
Senior Associate, Information Privacy and Security
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Virginia.
• Assist the Texas Integrated Eligibility Redesign System customer Security Team in the implementation and upkeep of information security measures.
• Act as the primary liaison between the customer Security Team and support teams for coordinating responses to ARC-AMPE and other security audits.
• Acquire knowledge of ARC-AMPE security controls and their relevance to the customer environment.
• Oversee and manage audit responses within the Archer GRC system, ensuring timely submission tracking.
• Provide consultation to control responders regarding control interpretation, evidence requirements, and submission processes.
• Keep an eye on CISA and OEM security alerts, correlating notifications with the customer architecture.
• Relay relevant alert findings to the customer within a 48-hour window and provide consultation on cyber threat remediation strategies.
• Aid in implementing security measures to safeguard computer systems, networks, and data.
• Investigate and assess technologies aimed at preventing data loss and service disruptions.
• Help ensure networks are equipped with adequate protections against unauthorized access.
• Maintain documentation related to security systems and assist with updates following any software or hardware modifications.
• Support application security evaluations and prepare documentation for vulnerability and security assessments.
• Participate in project conference calls and security review meetings.
• Conduct research on emerging threats, vulnerabilities, and exploits, and communicate findings to stakeholders.
• Assist with NIST 800-37, NIST 800-53, ARC/AMPE controls, POA&Ms, and Corrective Action Plans.
• Contribute to Disaster Recovery, Business Continuity Plan, and Continuity of Operations documentation and evaluations.
• Create impact assessment reports for security incidents and aid in the development of remediation documentation.
• Develop and maintain standard operating procedure documents.
• Document security procedure violations and escalate findings as necessary.
• Engage with users to gather data access requirements and address routine security inquiries.
• A Bachelor’s degree with 2 years of relevant experience, or 6 years of experience with a high school diploma or equivalent.
• Knowledge of IT security policies, standards, and procedures.
• Basic understanding of business continuity and disaster recovery principles.
• Exposure to risk assessment processes or practices related to data processing security.
• Familiarity with common security tools and measures, including firewalls, data encryption, and access controls.
• Proficient in documenting security findings and assisting in the preparation of reports and recommendations.
• Excellent written and verbal communication skills; capable of articulating security concepts in simple terms.
• Competent in managing and tracking multiple stakeholder deliverables and deadlines in an organized manner.
• Comfortable working independently and directly with customer stakeholders.
• Must be a US Citizen or a Green Card Holder.
• Preferred: Completion of information security training such as CompTIA Security+ or an equivalent entry/mid-level certification.
• Preferred: Familiarity with NIST frameworks, ARC/AMPE controls, or federal/state security compliance requirements.
• Preferred: Experience in a government IT or state agency setting.
• Preferred: Experience with Archer GRC or a similar GRC platform.
• Preferred: Understanding of CISA alert monitoring, threat intelligence feeds, or OEM security notifications.
• Preferred: Experience in coordinating security audit responses or supporting compliance activities in a government IT environment.
• Potential eligibility for overtime.
• Potential eligibility for shift differential.
• Potential eligibility for a discretionary bonus.
NVIDIA
Soteria - Security Solutions & Advisory
BMO U.S.
Abnormal Security
Get handpicked remote jobs straight to your inbox weekly.