> Markdown version of [/jobs/ext/2693075-it-risk-analyst-s](https://www.wearedevelopers.com/jobs/ext/2693075-it-risk-analyst-s). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Risk Analyst's - **Company:** Neos Consulting - **Location:** Austin, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Systems Engineering, Information Security Management, Information Technology - **Published:** September 3, 2026 - **Apply:** https://www.dice.com/job-detail/b2e97669-1dd0-425b-96c8-4a73ea621946 ## About the Role * 4 years - Experience with the National Institute of Standards Technology (NIST) 800-37 Risk Management Framework and 800-53 Security controls. * 4 years - Supporting various compliance audits including, PCI, SOC, HIPAA and ISO. * 4 years - Data Privacy experience * 3 years - Proven ability to work successfully with technical and non-technical groups, and manage multiple responsibilities * 2 years - Writing Information System Security Plans * Strong - Communication, analytical and interpersonal skills at all levels * Strong - Ability to work on multiple projects or project assignments * Degree - Bachelor's degree in Computer Science, Systems Engineering or equivalent experience Preferences: * 3 years - Experience facilitating productive meetings to formulate business requirements and communicate stakeholder needs to technical staff * Industry recognized certification such as CISSP, CISA, GCIH * Knowledge of Medicaid and/or CHIP programs and policy * 2 years - Working with Health and Human Services or other Medicaid centric organizations ## Description The IT Risk Analyst will lead the team responsible for elicitation, analysis and documentation of systems and state operations and coordination and facilitation of meetings with Medicaid/CHIP Services (MCS) and IT stakeholders. The team will evaluate over 50 systems to complete the Information Security Program Plan, Information System Security Plans and associated Risk Assessments. The Worker will coordinate with IT and business areas to identify risks, confirm controls, and make recommendations for improvement. The Worker will be responsible for identifying system interdependencies and confirming classification of data in a HIPAA environment. The Worker may serve as team lead over analysts. This job role will aide in analysis and documentation of systems necessary to complete the Information Security Program Plan and to conduct security risk assessments. The IT Risk Analyst's responsibilities include: * Working with subject matter experts across the MCS system to collect and update business and system data. * Gathering information on HHS data source systems which interface to MCS systems. * Completing Information Security Program Plan, Information System Security Plans and associated Risk Assessments using HHS defined security tools to identify risks and confirm current controls. ## Related Videos - [Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Model Based Systems Engineering in an Agile Product Development Process](https://www.wearedevelopers.com/videos/68-model-based-systems-engineering-in-an-agile-product-development-process) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)