GRC Security Analyst (Hybrid) at Remote, Remote, USA |
Email: [email protected] |
From: Sameer, GSK SOLUTONS INC [email protected] Reply to: [email protected] Job Title: GRC Security Analyst (Hybrid) Location: Dimondale, MI Duration: 12 Months+ Client: State of Michigan Job Description: This position will be dedicated to the Governance, Risk, and Compliance strategy including formal application/system reviews and documentation of the system security control tasks completed during the system security plan phase using NIST 800-53 Rev 5 framework. Candidate must be able to clearly discuss, explain, and document how the various systems meet or do not meet the assigned controls; how the control is being remediated if applicable; document and present exception requests as needed ; review security assessment reports; assist with completing Plan Of Actions and Milestones. Candidate must be able to independently lead working sessions with assigned team of both technical and non-technical individuals. Clear communication and presentation skills are required. Must be able to clearly explain technical information to both technical and non-technical individuals. Responsible for continual improvements of system security plan process. Provide technical guidance and support as needed. Act as liaison to DTMB and Treasury with the system security assessment process. Will be responsible for data Input and data oversight into GRC tool for assigned application system security plans. Work with management on strategies for annual system security and risk plan development. Follow the IT security technical architecture design methodology and best practices. Provides technical system security expertise as it relates to the integration of systems, security, middleware, services, database design, hardware/server, and tools, to IT project business and technical requirement sessions and for system implementation. Lead and coordinate with other technical resources in the overall system design, implementation and integration of systems with other existing systems/technologies/data sources on multiple platforms within the agency, across multiple state agencies, Enterprise Architecture and multiple software vendors as required. Expertise for adherence to Payment Card Industry (PCI) Data Security Standards (DSS), IRS Publication 1075 regulations, and IRS Safeguards Computer Security Evaluation Matrices (SCSEMs). Technical Documentation / Responses to address system security program requirements. Providing input for Disaster Recovery testing and processes. Keywords: information technology Michigan |
[email protected] View all |
Sat Sep 30 03:00:00 UTC 2023 |