Epicareer Might not Working Properly
Learn More

Security Analyst

Salary undisclosed

Checking job availability...

Original
Simplified
Job#: 2072095

Job Description:

Security Analyst

Location: Remote, but must be a resident of Wisconsin

*All qualified and interested candidates can please contact Schuyler Moose at

Position Details

The Division of Enterprise Technology (DET) manages the states information technology (IT) assets and uses technology to improve government efficiency and service delivery. DET administers enterprise solutions and consults on technology services for state agencies, local government and educational systems. Under the general direction of the Security Audit and Compliance Supervisor, this position provides assistance in the assessment of operations and adequacy of security controls and compliance with federal and state regulations (e.g. Criminal Justice Information Services (CJIS), Family Educational Rights and Privacy Act (FERPA), Federal Information Security Management Act (FISMA), Federal Tax Information (FTI), Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry (PCI), Social Security Administration (SSA), etc.) This position is responsible for:

determining whether electronic information systems operated and used by the DET are effectively managed and controlled

assisting in determining whether the application and general computer controls are adequate and functioning as intended, especially in the area of privacy and security

assisting in documenting improvements to existing or design-stage information systems to increase efficiency or adequacy of controls

maintaining policies and procedures related to the effective operation and control of the information systems

reviewing responses to external audit findings, and resolution of IT policy and procedural issues

performing self-assessments for compliance with regulatory and other industry standards for infrastructure services provided by DET

Responsibilities

Provide technical assistance on IT audit, security, and compliance requirements to internal and external customers

o Research, review and keep current on federal and state regulatory compliance requirements and security best practices.

o Maintain productive relations with supervisor and staff as a means of providing assistance with audit and compliance needs and areas of potential risk.

o Provide technical assistance, as requested, to Department managers in appropriate IT areas, such as development and implementation of internal control systems; development of policies and procedures; establishing benchmarks to measure the effectiveness of an IT application or function; and enhancing security features governing access to applications, LAN's and physical IT operations.

o Identify audit topics that should be considered for audit or limited review, based on indicators of any significant system changes, risks faced by the department and/or possible benefits of conducting such assessments.

o Assist Department and agency managers in developing responses to audits by external (state and federal) auditors, and in tracking responses to ensure that corrective actions are taken.

o Conduct follow-up reviews to determine whether recommendations have been implemented to adequately address the findings.

Serve as DET resource for documenting and assessing the adequacy of security controls for information systems

o Meet with internal customers to review and understand their requirements as they relate to enterprise security.

o Perform appropriate tests of general IT controls and specific application controls to verify that controls being audited are functioning as intended.

o Recommend to management changes necessary to improve the design and operating effectiveness IT security controls.

o Draft correspondence to management for audit results that clearly explain the findings and conditions disclosed during the audit, the basis for the audit conclusions and specific recommendations for corrective action.

o Develop an audit or limited review work plan detailing specific audit objectives, audit tasks to be performed, the criteria to be reviewed by management in assessing whether the IT system, function or activity being reviewed is performing effectively and timelines for completing planned tasks.

o Investigate security and compliance related issues for the enterprise and agencies as requested by management.

Participate in information technology security initiatives

o Participate in cross-functional teams in needs assessment, design, or implementation projects to address security audit and compliance needs.

o Review internal project study requests and project plans for compliance with IT security strategic goals.

o Evaluate customer requirements to determine if security solutions meet federal and state audit and compliance controls. Provide cost-benefit analyses as needed and solicit funding to develop and implement new projects and services.

o Provide information technology security expertise to system developers, system administrators, project managers and other IT professionals to ensure adequate security controls in IT systems.

Professional Development

o Maintain familiarity with activities and trends in the field of security and other related technologies.

o Attend appropriate training courses, conferences, and seminars.

o Read technical publications to maintain a high level of technical knowledge concerning security with particular emphasis on shared infrastructure technology.

o Participate in activities of professional and technical associations to contribute to the development in the data processing industry and in various agencies of government.

Knowledge, Skills, and Abilities

Ability to deliver quality service and maintain positive working relationships with customers.

Ability to function as a team member, including the open sharing of information, and willingness to help out wherever needed.

Ability to communicate clearly and effectively to both technical peers and less technical customers in person and via written media such as email, reports, and project charters.

Knowledge of and ability to apply IT service-delivery management best practices and procedures.

Ability to learn quickly; synthesize complex information, identify key points and communicate results accurately and effectively.

Knowledge and skill in standard audit procedures, including preparing an audit guide and identifying the steps taken in conducting the audit.

Knowledge of information technology controls.

Skill and experience in IT systems, software and web-based applications.

Knowledge of regulatory compliance requirements and assessment processes.

Knowledge of security concepts, risk management and investigation techniques.

Knowledge of practices of the Information Systems Audit and Control Association or any other applicable background for the audit of information systems.

Skill in writing technical, management and analysis reports and papers.

The position requires strong communications skills, both verbally and in writing, provides excellent customer service and assistance to internal and external stakeholders, and the ability to work with cross-functional teams.

EEO Employer

Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Employee Services Department at or .

Apex Systems is a world-class IT services company that serves thousands of clients across the globe. When you join Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRated's Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.

Apex Benefits Overview: Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Apex team member can provide.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job
Job#: 2072095

Job Description:

Security Analyst

Location: Remote, but must be a resident of Wisconsin

*All qualified and interested candidates can please contact Schuyler Moose at

Position Details

The Division of Enterprise Technology (DET) manages the states information technology (IT) assets and uses technology to improve government efficiency and service delivery. DET administers enterprise solutions and consults on technology services for state agencies, local government and educational systems. Under the general direction of the Security Audit and Compliance Supervisor, this position provides assistance in the assessment of operations and adequacy of security controls and compliance with federal and state regulations (e.g. Criminal Justice Information Services (CJIS), Family Educational Rights and Privacy Act (FERPA), Federal Information Security Management Act (FISMA), Federal Tax Information (FTI), Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry (PCI), Social Security Administration (SSA), etc.) This position is responsible for:

determining whether electronic information systems operated and used by the DET are effectively managed and controlled

assisting in determining whether the application and general computer controls are adequate and functioning as intended, especially in the area of privacy and security

assisting in documenting improvements to existing or design-stage information systems to increase efficiency or adequacy of controls

maintaining policies and procedures related to the effective operation and control of the information systems

reviewing responses to external audit findings, and resolution of IT policy and procedural issues

performing self-assessments for compliance with regulatory and other industry standards for infrastructure services provided by DET

Responsibilities

Provide technical assistance on IT audit, security, and compliance requirements to internal and external customers

o Research, review and keep current on federal and state regulatory compliance requirements and security best practices.

o Maintain productive relations with supervisor and staff as a means of providing assistance with audit and compliance needs and areas of potential risk.

o Provide technical assistance, as requested, to Department managers in appropriate IT areas, such as development and implementation of internal control systems; development of policies and procedures; establishing benchmarks to measure the effectiveness of an IT application or function; and enhancing security features governing access to applications, LAN's and physical IT operations.

o Identify audit topics that should be considered for audit or limited review, based on indicators of any significant system changes, risks faced by the department and/or possible benefits of conducting such assessments.

o Assist Department and agency managers in developing responses to audits by external (state and federal) auditors, and in tracking responses to ensure that corrective actions are taken.

o Conduct follow-up reviews to determine whether recommendations have been implemented to adequately address the findings.

Serve as DET resource for documenting and assessing the adequacy of security controls for information systems

o Meet with internal customers to review and understand their requirements as they relate to enterprise security.

o Perform appropriate tests of general IT controls and specific application controls to verify that controls being audited are functioning as intended.

o Recommend to management changes necessary to improve the design and operating effectiveness IT security controls.

o Draft correspondence to management for audit results that clearly explain the findings and conditions disclosed during the audit, the basis for the audit conclusions and specific recommendations for corrective action.

o Develop an audit or limited review work plan detailing specific audit objectives, audit tasks to be performed, the criteria to be reviewed by management in assessing whether the IT system, function or activity being reviewed is performing effectively and timelines for completing planned tasks.

o Investigate security and compliance related issues for the enterprise and agencies as requested by management.

Participate in information technology security initiatives

o Participate in cross-functional teams in needs assessment, design, or implementation projects to address security audit and compliance needs.

o Review internal project study requests and project plans for compliance with IT security strategic goals.

o Evaluate customer requirements to determine if security solutions meet federal and state audit and compliance controls. Provide cost-benefit analyses as needed and solicit funding to develop and implement new projects and services.

o Provide information technology security expertise to system developers, system administrators, project managers and other IT professionals to ensure adequate security controls in IT systems.

Professional Development

o Maintain familiarity with activities and trends in the field of security and other related technologies.

o Attend appropriate training courses, conferences, and seminars.

o Read technical publications to maintain a high level of technical knowledge concerning security with particular emphasis on shared infrastructure technology.

o Participate in activities of professional and technical associations to contribute to the development in the data processing industry and in various agencies of government.

Knowledge, Skills, and Abilities

Ability to deliver quality service and maintain positive working relationships with customers.

Ability to function as a team member, including the open sharing of information, and willingness to help out wherever needed.

Ability to communicate clearly and effectively to both technical peers and less technical customers in person and via written media such as email, reports, and project charters.

Knowledge of and ability to apply IT service-delivery management best practices and procedures.

Ability to learn quickly; synthesize complex information, identify key points and communicate results accurately and effectively.

Knowledge and skill in standard audit procedures, including preparing an audit guide and identifying the steps taken in conducting the audit.

Knowledge of information technology controls.

Skill and experience in IT systems, software and web-based applications.

Knowledge of regulatory compliance requirements and assessment processes.

Knowledge of security concepts, risk management and investigation techniques.

Knowledge of practices of the Information Systems Audit and Control Association or any other applicable background for the audit of information systems.

Skill in writing technical, management and analysis reports and papers.

The position requires strong communications skills, both verbally and in writing, provides excellent customer service and assistance to internal and external stakeholders, and the ability to work with cross-functional teams.

EEO Employer

Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Employee Services Department at or .

Apex Systems is a world-class IT services company that serves thousands of clients across the globe. When you join Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRated's Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.

Apex Benefits Overview: Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Apex team member can provide.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job