Search jobs > Raleigh, NC > It security specialist

IT Security Specialist

Crescens
Raleigh, NC, United States
Full-time

Job Title : IT Security Specialist

Location : Raleigh, NC

Duration : 12+ Months

Remote work is available with the manager's approval

Job Description :

The client requiring services of an IT Security Compliance Specialist to assist and assess the client Application and Infrastructure Modernization(AIM) CMS, USDA and ACF requirements for the project.

In addition this resource must also review the RFP, MOU and MOA for privacy, security, Business Continuity Planning, Disaster Recovery and audit requirements.

This resource must identify the risks and assist in the development of mitigation strategies, and to establish the target security / infrastructure architecture.

Duties include, are not limited to :

  • The ideal candidate for this role plans, implements, upgrades, or monitors security measures for the protection of computer networks and information.
  • This candidate will be expected to continuously assess the development process and suggest improvements.
  • Supports the ISSO with the management of system security plans, ensure the systems obtain and maintain an authorization to operate (ATO), and meets all requirements for certification and provide support to achieve all activities associated with the Assessment and Authorization (A&A) process.
  • Provides support and security compliance to meet the security standards for Applications and systems in Cloud environments (AWS or Azure or Google etc.).
  • Provides Security compliance oversight of information systems security program for applications and systems within the ATO boundary leveraging MARS-E, NIST, and HIPPA Guidelines.
  • Coordinates with the O&M and Infrastructure team to ensure COTS and other support software is current and compliant with current InfoSec policies;

The program participates in the IT Continuous Monitoring Program.

  • Provides support to Software Developers, Engineers and other team members on the optimal methods to meet security requirements while minimizing impact and delays in meeting mission requirements.
  • Work closely with the Enterprise Architecture (EA), Database Administrator (DBA), Migration and Application Development teams to develop and implement automated Disaster Recovery capabilities including automated alerting, notifications, containment, data backup & recovery.
  • Partner with EA, and Application Development teams to develop Security Event Logging and Monitoring processes.
  • Perform internal assessments of security controls to ensure compliance with legislation, regulation, and technical standards with technical teams.
  • Monitor infrastructure assets and services, evaluate application / system components through system compliance examinations and testing utilizing NIST 800-53.
  • Tracks and monitors remediation efforts stemming from IT assessment and financial audits through Plans of Actions and Milestones (POA&Ms) and Correction Action Plans (CAPs) and informing Senior Leadership of security measures in place.
  • Ensure appropriate security controls are in place that will safeguard digital files and vital electronic infrastructure.
  • It is imperative that the candidate possess and apply a comprehensive system security knowledge across key tasks and high impact assignments.
  • 5+ years of related work experience
  • 5 years' experience providing security compliance requirements for Applications in Cloud environments (AWS or Azure or Google etc.)
  • 5 years' experience updating or maintaining SSP / SSPP documents.
  • 5 years' experience participating in Assessment & Authorization (A&A / ATO)
  • 5 years' experience supporting infrastructure assets and services by proactive monitoring, evaluating application / system components through system compliance examinations and testing utilizing NIST 800-53
  • 5 years' experience providing security engineering review and recommendations.
  • 5 years' experience working with large teams in an Agile environment.
  • 5 years ISSO experience
  • Experience coordinating and working under an ATO.
  • Experience assessing system modifications such as major and minor releases and potential security impacts.
  • Experience providing recommendations for improvement to amend vulnerabilities.
  • Experience assisting Program Managers and Senior Leadership developing Correction Action Plans (CAPs) when responding to IT and Financial audits.

The ideal candidate will have experience working with current and emerging information security technologies, privacy and development methodologies.

Bachelor's degree in computer science, management information systems, or related field preferred. Candidate must have security architecture knowledge like TOGAF and MITA.

Good analytical and creative problem solving skills, and relies on experience and judgment to plan and accomplish goals, independently performs a variety of complicated tasks, with a wide degree of creativity and latitude is expected.

Skill :

  • Risk Management - must be able to Identify gaps through risk management, and assist in the development of mitigation strategies.
  • Experience updating privacy and security policies based on gaps found through an assessment process.
  • Experience documenting vulnerability assessment results in ccurate, clear, actionable, and available way to appropriate personnel
  • Must be able to review & assess MES systems throughout all phases of their life cycle in an effort to identify Privacy, Security Architecture
  • Must be able to serve as a knowledge base for organizations as it relates to CMS and state compliance requirements & mitigation strategies.
  • Experience Performing risk assessments based on NIST 800-53 Rev 4. HIPAA,SSA and IRS Pub 1075.
  • Experience with network mapping and vulnerability scanning tools such as NESSUS and NMAP.
  • Experience in reviewing RFP, RFQ, MOU and MOA for privacy and security architecture requiremetns
  • Experience in reviewing the Business Continuity plans, Disaster Recovery Testing plans based on Federal and State requirements
  • Experience providing security compliance requirements for Applications / Systems in Cloud Environments (AWS, Azure, Google cloud)
  • MITA (Medicaid Information Technology Architecture) Experience (Nice to have)
  • 2 days ago
Related jobs
Promoted
Serigor Inc.
Raleigh, North Carolina
Remote

In addition this resource must also review the RFP, MOU and MOA for privacy, security, Business Continuity Planning, Disaster Recovery and audit requirements. Supports the ISSO with the management of system security plans, ensure the systems obtain and maintain an authorization to operate (ATO), and...

Promoted
Alliance
Morrisville, North Carolina

Under direct supervision of the Director-Infrastructure and Security the Microsoft 365 IT Security Specialist is responsible for the management, administration, security, and maintenance of the Microsoft 365 suite of products and tools used by Alliance Health. The position will work closely with oth...

Promoted
Crescens
Raleigh, North Carolina

Job Title: IT Security Specialist. In addition this resource must also review the RFP, MOU and MOA for privacy, security, Business Continuity Planning, Disaster Recovery and audit requirements. Supports the ISSO with the management of system security plans, ensure the systems obtain and maintain an ...

eTeam Inc
Raleigh, North Carolina

Computer Incident Response Team (CIRT), Computer Emergency Response Team (CERT), Computer Security Incident Response Center (CSIRC) or a Security Operations Center (SOC). Candidate will support the mission of the Threat Intelligence Unit by analyzing and tracking adversaries, creating and sharing in...

CliftonLarsonAllen
Raleigh, North Carolina

Act as a liaison between the security team and various business units to facilitate communication and collaboration on security-related initiatives. As an IT GRC Analyst in conjunction with the IT GRC Leadership team, you will function as key contributor to supporting and growing CLA’s IT compliance...

Serigor Inc.
Raleigh, North Carolina
Remote

Job Title: IT Security Specialist st (Remote) Location: Raleigh NC Duration: 12+ Months Job Description: The client requiring services of an IT Security Compliance Specialist  to assist and assess the client Application and Infrastructure Modernization(AIM) CMS, USDA and ACF requirements for th...

Promoted
IMEG Corporation
Raleigh, North Carolina
Remote

From opportunities to get involved and give back locally through our Community Involvement Committees to the ability to partner with exciting clients, we take our jobs seriously but have a great time in the process. We are committed to providing equal employment opportunities in all employment pract...

Promoted
N-able Technologies, Inc.
Morrisville, North Carolina

N-able is seeking a Security Principal - Business Continuity to come join us on our exciting journey of growth! Our vision is to enable the digital evolution of small and medium size businesses. In this position, a deep understanding of end-to-end business processes, security frameworks, and technol...

Promoted
Follett School Solutions
Raleigh, North Carolina

Provide support for remote system access, including VPN and remote desktop connections. Provide remote support to users and respond to after-hours support requests. For librarians, Follett can help you build a diverse collection of print and digital resources that support every student. Documents po...

Promoted
ALTA IT Services
Raleigh, North Carolina

ALTA IT Services is staffing a direct hire opportunity for an Accounting Specialist to support an association non-profit in Durham, NC. The Accounting Specialist will provide accounting administrative support to the client its affiliate Accounting Firm. This full-time, exempt position will report to...