Office of Cybersecurity Senior IT Security Analyst (DoIT #10117005)

State of New Mexico
Santa Fe, NM, United States
24 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$75,774.0 - $113,672.0
Working hours
Shift work
Job source

Tech stack

Artificial Intelligence Software System Penetration Testing Cyber Security Information Systems Digital Assets Disaster Recovery Information Security Management Systems Development Life Cycle SAP Security Security Information and Event Management Software Vulnerability Management Mttr
+2 more
Information Technology Security Orchestration, Automation & Response

Job description

To maintain an adequate security posture by developing appropriate IT security policies, standards, and procedures with periodic updates to accurately reflect ever changing technology, legislative and user needs. The OCS has the responsibility in protecting and monitoring the State of New Mexico’s technology infrastructure and digital assets, including state agencies, mission critical systems and data.

Cyberattacks are dramatically increasing, and cybersecurity operations are facing new challenges. Cybersecurity is not just an IT problem anymore, it is a critical business risk, homeland security and public safety threat, voter confidence issue, and an economic development opportunity.

Technology continues to evolve, the cybersecurity landscape is constantly changing, increasing potential vulnerabilities and risk. Therefore, it is essential for the State Chief Information Security Officer (CISO) to secure additional security analysts to support the Office of Cybersecurity.

This posting will be used for ongoing recruitment and may close at any time. Applicant lists may be screened more than once. Why does the job exist?

The Senior Security Analyst plays a critical role in advancing the mission of the Office of Cybersecurity (OCS) to protect the State of New Mexico’s digital infrastructure. This position ensures the security of information systems and verifies that services, vendors, and stakeholders adhere to all applicable legal, safety, and quality standards. The role provides strategic leadership across OCS’s information security programs, including compliance management, evaluation, mitigation, and incident response. To strengthen the state’s cybersecurity posture, this position is responsible for:

  • Developing and implementing proactive cybersecurity compliance strategies
  • Identifying and addressing potential compliance risks
  • Introducing and improving technologies and processes that enhance security
  • Leading surveillance, monitoring, and incident response strategies
  • Delivering consultative and training services with a security¿first mindset

The Senior Security Analyst manages cybersecurity services delivered to state agencies, K¿12 public schools, higher education institutions, local governments, and tribal entities. These services include vulnerability management, attack surface management, penetration testing, user security awareness training, and operating the Security Operations Center (SOC) for SoNM agencies.

Additional responsibilities include:

  • Contributing to the design and implementation of enterprise¿wide business continuity and disaster recovery management programs, including maturity models, methodologies, sourcing strategies, plans, metrics, and scorecards
  • Assisting business partners in determining critical business processes and systems¿ Overseeing security incident and response management
  • Leading and responding to complex security incidents and investigations
  • Conducting advanced IT data and security reviews and audits to ensure regulatory and standards compliance
  • Participating in third¿party security investigations and compliance reviews
  • Interfacing with vendors to evaluate new security products or support security assessments
  • Maintaining vendor relationships related to security system updates and technical support
  • Identifying and resolving root causes of security¿related issues
  • Coordinating with vendors to ensure proper implementation and maintenance of managed services
  • Evaluating and recommending security tools and solutions

Through these responsibilities, this role ensures OCS remains a trusted partner by driving effective security strategies and maintaining strong compliance and risk¿management practices across the state’s digital ecosystem. How does it get done?

The Senior Security Analyst is responsible for safeguarding the confidentiality, integrity, and availability of the State of New Mexico’s information systems. This role supports the Office of Cybersecurity by leading and executing a wide range of security operations, compliance, and incident response activities.

Security Governance and Compliance

  • Develop, implement, and enforce enterprise security policies, standards, and procedures
  • Support the creation and review of cybersecurity documentation, including:
  • Security policies and procedures
  • Information system security plans (ISSPs)
  • Incident response and disaster recovery plans
  • Configuration and change management plans
  • Ensure compliance with NIST 800 series and other applicable frameworks
  • Interpret and communicate regulatory and compliance requirements to stakeholders

AI Governance, Risk, and Compliance

  • Establish, maintain, and operationalize governance structures to ensure AI systems are developed, deployed, and used securely, ethically, and in alignment with legal, regulatory, and organizational requirements.
  • Develop, review, and refine AI related policies, standards, and guidelines consistent with emerging state and federal regulations.
  • Support design and implementation of AI governance frameworks, including lifecycle oversight, documentation requirements, transparency expectations, and risk tiering processes.
  • Identify, evaluate, and track AI related risks such as model bias, data protection concerns, misuse scenarios, vendor exposure, and operational security issues.
  • Review and assess third party AI tools and platforms for security, privacy, and governance compliance; support procurement evaluations and implementation decisions.
  • Monitor legislative and regulatory developments and assist with readiness and compliance alignment.
  • Provide cross functional governance, policy, compliance, and risk subject matter support to OCS projects (non engineering).

AI Development Governance Support

  • Contribute to governance processes that oversee responsible AI system development, documentation, and operational controls.
  • Ensure compliance with OCS AI System Inventory, risk tier classification workflows, and Gen AI security authorization requirements.

Security Orchestration, Automation, and Response (SOAR) Enablement

  • Use automation and orchestration to improve SOC workflow efficiency, precision, and scalability.
  • Support development and enhancement of standardized playbooks and automated response flows to reduce MTTD/MTTR and strengthen enterprise resilience.
  • Partner with SOC stakeholders to integrate SOAR-driven improvements into monitoring, alert handling, and incident response programs.

Security Operations Center (SOC) and Monitoring

  • Monitor systems and logs using SIEM tools to detect and respond to anomalies
  • Conduct threat hunting and analyze indicators of compromise (IOCs)
  • Review and update security tools to block malicious IPs and signatures
  • Escalate incidents and coordinate with state agencies and third-party partners
  • Maintain documentation of all actions taken during investigations

Risk Management and Incident Response

  • Conduct risk assessments
  • Lead or support investigations into cybersecurity incidents
  • Coordinate with internal and external teams to resolve incidents in line with policy
  • Recommend and implement technical solutions to mitigate identified risks

Security Services and Technical Oversight

Oversee services such as:

  • Vulnerability Management as a Service (VMaaS)
  • Attack Surface Management (ASM)
  • Penetration testing
  • User security awareness training
  • Participate in the design of secure infrastructure and application solutions
  • Provide input on disaster recovery planning and business continuity

Stakeholder Engagement and Training

  • Deliver security awareness training and track participation
  • Respond to security inquiries, assessments, and questionnaires from agencies and partners
  • Build trusted relationships across state agencies, educational institutions, and tribal entities

Who are the customers?

The State Chief Information Security Officer, State of New Mexico agencies, K-12 public school districts, higher educational institutions, local governments, and tribal entities.

Requirements

Bachelor’s degree in Computer Science, Management Information Systems (MIS), Information Technology, Engineering, or similar technical degree and three (3) years of experience in IT security or compliance validation (e.g., HIPAA, PCI). Any combination of education from an accredited college or university in a related field and/or direct experience in this occupation totaling seven (7) years may substitute for the required education and experience. A certificate in IT security/forensics (e.g., CISSP, CEH, CCFP, CCSP, HCISPP, SSCP) or regulated compliance (e.g., PCIP, ASV, ISA, QSA) can be used to substitute one (1) year of experience. Employment Requirements

Must possess and maintain current ID or Driver’s License. Pre-employment background investigation is required, and employment is conditional pending results. Working Conditions

Work will be performed in an office environment. Many requests will arrive by phone or in-person and the person must be able to speak and respond to the requester clearly. The person will work extended periods seated in front of a computer. The person must be able to operate a computer, keyboard, and mouse. Position requires occasional 1) travel, 2) night/weekend/holiday work, and 3) call-back work. Supplemental Information

Benefits & conditions

3.53.5 out of 5 stars 715 Alta Vista St, Santa Fe, NM 87505 $36.43 - $54.65 an hour - Full-time

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · World Congress 2021

2:30 min

Evaluating and selecting an AI pair programming tool

Alexander Trusheim Alexander Trusheim +1 · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:07 min

Establishing service level agreements directly for internal platforms

Pawel Piwosz · LIVE

Videos

See all

Related articles

See all