> Markdown version of [/jobs/ext/2966677-systems-analyst](https://www.wearedevelopers.com/jobs/ext/2966677-systems-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Systems Analyst - **Company:** Lumen Solutions Inc. - **Location:** Austin, TX, United States - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, Cyber Security, Virtual Desktops, Systems Development Life Cycle, Web Application Security, Software Vulnerability Management, Privacy Controls, Multiplatform, Devsecops, Plan of Action and Milestones - **Published:** September 17, 2026 - **Apply:** https://www2.jobdiva.com/portal/?a=yyjdnwtj1vk20likwp2a7oa2mc2scw064c948z22g23e046qehohegye8oqt3zi6&compid=0/jobs/27468728#/jobs/27468728 ## About the Role Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity. Years Required/Preferred Experience 12 Required deep focus on: Governance, Risk, and Compliance (GRC), Enterprise Security and Security Architecture, Vulnerability Management and Penetration Testing , Cloud Security and hybrid environments 10 Required Proven experience owning SSP development end to end 10 Required Hands on experience with CMS MARS E v2.2 or comparable federal/state security frameworks 10 Required Strong expertise in: Control implementation documentation, Audit evidence collection and validation, POA&M creation, tracking, and remediation management 8 Required Ability to translate technical security issues into compliance aligned remediation actions 8 Required Strong stakeholder management skills across security, infrastructure, and application teams 8 Required Excellent written and verbal communication skills, particularly for executive stakeholders 8 Required Knowledge of NIST 800 53, NIST RMF, and privacy controls 8 Required Knowledge of Secure SDLC and DevSecOps practices 5 Preferred Experience operating in multi-vendor, multi-platform environments 5 Preferred Demonstrated ability to reduce repeat audit findings and improve compliance maturity 5 Preferred Experience mentoring or guiding teams on security governance best practices 1 Preferred Experience supporting HHSC systems, including SSP development and compliance ***Lumen and / or its clients will not provide equipment (Laptop, monitor, etc.) to the selected contractor. The contractor must have their own equipment. Access to a virtual desktop set up (software) will be provided by Lumen's client, allowing the user access to the required systems and technology.*** ## Description The Security Engineer will project work by leading security governance, compliance, and risk management activities, with a strong focus on System Security & Privacy Plans (SSP/SSPP). This role bridges technical security operations and regulatory compliance, ensuring audit readiness, effective vulnerability remediation, and secure delivery of public-facing services across complex, multi-platform environments. * Lead end to end System Security & Privacy Plan (SSP/SSPP) development, maintenance, and updates for enterprise systems * Drive remediation activities through POA&M management, ensuring timely closure of compliance gaps * Translate penetration testing and vulnerability findings into actionable remediation work items (EPICs/user stories) * Coordinate with application, infrastructure, and security teams to validate remediation through re-testing and evidence * Oversee risk-based vulnerability management, including prioritization and SLA-driven remediation * Provide governance oversight for endpoint protection, web application security, and cloud security controls * Produce assessor ready documentation, including configurations, monitoring evidence, approvals, and incident traceability * Support continuous audit readiness and reduce repeat findings through disciplined governance and documentation practices ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [The Dark Corners of Kotlin Multiplatform](https://www.wearedevelopers.com/videos/100143-the-dark-corners-of-kotlin-multiplatform) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)