Job Title: Information Security Compliance Consultant
Overview / Summary
This position will perform duties as part of DIS execution of its responsibilities under the statewide information security program. The role supports agencies with information security program implementation, compliance assessments, documentation development, and progress tracking to ensure alignment with state security standards.
Key Responsibilities
• Support agencies during the development of their information security programs through direct tactical implementation assistance.
• Develop and track agency information security implementation plans.
• Interview administrators, managers, business owners, technical owners, and third parties to gather information and support the development of program artifacts.
• Conduct high-level assessments of agency information security efforts to evaluate progress.
• Perform high-level analysis of processes and procedures to ensure compliance with state standards.
• Determine policies and procedures used for agency processes through stakeholder interviews.
• Track information security implementation plan progress.
• Document information gathered from interviews and document reviews.
• Assist with the development of formal processes and procedures.
• Assess agency documentation to ensure appropriate approaches are used to comply with security controls.
Required Qualifications
• Bachelor's Degree.
• 10+ years of experience in Information Security and Compliance.
• 2+ years of experience with security audits based on a standard control set as an auditor or responding Information System Security Officer.
• Strong working knowledge of NIST 800-53 (2+ years of experience).
• Prior experience with POA&M or CAP.
• Strong communication skills.
• 3+ years of experience using a GRC tool such as Archer or similar.
Preferred Qualifications
• Experience completing an Information Security Plan or System Security Plan notebook.
• Ability to simultaneously manage multiple information security work efforts.
• Knowledge of IRS 1075, HIPAA, CJIS, MARS-E, and/or PCI-DSS.
• Government sector experience.
• Ability to identify, map, and re-engineer business processes.
• Strong schedule management and resource planning skills.
• Ability to work in a high-volume, fast-paced environment.
• Strong collaboration skills and ability to meet deadlines.
Preferred Certifications
• CISA, GSLC, or equivalent certification.
#LI-ST1 #LI-Remote #Hiring