Information Security Compliance Consultant

HTC Global Services, Inc.
United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Security Management PCI Data Security Standards Information Security Management System

Job description

This position will perform duties as part of DIS execution of its responsibilities under the statewide information security program. The role supports agencies with information security program implementation, compliance assessments, documentation development, and progress tracking to ensure alignment with state security standards., Support agencies during the development of their information security programs through direct tactical implementation assistance. Develop and track agency information security implementation plans. Interview administrators, managers, business owners, technical owners, and third parties to gather information and support the development of program artifacts. Conduct high-level assessments of agency information security efforts to evaluate progress. Perform high-level analysis of processes and procedures to ensure compliance with state standards. Determine policies and procedures used for agency processes through stakeholder interviews. Track information security implementation plan progress. Document information gathered from interviews and document reviews. Assist with the development of formal processes and procedures. Assess agency documentation to ensure appropriate approaches are used to comply with security controls.

Requirements

Bachelor s Degree. 10+ years of experience in Information Security and Compliance. 2+ years of experience with security audits based on a standard control set as an auditor or responding Information System Security Officer. Strong working knowledge of NIST 800-53 (2+ years of experience). Prior experience with POA&M or CAP. Strong communication skills. 3+ years of experience using a GRC tool such as Archer or similar.

Preferred Qualifications Experience completing an Information Security Plan or System Security Plan notebook. Ability to simultaneously manage multiple information security work efforts. Knowledge of IRS 1075, HIPAA, CJIS, MARS-E, and/or PCI-DSS. Government sector experience. Ability to identify, map, and re-engineer business processes. Strong schedule management and resource planning skills. Ability to work in a high-volume, fast-paced environment. Strong collaboration skills and ability to meet deadlines.

Preferred Certifications CISA, GSLC, or equivalent certification.

Benefits & conditions

HTC Global Services wants you to join our team. Come build new things with us and advance your career. At HTC Global, you ll collaborate with experts, work alongside clients, and be part of high-performing teams driving success together. You ll have long-term opportunities to grow your career and develop skills in the latest emerging technologies.

At HTC Global Services, our employees have access to a comprehensive benefits package. Benefits can include Group Health (Medical, Dental, and Vision), Paid Time Off, Paid Holidays, 401(k) matching, Group Life and Disability insurance, Professional Development opportunities, Wellness programs, and a variety of other perks.

Our success as a company is built on inclusion and diversity. HTC Global Services is committed to providing a workplace free from discrimination and harassment, where every employee is treated with dignity and respect. We celebrate differences and believe that diverse cultures, perspectives, and skills drive innovation and success. HTC is an Equal Opportunity Employer and a proud National Minority Supplier. We seek to empower each individual, fostering an environment where everyone feels valued, included, and respected.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Platform compliance and security certifications for sensitive data

Chad Carlson · WWC 2021

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:25 min

The growing power and security responsibility of developers

Tino Sokic · WWC 2023

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:03 min

Securing applications against exceptional condition mishandling

Christian Wenz Christian Wenz · WWC Europe 2026

Videos

See all

Related articles

See all