Systems Analyst

Lumen Solutions Inc.
Austin, TX, United States
8 days ago
Apply on www2.jobdiva.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cloud Computing Security Cyber Security Virtual Desktops Systems Development Life Cycle Web Application Security Software Vulnerability Management Privacy Controls Multiplatform Devsecops Plan of Action and Milestones

Job description

The Security Engineer will project work by leading security governance, compliance, and risk management activities, with a strong focus on System Security & Privacy Plans (SSP/SSPP). This role bridges technical security operations and regulatory compliance, ensuring audit readiness, effective vulnerability remediation, and secure delivery of public-facing services across complex, multi-platform environments.

  • Lead end to end System Security & Privacy Plan (SSP/SSPP) development, maintenance, and updates for enterprise systems

  • Drive remediation activities through POA&M management, ensuring timely closure of compliance gaps

  • Translate penetration testing and vulnerability findings into actionable remediation work items (EPICs/user stories)

  • Coordinate with application, infrastructure, and security teams to validate remediation through re-testing and evidence

  • Oversee risk-based vulnerability management, including prioritization and SLA-driven remediation

  • Provide governance oversight for endpoint protection, web application security, and cloud security controls

  • Produce assessor ready documentation, including configurations, monitoring evidence, approvals, and incident traceability

  • Support continuous audit readiness and reduce repeat findings through disciplined governance and documentation practices

Requirements

Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity. Years Required/Preferred Experience 12 Required deep focus on: Governance, Risk, and Compliance (GRC), Enterprise Security and Security Architecture, Vulnerability Management and Penetration Testing , Cloud Security and hybrid environments 10 Required Proven experience owning SSP development end to end 10 Required Hands on experience with CMS MARS E v2.2 or comparable federal/state security frameworks 10 Required Strong expertise in: Control implementation documentation, Audit evidence collection and validation, POA&M creation, tracking, and remediation management 8 Required Ability to translate technical security issues into compliance aligned remediation actions 8 Required Strong stakeholder management skills across security, infrastructure, and application teams 8 Required Excellent written and verbal communication skills, particularly for executive stakeholders 8 Required Knowledge of NIST 800 53, NIST RMF, and privacy controls 8 Required Knowledge of Secure SDLC and DevSecOps practices 5 Preferred Experience operating in multi-vendor, multi-platform environments 5 Preferred Demonstrated ability to reduce repeat audit findings and improve compliance maturity 5 Preferred Experience mentoring or guiding teams on security governance best practices 1 Preferred Experience supporting HHSC systems, including SSP development and compliance

Lumen and / or its clients will not provide equipment (Laptop, monitor, etc.) to the selected contractor. The contractor must have their own equipment. Access to a virtual desktop set up (software) will be provided by Lumen’s client, allowing the user access to the required systems and technology.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www2.jobdiva.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:43 min

Building portable Bluetooth logic using Kotlin multiplatform

Georg Dresler Georg Dresler · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all