IT Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The State of Arizona (AZDES) is seeking an experienced IT Security Analyst (Governance, Risk & Compliance - GRC) to support the Division of Technology Services. The selected candidate will perform IT security risk assessments, compliance reviews, audit support, and security documentation while ensuring compliance with security frameworks including NIST 800-53 Rev. 5 and the Risk Management Framework (RMF). This role requires collaboration with business and technical teams to strengthen enterprise security, governance, and compliance initiatives.
Requirements
Strong experience with NIST 800-53 Rev. 5 Experience implementing the Risk Management Framework (RMF) Experience with Windows and Unix environments Experience performing IT security risk assessments, compliance reviews, and security audits Knowledge of information security governance, risk management, and internal controls Experience preparing audit documentation, security reports, findings, and POA&Ms Knowledge of security and privacy regulations (NIST, IRS Pub 1075, HIPAA/HITRUST, CJIS, MARS-E) Experience investigating security incidents and suspicious network activity Strong written, verbal, analytical, and communication skills Ability to work collaboratively with technical teams, business units, and project managers Preferred Skills Project Management experience Professional certifications such as CISSP, CCSP, GSTRT, GSNA, or CAP Experience developing security policies, standards, and procedures Experience supporting enterprise GRC programs Knowledge of database administration, networking, and software development environments
Benefits & conditions
Local Phoenix, AZ candidates only (within approximately a 1-hour driving distance) Hybrid work schedule (All work must be performed within Arizona) Contract-to-Hire (4 Months) - Candidates must be eligible for full-time conversion No Visa Sponsorship W2 Only (No C2C) Candidates previously submitted to Req #10482 or Req #11481 will not be considered Resume must clearly mention the candidate’s current location Candidate must be available for in-person interviews within one week of the posting closing Candidate must be able to start within two weeks of receiving an offer HireRight Background Check, Drug Screening, and Global ID Verification are mandatory Primary Skills NIST 800-53 Rev. 5, Risk Management Framework (RMF), Governance Risk & Compliance (GRC), Information Security, Risk Assessment, Security Audits, Compliance, Security Governance, Windows, Unix, Cybersecurity, Internal Controls, Security Policies, POA&M, Incident Response, NIST Compliance, CJIS, HIPAA/HITRUST, IRS Pub 1075, MARS-E, Project Management, CISSP, CCSP, GSNA, GSTRT, CAP Certification.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks
Dev Digest 134 - Where pixels sing?
The Overflow: Security and Privacy