F.A.C., and Section 282.318, Florida Statutes.
  • CJIS Security Policy implementation or audit experience.
  • HIPAA Security Rule and PHI-handling experience.
  • Hands-on Microsoft 365 G5, Microsoft Defender (Endpoint, Vulnerability Management), and Microsoft Purview experience.
  • Vulnerability management tooling and remediation-coordination experience.
  • Experience developing IAM / access-control standards and provisioning-integrity controls.
  • PowerShell or comparable scripting for security automation and reporting.

Pay & Schedule

  • Location: Tallahassee, Florida
  • Job type: Contract
  • Salary: $65 - 85 per hour
  • Work hours: 8am to 5pm

Similar jobs

Senior Security Analyst

23andMePalo Alto, CA· Yesterday
Information Technology$110k–$140k/yrapply on 23andme.wd5.myworkdayjobs.com