Job Description
Title: Senior Information Security GRC Analyst
Client: State of South
Carolina
Location:- Columbia, SC
Duration: 6+ Months
Job Description
Senior Information Security GRC
Analyst for an opportunity with our client based in Columbia, SC.
Work location: Fully remote. Some onsite work will be required.
Duration: 12 months, with the possibility of extension
Candidate location: Preference will be given to local candidates who can
come to the office as needed for client and departmental meetings, trainings,
and other onsite activities.
Scope of the project:
· Supporting agencies during their development of the information security program with direct tactical implementation assistance.
· Developing and tracking agency information security implementation plans.
· Interview administrators, managers, and third parties to aid in the development of program artifacts.
· Ensuring high-level assessments of agencies’ INFOSEC work to ensure progress is made.
· Providing high-level analysis of process and procedures work to ensure compliance with state standards.
Duties:
· Interviewing business and technical owners to determine policies and procedures used for each agency process.
· Developing and tracking INFOSEC implementation plan progress.
· Documenting information gathered during both interviews and
· Document reviews to assist with developing formal processes and procedures.
· Assessing agency documentation to ensure adequate approaches are used to comply with controls.
Required skills:
· 10+ years of experience in information security and compliance.
· 2+ years of experience with security audits based on a standard control set as an auditor or responding information system security officer.
· Must have a strong working knowledge of NIST 800-53 (2 years of experience).
· Prior experience with POA&M or CAP.
· Strong communication experience.
· Experience with using a GRC tool (Archer or similar) (3 years of experience).
· Bachelor's degree - field of study is open, but the degree must be complete and verifiable
Preferred skills:
· Have completed an information security plan or system security plan notebook.
· Simultaneously manage multiple infosec work efforts.
· Knowledge of IRS 1075, HIPAA, CJIS, MARS-E, and/or PCI-Agency.
· Government sector experience
· CISA, GSLC, or equivalent certification
Additional skills:
· Ability to identify, map, and re-engineer business processes.
· Strong schedule management and resource planning skills.
· Ability to work at a high volume and fast pace.
· Strong collaborator and strong ability to meet deadlines.
Thanks and Regards,
Ashish Kumar
Senior Technical Recruiter | Sibitalent Corp