1

Security Analyst Iii Jobs (NOW HIRING)

... and communicate analysis. Answer clarifying questions. · Escalate to ISS leadership if an ... DHS is seeking a Level III security professional with vulnerability management knowledge, strong ...

... and communicate analysis. Answer clarifying questions. · Escalate to ISS leadership if an ... DHS is seeking a Level III security professional with vulnerability management knowledge, strong ...

Security Analyst 3 Client: VDOT Location: 1221 E Broad St. Richmond VA, 23219 Duration: 07+ Months * VDOT is seeking a highly motivated Security Analyst to support cybersecurity operations within the ...

Showing results 21-40

Security Analyst Iii information

See salary details

$39.5K

$107.3K

$141K

How much do security analyst iii jobs pay per year?

As of Sep 2, 2026, the average yearly pay for security analyst iii in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is a Security Analyst III?

Security Analyst III positions are advanced roles within an organization's cybersecurity team, responsible for identifying, analyzing, and mitigating security threats to computer systems and networks. These professionals typically perform complex security assessments, lead incident response efforts, and develop strategies to strengthen the organization's overall security posture. Security Analyst IIIs often mentor junior analysts, manage security tools, and ensure compliance with relevant regulations and standards. They play a key role in protecting sensitive information from cyberattacks and data breaches.

What are the key skills and qualifications needed to thrive as a Security Analyst III?

To thrive as a Security Analyst III, you need advanced knowledge of information security principles, risk assessment, and incident response, typically supported by a bachelor’s degree in cybersecurity or a related field and several years of experience. Familiarity with SIEM tools, intrusion detection systems, vulnerability scanners, and certifications like CISSP or CISM are commonly required. Strong analytical thinking, attention to detail, and effective communication skills help you identify threats and collaborate with stakeholders. These skills ensure robust protection of organizational assets, timely mitigation of security incidents, and compliance with regulatory requirements.

What are some common challenges faced by a Security Analyst III and how can they be addressed?

As a Security Analyst III, you will often encounter complex security threats that require quick identification and response. One of the main challenges is staying ahead of rapidly evolving cyber threats while managing multiple security tools and responding to incidents in real time. Collaboration with IT, development, and compliance teams is crucial, as is continuous learning to keep up with new technologies and threat vectors. Developing strong incident response procedures and participating in regular training can help address these challenges and ensure effective protection of organizational assets.

What is the difference between Security Analyst Iii vs Security Analyst Ii?

CriteriaSecurity Analyst IiiSecurity Analyst Ii
CertificationsCompTIA Security+, CISSP (preferred)CompTIA Security+, CEH (preferred)
Work EnvironmentMid-level cybersecurity team, security operations centersEntry to mid-level security teams, monitoring and incident response
ResponsibilitiesAdvanced threat detection, incident analysis, security tool managementMonitoring security alerts, basic incident response, vulnerability assessments

The main difference between Security Analyst Iii and Security Analyst Ii lies in experience and responsibilities. Security Analyst Iii typically handles more complex security issues, performs advanced threat analysis, and manages security tools, whereas Security Analyst Ii focuses on monitoring, basic incident response, and supporting security operations. Certifications like Security+ and CISSP are common for both, but Security Analyst Iii often requires more experience and specialized skills.

More about Security Analyst Iii jobs
Infographic showing various Security Analyst Iii job openings in the United States as of August 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $107,334 per year, or $51.6 per hour.

Security Analyst III

Technoviz LLC

Madison, WI • On-site

$45/hr

Full-time

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

Benefits:
  • Competitive salary
  • Opportunity for advancement
  • Training & development

Position Summary: The Department of Health Services (DHS) is one of the largest and most diverse state agencies in Wisconsin. DHS employs more than 7,000 staff spanning ten divisions and offices and seven 24/7 institutions located throughout Wisconsin. Programs and services administered by DHS include Medicaid and other human service programs, alcohol and other drug abuse prevention services, mental health, public health, and long-term care. 
 
The Information Security Section (ISS) serves the Department by creating an information security culture and enabling the business. We are metrics minded, employee focused, and view security as a service.  ISS is responsible for  
•          Identifying and continuously assessing risk 
•          Developing, institutionalizing, and improving strategies to mitigate risk
•          Limiting the potential effects of information security events
•          The selection, assessment, authorization, and monitoring of security controls while contributing to the overall information security plan.
The Information Security Section (ISS) is functionally organized into Security Awareness and Governance, Compliance, Architecture, and Portfolio Management. Cross-team collaboration is essential to our success.  
 
The DHS Liaison serves the Division of Medicaid Services and is the champion for security initiatives integrating information security into program operations. This work is completed by engaging other security staff, communicating risk, and developing strategies to reduce risk. To successfully do this work, one must possess strong communication and interpersonal skills capable of presenting to diverse audiences including executive and non-technical individuals.
 
A federally recognized (ANSI) information security certification must be obtained within 6 months of the start date and maintained for this position. The Department of Defense (DOD) 8570 Baseline Certifications defined by Defense Information Systems Agency (DISA) is the baseline to consider when reviewing the relevance of the certification.
 
Goals and Worker Activities
1. Integrate security into program operations 
·         Partner with organizational leaders to incorporate information security best-practices into technical and operational development.   
·         Provide recommendations on how to improve the information security posture of programs and reduce risk.
·         Communicate risks in simple and comprehensible terms. Provide options to mitigate risk considering business impact. 
·         Draft security requirements to be included into charters, scope documents, procurements.
·         Document and communicate analysis. Answer clarifying questions.   
·         Escalate to ISS leadership if an acceptable level of risk cannot be achieved
2. Act as a liaison between the program area and the Information Security Section
·         Be a solutions-focused advocate. 
·         Intake projects and other program initiatives and champion them through the appropriate ISS workstream 
·         Gather information as needed so that security team can perform thorough analysis
·         Communicate workstream deliverables to the customer. Verify that the deliverable meets the customer need, follow-up on any clarifications.   
·         Coordinate across ISS meeting their security-focused needs
·         Coordinate with other BITS staff, Office of Legal Counsel, Bureau of Procurement and Contracting, and other program staff as needed in order to arrive to an outcome
3. Support audit, assessment, incident response, and other regulatory activities
·         Responsibility and authority will vary based on the use case and customer need. 
·         Request and/or gather artifacts demonstrating compliance.
·         Schedule/facilitate communications between auditor/incident response, vendors, technical teams, and other program stakeholders.
·         In partnership with ISS, assess audit results and develop corrective action plans/plans of action and milestone. 
·         Provide oversight to the resolution, test for compliance, and request authority to close. 
·         Respond to regulatory inquiry and draft documents as needed 
4. Participate and support Program Integration related activities
·         Back-up other security liaison roles
·         Draft and deliver status reports 
·         Establish and maintain positive working relationships with stakeholders
·         Establish and documents standard operations for job-related activities.
5. Support Vulnerability Management related to DMS and its vendors
·         Foster transparency, accountability, and timely resolution of vulnerabilities with DMS and its vendors
·         Support DMS and its vendors in adhering to state and federal regulations and Policies, Procedures, Standards and Guidelines (PPSGs) related to vulnerability management
·         Draft and monitor plans of action and milestones for non-compliance
6. Support DHS’s transition from the Center for Medicare and Medicaid Services (CMS) compliance requirements known as the Minimum Acceptable Risk Standards for Exchanges (MARS-E) to the new requirements known as Acceptable Risk Controls for ACA, Medicaid, and Partner Entities (ARC-AMPE) 
·         In partnership with Deloitte, DET, and ISS conduct GAP analysis to support transition, implementation, and maturation of DHS’s transition from MARS-E to ARC-AMPE
·         Draft the ARC-AMPE System Security and Privacy Plan (SSPP) and keep it current
·         Draft and monitor plans of action and milestones for non-compliance
7. Support DHS in completing software reviews, cloud brokerage reviews, and AI Use Case reviews 
8. Other duties as assigned
·         Back-up other security staff 
·         Write concept papers, proposals and briefs, and other documentation
 
Knowledge, Skills, and Abilities:
·         Well qualified candidate will have broad knowledge of information security and experience application development, technical architecture, contracting, audit, or vendor management.
·         Be familiar with NIST or another recognized framework
·         Demonstrated ability to solve complex problems, convey both oral and written instruction, and handle multiple task interruptions while providing services in a professional and courteous manner.
·         Demonstrated attention to detail and organizational skills. 
·         Demonstrated ability to work effectively with customers to solve business challenges while balancing the need for confidentiality, integrity, and availability.
·         Demonstrated commitment to fostering a diverse working environment.
Demonstrated ability to work independently, as part of a team of peers, and also to support and contribute to a multidiscipline team environment.
Project Details: DHS is seeking a Level III security professional with vulnerability management knowledge, strong documentation and compliance experience, and excellent stakeholder communication skills. Success in this position depends on the ability to work cross-functionally, manage competing priorities, contribute to federal security compliance efforts, and serve as a trusted partner to both security teams and business stakeholders.
This role requires understanding security concepts, technical requirements, and operational processes, and communicating them effectively to non-security audiences. The position contributes to key security and privacy deliverables, including system security and privacy plans, and plays a significant role in developing and maintaining these documents. It also supports vulnerability management efforts across the CARES environment, with a strong focus on tracking, monitoring, and ensuring remediation activities are completed.
Interview Process:
Two Round Virtual Interview Process. Video conference interview or an onsite interview may be required. AI Assistance is PROHIBITED during the interviews. A real time photo is required to be uploaded for interviews.
Remote or On-site?
Must be a WI resident. NO relocation is allowed. Can work remote up to five days, however, the candidate must come in if needed including on short notice. At a minimum, the candidate will come in quarterly but could be more frequently as determined by business needs. Remote work will be discussed with candidates in the interview phase.