Senior Information Security GRC Analyst (Security Architect - Consultant)

Intersources Inc.
Columbia, SC, United States
about 2 months ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$26,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Information Security Management PCI Data Security Standards Smartsuite

Job description

Candidate Location: No South Carolina residency required. Open to nationwide candidates. Preference will be given to local candidates who can attend client meetings, trainings, and other onsite activities as needed. Travel expenses for onsite work are the responsibility of the consultant.

Daily Duties / Responsibilities:

  • Support DIS in executing the statewide Information Security Program.
  • Conduct interviews with business owners, technical teams, administrators, and third parties to understand agency security processes.
  • Develop and track agency Information Security implementation plans.
  • Review security documentation to ensure compliance with established security controls.
  • Document policies, procedures, and security processes.
  • Perform security compliance assessments using standard control frameworks.
  • Assess agency compliance with NIST 800-53 security controls.
  • Track POA&M and Corrective Action Plan (CAP) activities.
  • Utilize Archer or similar GRC tools to manage compliance activities.
  • Identify process improvements and assist agencies with security implementation.
  • Manage multiple information security initiatives while meeting project deadlines.
  • Collaborate with agency stakeholders to improve overall security compliance.

Requirements

  • 10+ years of Information Security and Compliance experience.
  • 2+ years of experience performing security audits using a standard control framework as an Auditor or Information System Security Officer (ISSO).
  • Strong working knowledge of NIST SP 800-53 (2+ years).
  • Experience with POA&M (Plan of Action & Milestones) or Corrective Action Plans (CAP).
  • 3+ years of experience using Archer or similar GRC tools.
  • Strong written and verbal communication skills.
  • Bachelor’s Degree (completed and verifiable).

Preferred Skills:

  • Experience developing Information Security Plans (ISP) or System Security Plans (SSP).
  • Experience managing multiple information security work efforts simultaneously.
  • Knowledge of IRS 1075, HIPAA, CJIS, MARS-E, and/or PCI-DSS.
  • Government/Public Sector experience.
  • Strong business process analysis and documentation skills.

Required Education:

  • Bachelor’s Degree (Required)

Preferred Certifications:

  • CISA
  • GSLC
  • Equivalent Information Security Certification

About the company

InterSources Inc , is a Small, Woman, and Minority-Owned Business Enterprise, ISO/IEC 27001, SOC 2 Type 2 certified company with massive 18+ years of diversified experience in providing IT Consulting Services, Artificial Intelligence, Data Analysis, Application Development, Cloud Services, Cybersecurity, Digital Marketing, ERP Management, Custom Software Development, Web Development, UI/ UX Design, System Integration, QA Support etc. We make reasonable accommodations for clients and employees, and we do not discriminate based on any protected attribute including race, religion, color, national origin, gender sexual orientation, gender identity, age, or marital status. We also are a Google Cloud and Oracle partner company.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on intersourcesinc.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Platform compliance and security certifications for sensitive data

Chad Carlson · WWC 2021

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · WWC 2023

Videos

See all

Related articles

See all