Technical Security Analyst / Boston MA / Hybrid
- Salary
- $80–$95/hr
- Hiring from
- United States
- Work type
- Hybrid
- Posted
Is this job info correct?
509,322 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
SPECIFIC DUTIES
- Partner with the BEST Team, SI, and product vendors, CTR and EOTSS to identify security requirements, using methods that may include risk and business impact assessments, including: provide operational support as defined by SLA requirements agreed to by the Commonwealth, the product vendor, and SI; implementation of Commonwealth IT policies related to user security and data security; work with the Commonwealth Risk Management Office in their assessments and recommended controls regarding data security and security operations; conduct additional business system analysis as needed; facilitate communication between users and vendors using issue management software; support development of the operational support playbook for "day 2" operations.
- Ensure the completion of information security operational documentation.
- Work with BEST information security leadership to develop strategies, procedures and recommended roles and responsibilities to enforce security requirements and address identified risks related to the use of the new solution.
- Perform configuration updates and execution role in application development and implementation related to security requirements and controls; ensure security controls are implemented as planned and security and access needs are addressed throughout the user life cycle.
- Participate in and support the data conversion of end users from the legacy system to the new system.
- Work with BEST, CTR's, and EOTSS' CSOs, CIOs, and the Commonwealth's Risk Management Office to identify, select and implement technical controls related to data security and to implement security processes and procedures that ensure security controls are managed and maintained both centrally through the new solution, and within agencies if certain security management tasks are decentralized.
- Advise the BEST Team, SI and product vendors regarding end user security roles and groups, data access controls and security role provisioning and de-provisioning protocols to ensure data are accessed appropriately in the new solution.
- Support the BEST Team and Commonwealth agencies in identifying approved end users of the new solution and coordinating provisioning of users for Day One go live.
- Support the definition and implementation of the security needs along with the BEST Security Workstream.
- Support the BEST Maintenance and Operations Workstream.
- Advise security administrators on normal and exception-based processing of security authorization requests, including the use of SI or product vendor provided tools that monitor system use and data access irregularities.
- Assist security administrators and IT staff in the resolution of reported security incidents.
- Act as a liaison between incident response leads and subject matter experts.
- Monitor daily or weekly reports and security logs for unusual events.
- Maintain an awareness of existing and proposed security-standard-setting groups, state and federal legislation and regulations pertaining to information security; identify regulatory changes that will affect information security policy, standards, and procedures, and recommend appropriate changes.
- Research and assess new threats and security alerts and recommend remedial actions.
- Support the implementation of the new solution's complete security profile, including but not limited to: Azure Active Directory (AD) entry; Single Sign-on (SSO) integration between EOTSS and Workday; New Solution User Security Role; New Solution User Workflow Role.
REQUIRED SKILLS
- Extensive experience providing operational security support to end users
- Experience working with modern issue tracking systems (JIRA)
- Understanding of enterprise security best practices, including IAM, RBAC, Network Security, SaaS, Cloud Security, Data Security, Encryption, and File transfer management
- In-depth exposure to defining and implementing end user security protocols in a large public or private sector entity comparable in size to the Commonwealth
- Exposure to technical configurations, technologies, and processing environments in one or more projects of similar size and complexity to BEST
- Understanding of information risk concepts and principles as a means of relating business needs to security controls
- Experience with common information security management frameworks, such as ISO 2700x, ITIL, COBIT, and NIST
- In-depth knowledge of risk assessment methods and technologies
- Understanding of Human Resource and Payroll systems security requirements
- Excellent technical knowledge of mainstream operating systems and a wide range of security technologies, such as network security appliances, identity and access management (IAM) systems, anti-malware solutions, automated policy compliance tools, and desktop security tools
- More than 3 years of experience in developing, documenting, and maintaining security policies, processes, procedures, and standards
- Knowledge of network infrastructure, including routers, switches, firewalls, and the associated network protocols and concepts
- Strong analytical skills to analyze security requirements and relate them to appropriate security controls
- Ability to interact with personnel at all levels and across all business units and organizations, and to comprehend business imperatives
- Excellent written and verbal communication skills
MINIMUM ENTRANCE REQUIREMENTS
- Bachelor's degree in computer science, system analysis or a related study, or equivalent experience in the field of audit compliance and security risk and compliance management
- Minimum of five years of implementation and operational experience in IT, with knowledge in the following technical disciplines: application development, audit compliance, database management, infrastructure and network design, security risk and compliance management, and cloud solutions
- Partner with the BEST Team, SI, and product vendors, CTR and EOTSS to identify security requirements, using methods that may include risk and business impact assessments, including: provide operational support as defined by SLA requirements agreed to by the Commonwealth, the product vendor, and SI; implementation of Commonwealth IT policies related to user security and data security; work with the Commonwealth Risk Management Office in their assessments and recommended controls regarding data security and security operations; conduct additional business system analysis as needed; facilitate communication between users and vendors using issue management software; support development of the operational support playbook for "day 2" operations.
- Ensure the completion of information security operational documentation.
- Work with BEST information security leadership to develop strategies, procedures and recommended roles and responsibilities to enforce security requirements and address identified risks related to the use of the new solution.
- Perform configuration updates and execution role in application development and implementation related to security requirements and controls; ensure security controls are implemented as planned and security and access needs are addressed throughout the user life cycle.
- Participate in and support the data conversion of end users from the legacy system to the new system.
- Work with BEST, CTR's, and EOTSS' CSOs, CIOs, and the Commonwealth's Risk Management Office to identify, select and implement technical controls related to data security and to implement security processes and procedures that ensure security controls are managed and maintained both centrally through the new solution, and within agencies if certain security management tasks are decentralized.
- Advise the BEST Team, SI and product vendors regarding end user security roles and groups, data access controls and security role provisioning and de-provisioning protocols to ensure data are accessed appropriately in the new solution.
- Support the BEST Team and Commonwealth agencies in identifying approved end users of the new solution and coordinating provisioning of users for Day One go live.
- Support the definition and implementation of the security needs along with the BEST Security Workstream.
- Support the BEST Maintenance and Operations Workstream.
- Advise security administrators on normal and exception-based processing of security authorization requests, including the use of SI or product vendor provided tools that monitor system use and data access irregularities.
- Assist security administrators and IT staff in the resolution of reported security incidents.
- Act as a liaison between incident response leads and subject matter experts.
- Monitor daily or weekly reports and security logs for unusual events.
- Maintain an awareness of existing and proposed security-standard-setting groups, state and federal legislation and regulations pertaining to information security; identify regulatory changes that will affect information security policy, standards, and procedures, and recommend appropriate changes.
- Research and assess new threats and security alerts and recommend remedial actions.
- Support the implementation of the new solution's complete security profile, including but not limited to: Azure Active Directory (AD) entry; Single Sign-on (SSO) integration between EOTSS and Workday; New Solution User Security Role; New Solution User Workflow Role.
REQUIRED SKILLS
- Extensive experience providing operational security support to end users
- Experience working with modern issue tracking systems (JIRA)
- Understanding of enterprise security best practices, including IAM, RBAC, Network Security, SaaS, Cloud Security, Data Security, Encryption, and File transfer management
- In-depth exposure to defining and implementing end user security protocols in a large public or private sector entity comparable in size to the Commonwealth
- Exposure to technical configurations, technologies, and processing environments in one or more projects of similar size and complexity to BEST
- Understanding of information risk concepts and principles as a means of relating business needs to security controls
- Experience with common information security management frameworks, such as ISO 2700x, ITIL, COBIT, and NIST
- In-depth knowledge of risk assessment methods and technologies
- Understanding of Human Resource and Payroll systems security requirements
- Excellent technical knowledge of mainstream operating systems and a wide range of security technologies, such as network security appliances, identity and access management (IAM) systems, anti-malware solutions, automated policy compliance tools, and desktop security tools
- More than 3 years of experience in developing, documenting, and maintaining security policies, processes, procedures, and standards
- Knowledge of network infrastructure, including routers, switches, firewalls, and the associated network protocols and concepts
- Strong analytical skills to analyze security requirements and relate them to appropriate security controls
- Ability to interact with personnel at all levels and across all business units and organizations, and to comprehend business imperatives
- Excellent written and verbal communication skills
MINIMUM ENTRANCE REQUIREMENTS
- Bachelor's degree in computer science, system analysis or a related study, or equivalent experience in the field of audit compliance and security risk and compliance management
- Minimum of five years of implementation and operational experience in IT, with knowledge in the following technical disciplines: application development, audit compliance, database management, infrastructure and network design, security risk and compliance management, and cloud solutions
Flexible work from home options available.
Compensation: $80.00 - $95.00 per hour
ABOUT US
Volantsoft was founded in 2011 by Anil Yarlagadda . Right from the beginning, the company aimed at being a leading professional in the IT industry by serving clients from diverse backgrounds. By building on the trust of our clients we established long-term relationships with all our customers that we partnered with. In helping our clients achieve success after success through the software solutions we provided them, we were able to grow our own business to reach a new potential and expand our presence around the world.
We provide a broad gamut of services and solutions which go through continuous modernization so that we can provide the best solutions that technology has to offer to our clients. These services include cloud services, quality assurance, mobility solutions as well as Enterprise Application development and integration. We also provide consulting services to our clients. The superior quality of our services has helped our customers become high- performance businesses. With a global presence and an innovative team Volantsoft helps you make a difference in your industry.
In addition to empowering businesses, we also take pride in assisting the creative new brains in the industry by providing job-oriented training to those who aspire to be a part of the IT industry. All the trainees get a chance to work on real time projects which helps them explore the industry through realistic experiences. All our trainees display the same fervour of helping our clients since they work in a conducive environment that nurtures them to strongly innovate so that they can reflect the same efficiency once they complete their training.
The company’s mission and vision is a strong reflection of our values. We value being an ethically strong business which wants to spearhead success through change. We value integrity and reliability in our team which is one of the reasons why our customers find us dependable. Our team works to achieve excellence and shares a strong sense of respect for every individual we interact with. We believe that every company has its own learning curve and we nurture the growth of our clients which in turn helps us learn more.