Description & Requirements
Reporting to the Sr. Manager for the Program Security Services team (US Services), the Lead Analyst-ISSO is responsible for managing the overall security posture of their assigned projects. Acting as an independent contributor, the Lead Analyst-ISSO will document and validate security compliance requirements, as defined in client contracts and established regulatory frameworks (NIST 800-53, HIPAA, IRS 1075, CMS MARS-E/ARC-AMPE, PCI-DSS). This position requires broad knowledge of Information Technology, including cloud providers such as Azure and AWS. This role will also manage stakeholder relationships with both internal and external customers.
Additional Requirements as per contract/client:
Candidates must be a US Citizen.Essential Duties and Responsibilities:
-Responsible for ensuring information security for an assigned area of Business / Project focusing on key areas of risk, outlined in the Information Security policy, under the direction of the Information Security management team.
- Conduct Information Security risk assessments and compliance evaluations for infrastructure and application assets within required timeframes and to industry standards and regulatory specifications.
- Ensure controls implementation for identified Information Security risks for business area of responsibility.
- Define, create and maintain the documentation for certification and accreditation of each information system in accordance with regulatory requirements.
- Support audit and client engagements, coordinate the collection, review and submission of Information Security deliverables and coordinate the remediation of audit concerns.
- Manage expectations with multiple stakeholders on projects and programs in conjunction with the Information Security team.
- Promotion of Information Security awareness through various communication channels within the organization.
- Collaborate with the Information Security team members on process improvements, secure design and recertification of MAXIMUS assets.
- Travel required up to 25%.
- Other duties as assigned.
- Develop Plan of Action and Milestones (POA&M) as necessary
- Manage exceptions to policies and procedures
- Please refer to the additional information section of the job requisition for this opening to determine clearance eligibility required.
- Bachelor's Degree
- 7+ of security or technology related experience
- Works on complex issues where analysis of situations or data requires an in depth evaluation of variable factors.
- Exercises judgement in selecting methods, techniques, and evaluation criteria for obtaining results.
- Networks with key contacts outside own area of expertise.
- Develops solutions to a variety of complex problems.
- Work requires considerable judgment and initiative.
- Ability to communicate technical information in understandable business terms
- Excellent interpersonal skills, presentation skills, and verbal / written communication skills
- Strong customer service abilities required.
- Ability to work collaboratively with a broad range of staff. Skilled in Microsoft Office software including Word, Excel, Visio, MS Project, and PowerPoint
- Ability to perform comfortably in a fast-paced, deadline-oriented work environment
- Ability to execute many complex tasks simultaneously, and work as a team member as well as independently
At least one of the following certifications is required: CISSP, CISA or CISM.
Experience with NIST 800-53 and HIPAA are required.
Experience with Cloud providers, such as Azure and AWS.
Knowledge of any of the following security frameworks is preferred: IRS 1075, CMS MARS-E/ARC-AMPE, PCI-DSS.
Smartsheet experience preferred.