Senior Information Security Analyst

Clearance Level
None
Category
Information Security
Location
Menands, New York
(Hybrid Workplace)
Key Skills For Success

DevOps

Information Security

Information Systems

Vulnerability Assessments

REQ#: RQ195225
Public Trust: None
Requisition Type: Regular
Your Impact

Own your opportunity to work alongside federal civilian agencies. Make an impact by providing services that help the government ensure the well being of U.S. citizens.

Job Description

Information Security Analyst Senior

Transform technology into opportunity as an Information Security Analyst Senior with GDIT. A career in enterprise IT means connecting and enhancing the systems that matter most. At GDIT you’ll be at the forefront of innovation and play a meaningful part in improving how agencies operate.

At GDIT, people are our differentiator. As an Information Security Analyst Senior you will help ensure today is safe and tomorrow is smarter. Our work depends on an Information Security Analyst Senior joining our team to support New York State Department of Heath Medicaid Management Information System activities at Riverview Center in Menands, NY.

As an Information Security Analyst Senior supporting the eMedNY CISO team, you will be trusted to work on developing technical solutions to a wide range of difficult problems. The successful candidate should have experience in or knowledge of regulatory compliance, NIST SP 800-53, Rev 4 and 5, Medicaid Management Information Systems, NYS, and CMS. Also required, a comprehensive understanding and wide application of technical principles, theories, and concepts related to information security, with particular focus on vulnerability management and an emphasis on effective security and compliance management of vulnerabilities and security patches. General knowledge of other related disciplines such as systems development, configuration management, change management, network security and asset management. Solutions are imaginative, thorough, practicable and consistent with organization objectives.

HOW AN INFORMATION SECURITY ANALYST SENIOR WILL MAKE AN IMPACT:

  • Review and document security and privacy controls, documenting plans of action and milestones, and performing security risk analyses.
  • Experience in policy, procedure and standards development and review, and experience in developing and reviewing System Security Plans (SSPs) and other security documentation.
  • Review development processes for Application Security best practices and review application artifacts in each environment. 
  • Provide application-scanning, penetration testing and programming/coding for security tooling and scripts.
  • Advise the development team on how to remediate vulnerabilities, perform application security best practices, and address application security vulnerabilities.
  • Experience in Governance Risk and Compliance (GRC)
  • Demonstrate flexibility and the ability to handle other areas of information security, including business continuity, operations security, cryptography, forensics, regulatory compliance, insider threat detection and mitigation, and physical security analysis (including facilities analysis, and security management). 
  • Validate system security requirements definition and analysis; establish system security designs; and implement security designs in hardware, software, data, and procedures.
  • Validate security requirements and perform system certification and accreditation planning and testing along with liaison activities.
  • Secure systems operations and maintenance.

WHAT YOU’LL NEED:

  • Education: Bachelor’s degree or equivalent in Computer Science, Mathematics, Engineering or a related discipline
  • Required Experience: Three or more years related experience in Information Assurance. Currently hold a security certification or obtain one within 12 months of hire.
  • Required Technical Skills: Familiarity with Qualys, GRC, Varonis, SIEM, Defender, Active Directory, Linux, and GitLab.
  • Required Skills and Abilities:
    • An understanding of Privacy and familiarity with the NIST 800-53 Privacy controls
    • Experience with Security Control families in NIST SP 800-53 or Centers for Medicaid and Medicare Services
    • Experience in DevSecOPS and Development in Agile environments
    • A working knowledge of container security
    • Familiarity with vulnerability assessment and scanning as well as other security tools, such as, Tenable Nessus, SAST, DAST
    • To work in a collaborative team environment as well as individually
    • Strong interpersonal and communication skills are required to communicate with customers, support personnel, application development personnel and management
    • Must be able to prioritize and multi-task
    • Ability to work with minimal supervision
  • Preferred Skills:
    • Experience with Galvanize GRC tools
    • Experience with Privacy
    • New York State Medicaid Management Information Systems experience preferred
    • Experience in Secure Systems Development Life Cycle
    • Ability to Script using Python or other scripting languages
    • Familiarity with JAVA
    • Working knowledge of OWASP
  • Preferred Certifications:
    • Security Certifications such as Information Systems Certification and Accreditation Professional (ISCAP) or INFOSEC Assessment Methodology Certification (IAM)
    • Certification as an ISSO
    • CISSP certification
Work Requirements
Years of Experience

3 + years of related experience

* may vary based on technical training, certification(s), or degree

Certification

Travel Required

None

Salary and Benefit Information

The likely salary range for this position is $83,429 - $111,550. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
View information about benefits and our total rewards program.

About Our Work

We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across over 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans