> Markdown version of [/jobs/ext/2642107-it-security-ba](https://www.wearedevelopers.com/jobs/ext/2642107-it-security-ba). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security BA - **Company:** Cerebra Consulting - **Location:** Quincy, MA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Runbook, CIS Benchmarks - **Published:** August 31, 2026 - **Apply:** https://www.dice.com/job-detail/bdb56f33-b5e9-49cd-bcea-94a5c58331e5 ## About the Role * 8 years of IT/Cybersecurity experience * 3+ years as a Business Analyst, Process Analyst, Technical Writer, or Security Analyst * Strong security process documentation (policies, SOPs, playbooks, runbooks, workflows) * Experience with requirements gathering and stakeholder interviews * Ability to analyze and improve security processes * Knowledge of NIST CSF, CIS Controls, and ISO 27001 * Experience supporting security governance, compliance, and audits * Excellent written communication and presentation skills * Experience creating process maps, flowcharts, and swim lane diagrams. ## Description * Support the EOHHS CISO Office with security operations and governance initiatives * Document and improve security policies, procedures, SOPs, playbooks, and workflows * Conduct process analysis to identify gaps, risks, and improvement opportunities * Work closely with security teams, IT teams, and agency stakeholders * Create process maps, swim lane diagrams, reports, dashboards, and presentations * Support security compliance, audit readiness, and governance activities * Gather and document business and security requirements * Track security projects, risks, issues, and decisions * Develop future-state processes and operational roadmaps * Help create security training and communications * Translate undocumented security practices into repeatable, auditable processes. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)