Job Description
Only local candidates should apply for this position. We are seeking an experienced Senior Security & Compliance Analyst to support enterprise information security governance, risk management, compliance, and security operations. The ideal candidate will have extensive experience implementing security frameworks, conducting risk assessments, developing security policies, supporting audits, and ensuring regulatory compliance. This role requires a strong balance of governance (GRC) expertise and hands-on security operations experience.
Required Qualifications: - Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field (or equivalent work experience).
- Minimum 7+ years of experience across information security disciplines.
- Minimum 4+ years of combined IT and information security experience with exposure to: Systems Analysis, Application Development, Database Design & Administration.
- 1 2+ years of dedicated information security experience.
- Strong experience in Security Governance, Risk, and Compliance (GRC) and hands-on security operations.
- Experience drafting and maintaining: Information Security Policies, Security Standards, Security Procedures.
- Hands-on experience implementing and assessing: NIST SP 800-53, NIST Cybersecurity Framework (CSF).
- Experience performing: Security Risk Assessments, Gap Assessments, Internal & External Audit Support, Compliance Reviews.
- Strong understanding of enterprise security controls and security best practices.
- Excellent communication, documentation, and stakeholder management skills.
Required Certifications: - Candidate must possess at least one of the following active certifications: CISSP Certified Information Systems Security Professional, CISM Certified Information Security Manager, CISA Certified Information Systems Auditor, CRISC Certified in Risk and Information Systems Control, CGRC (formerly CAP) Certified in Governance, Risk & Compliance.
Preferred Qualifications: - Experience supporting Florida State Government or Public Sector organizations.
- Knowledge of: Rule 60GG-2, Florida Administrative Code (F.A.C.) Section 282.318, Florida Statutes.
- Experience implementing or auditing: CJIS Security Policy, HIPAA Security Rule, Protected Health Information (PHI) compliance.
- Hands-on experience with: Microsoft 365 G5 Security, Microsoft Defender for Endpoint, Microsoft Defender Vulnerability Management, Microsoft Purview.
- Experience with: Vulnerability Management, Security Remediation Coordination, Identity & Access Management (IAM), Access Control Standards, Provisioning & User Access Governance, PowerShell or similar scripting language for security automation and reporting.
Key Responsibilities: - Develop, maintain, and enforce enterprise information security policies, standards, and procedures.
- Implement and assess security controls based on NIST SP 800-53 and NIST CSF.
- Conduct enterprise security risk assessments and recommend mitigation strategies.
- Support internal, external, and regulatory security audits.
- Monitor compliance with organizational security policies and regulatory requirements.
- Coordinate vulnerability remediation activities with infrastructure and application teams.
- Develop IAM standards and access governance processes.
- Support Microsoft security technologies, including Microsoft Defender and Microsoft Purview.
- Automate security reporting and operational tasks using PowerShell or similar scripting tools.
- Collaborate with cross-functional teams to strengthen the organization's security posture.
- Prepare executive reports, compliance documentation, and audit evidence.
Technical Skills: - Information Security Governance (GRC)
- Risk Assessment & Risk Management
- NIST SP 800-53
- NIST Cybersecurity Framework (CSF)
- Security Policies & Standards
- Audit & Compliance
- Vulnerability Management
- Microsoft 365 Security
- Microsoft Defender Suite
- Microsoft Purview
- Identity & Access Management (IAM)
- Access Control
- PowerShell
- Security Operations
- Security Documentation
For applications and inquiries, contact:hirings@openkyber.com
Job Tags
Work experience placement, Local area