The Senior Security & Compliance Analyst will provide, but not be limited to, the following activities and tasks.
- Minimum Qualifications. The candidate must possess the minimum qualifications and experience of the STC Job Family cited in Section 2 (Security Management, Job #6810, Security Analyst (C. Advanced)), together with the following Department minimum qualifications and experience:
- Per the STC Job Family description: a minimum of four (4) years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, and database design and administration, including one to two (1-2) years of experience with information security, and knowledge of security issues, techniques, and implications across all existing computer platforms.
- Minimum of seven (7) years across information security disciplines, with demonstrated experience in both security governance/compliance (GRC) and hands-on security operations.
- Demonstrated experience drafting information security policy and standards and implementing NIST SP 800-53 and/or NIST CSF controls.
- Demonstrated experience performing security risk assessments and supporting internal or external audits.
- On-site availability at the Department's location, 4040 Esplanade Way, Tallahassee, Florida. Remote work may be considered on an occasional, ad-hoc basis with prior written approval of the Contract Manager; this is not a hybrid or permanent remote arrangement. Travel costs will not be reimbursed.
- Education and Certification. The candidate must possess, at a minimum, a Bachelor's degree in computer science, information systems, cybersecurity, or a related field, or equivalent work experience; and at least one current industry certification from the following (others may be considered):
- CISA - Certified Information Systems Auditor (strongly aligned to the GRC/audit core).
- CRISC - Certified in Risk and Information Systems Control.
- CGRC - Certified in Governance, Risk and Compliance (formerly CAP).
- CISM - Certified Information Security Manager.
- CISSP - Certified Information Systems Security Professional.
- Preferred Qualifications. The following are preferred and will strengthen a candidate's evaluation:
- Florida state government or public-sector information security experience.
- Working knowledge of Rule 60GG-2, F.A.C., and Section 282.318, Florida Statutes.
- CJIS Security Policy implementation or audit experience.
- HIPAA Security Rule and PHI-handling experience.
- Hands-on Microsoft 365 G5, Microsoft Defender (Endpoint, Vulnerability Management), and Microsoft Purview experience.
- Vulnerability management tooling and remediation-coordination experience.
- Experience developing IAM / access-control standards and provisioning-integrity controls.
- PowerShell or comparable scripting for security automation and reporting.