- Company Name
- Zolon Tech Inc.
- Job Title
- Security Analyst – Consultant
- Job Description
-
**Job Title**
Security Analyst – Consultant
**Role Summary**
Provide advanced cybersecurity consulting for enterprise systems, ensuring compliance with FISMA, NIST, HIPAA Security and Privacy, CMS MARS‑E. Conduct audits, assess security controls, and recommend mitigation strategies across IBM System/390, Windows, Linux, relational and non‑relational databases, networking, and web applications. Collaborate with business units, vendors, and cross‑functional teams to align technical solutions with organizational goals.
**Expectations**
* Deliver expert guidance on security architecture and compliance.
* Maintain up‑to‑date knowledge of regulatory frameworks and industry best practices.
* Manage multiple projects simultaneously, meeting deadlines in a dynamic environment.
* Communicate complex security concepts to diverse audiences, from technical staff to executive leadership.
**Key Responsibilities**
1. Lead security assessments and audits of IBM System/390, Windows, Linux, database, network, and web application environments.
2. Maintain and update security posture documentation, including policy, procedures, and control matrices.
3. Leverage eGRC platforms to track risk, incidents, and remediation progress.
4. Coordinate with SCDHHS OCS initiatives, vendors, and internal teams to implement corrective actions.
5. Produce detailed reports, presentations, and actionable recommendations for stakeholders.
6. Facilitate compliance with FISMA, NIST, HIPAA, and CMS MARS‑E standards.
7. Mentor junior staff and provide technical leadership on security projects.
**Required Skills**
- 5+ years IT experience auditing/applied security on IBM System/390, Windows, Linux, relational and non‑relational databases, networking, and web applications.
- In‑depth knowledge of FISMA, NIST, HIPAA Security & Privacy, CMS MARS‑E.
- Proven experience within a FISMA‑compliant program and using eGRC solutions.
- Health Information Technology domain knowledge.
- One or more certifications: ISC(2), ISACA, SANS GIAC (or equivalent).
- Strong analytical, problem‑solving, and project‑management skills.
- Proficiency with Microsoft Office (Word, Excel, PowerPoint, Visio); adept at template and branding consistency.
- Excellent communication and stakeholder engagement abilities.
**Required Education & Certifications**
- Certification: ISC(2), ISACA, SANS GIAC, or equivalent information security credential.
- Education: Bachelor’s degree in Computer Science, Information Security, or related field; or 10+ years of equivalent experience.
**Preferred Education & Certifications**
- Bachelor’s degree in a related discipline or 10+ years of field experience.
- ITIL experience in Information Security Management.