Security Analyst
Security Analyst - State of Wisconsin (DHS))Position: Security Analyst (DHS Liaison)Duration: Through June 30, 2027, with possible extensionWork LocationWisconsin residents onlyNo relocation permittedRemote work up to five days per weekCandidate must report onsite when required, including short notice requestsMinimum onsite attendance is quarterly, but more frequent visits may be required based on business needsRemote work expectations will be discussed during the interview processProject Overviewseeking Security Professional with strong expertise in:Vulnerability ManagementSecurity DocumentationRegulatory ComplianceStakeholder CommunicationSuccess In This Role Requires The Ability ToWork cross-functionally across teamsManage competing prioritiesSupport federal security compliance initiativesServe as a trusted advisor to both security teams and business stakeholdersThis position requires a solid understanding of security concepts, technical requirements, and operational processes, along with the ability to communicate effectively with non-technical audiences.The role contributes to key security and privacy deliverables, including:System Security and Privacy Plans (SSPP)Security compliance documentationVulnerability management tracking and remediation oversightThe candidate will also support vulnerability management activities across the CARES environment, ensuring remediation efforts are tracked, monitored, and completed.Interview ProcessTwo-round virtual interview processVideo conference interview or onsite interview may be requiredAI assistance is strictly prohibited during interviewsA real-time photo must be uploaded for interview verificationPosition SummaryTen divisions and officesSeven 24/7 institutions located throughout WisconsinPrograms And Services Administered By DHS IncludeMedicaid and other human services programsAlcohol and drug abuse prevention servicesMental health servicesPublic health programsLong-term care servicesThe Information Security Section (ISS) supports the department by promoting a strong information security culture and enabling business operations. ISS is:Metrics-drivenEmployee-focusedService-orientedISS Responsibilities IncludeIdentifying and continuously assessing riskDeveloping and improving risk mitigation strategiesLimiting the impact of information security incidentsSelecting, assessing, authorizing, and monitoring security controlsSupporting the department's overall information security programThe ISS Is Organized Into The Following Functional AreasSecurity Awareness and GovernanceComplianceSecurity ArchitecturePortfolio ManagementCross-team collaboration is essential to success.serves the Division of Medicaid Services (DMS) and acts as a champion for integrating information security into program operations. This work involves collaborating with security teams, communicating risk, and developing mitigation strategies while maintaining strong relationships with business stakeholders.The ideal candidate must possess exceptional communication and interpersonal skills with the ability to present information effectively to:Executive leadershipBusiness stakeholdersTechnical teamsNon-technical audiencesCertification RequirementA federally recognized ANSI-accredited Information Security Certification must be obtained within six (6) months of the start date and maintained throughout employment.The Department of Defence (DoD) 8570 Baseline Certifications, as defined by the Defense Information Systems Agency (DISA), should be used as a reference for acceptable certifications.Goals and Worker Activities Integrate Security into Program OperationsPartner with organizational leaders to incorporate information security best practices into technical and operational initiativesRecommend improvements to strengthen security posture and reduce riskCommunicate risks in clear, business-friendly languageProvide mitigation options while considering business impactDraft security requirements for:Project chartersScope documentsProcurement activitiesDocument analysis and communicate recommendationsRespond to clarifying questions from stakeholdersEscalate risks to ISS leadership when acceptable risk levels cannot be achieved Serve as a Liaison Between Program Areas and ISSAct as a solutions-focused advocateIntake projects and business initiatives and guide them through appropriate ISS workstreamsGather information necessary for thorough security analysisCommunicate security deliverables to stakeholdersEnsure deliverables meet customer requirementsCoordinate clarification activities as neededCollaborate across ISS teams to meet security requirementsWork with:BITS staffOffice of Legal CounselBureau of Procurement and ContractingProgram stakeholders Support Audit, Assessment, Incident Response, and Regulatory ActivitiesRequest and gather compliance-related artifactsFacilitate communication among:AuditorsIncident response teamsVendorsTechnical teamsBusiness stakeholdersAssess audit results in partnership with ISSDevelop:Corrective Action Plans (CAPs)Plans of Action and Milestones (POA&Ms)Provide oversight through remediation and validationVerify compliance before closureRespond to regulatory inquiriesDraft supporting documentation Support Program Integration ActivitiesProvide backup for other Security Liaison rolesDraft and deliver status reportsBuild and maintain positive stakeholder relationshipsEstablish and document standard operating procedures (SOPs) Support Vulnerability Management Support vulnerability management activities for DMS and its vendors by:Promoting transparency and accountabilityDriving timely resolution of vulnerabilitiesSupporting adherence to:State regulationsFederal regulationsPolicies, Procedures, Standards, and Guidelines (PPSGs)Drafting and monitoring remediation plans and POA&MsTracking non-compliance issues through resolution Support DHS Transition from MARS-E to ARC-AMPE Support DHS's migration from the Centers for Medicare & Medicaid Services (CMS) compliance framework:FromMinimum Acceptable Risk Standards for Exchanges (MARS-E)To:Acceptable Risk Controls for ACA, Medicaid, and Partner Entities (ARC-AMPE)Responsibilities IncludePartnering with Deloitte, DET, and ISS to conduct gap assessmentsSupporting transition planning, implementation, and maturity effortsDrafting and maintaining the ARC-AMPE System Security and Privacy Plan (SSPP)Developing and monitoring POA&Ms for identified compliance gaps Security Review SupportSupport DHS Initiatives InvolvingSoftware reviewsCloud brokerage reviewsAI Use Case reviews Additional DutiesProvide backup support to other security personnelDevelop:Concept papersProposalsBriefing materialsSecurity documentationReports and recommendationsKnowledge, Skills, And AbilitiesThe ideal candidate will possess:Security Knowledge Broad information security knowledgeExperience in one or more of the following:Application developmentTechnical architectureContractingAudit and complianceVendor management Compliance & Framework ExpertiseFamiliarity with NIST or other recognized security frameworksUnderstanding of security governance and regulatory requirementsCommunication SkillsStrong verbal communication skillsStrong written communication skillsAbility to explain complex security concepts to technical and non-technical audiencesProblem SolvingAbility to solve complex business and security challengesAbility to manage multiple priorities and interruptions effectivelyOrganizational SkillsStrong attention to detailExcellent documentation capabilitiesEffective project and task management skillsCustomer Focus Ability to balance:ConfidentialityIntegrityAvailabilityStrong customer service orientation TeamworkAbility to work independentlyAbility to collaborate with peersAbility to contribute effectively within multidisciplinary teamsDiversity & InclusionDemonstrated commitment to fostering a diverse and inclusive workplace environment