Senior IT Security Analyst at TalentBurst
Quincy, MA
About the Job
Title: Senior IT Security Analyst
Location: Quincy, MA (Hybrid)
Duration: 6 months contract
The primary work location for this role will be 100 Hancock Street, Quincy MA 02171. The work schedule for this position is Monday – Friday, 9:00 AM – 5:00 PM, with flexibility available and based on operational needs.
This position would be expected to follow a hybrid model of reporting to work that combines in-office workdays and work from home days as needed.
POSITION OVERVIEW:
EOHHS is seeking to hire a Senior IT Security Analyst to join our team supporting our Medicaid Management Information System (MMIS) team. The Senior IT Security Analyst will assist in identifying, deploying, and incorporating security controls into an MMIS system so that the controls become an integral part of its operational capabilities. Additional responsibilities include participation in efforts to select appropriate DevSecOps tools and security methods, assistance with annual security audits, and reporting and triaging detected security vulnerabilities with internal & external stakeholders to ensure timely remediation of issues.
DETAILED LIST OF JOB DUTIES AND RESPONSIBILITIES:
- Assist in efforts to implement a robust MMIS security posture as the MMIS system migrates to the AWS cloud datacenter and beyond.
- Work with the MMIS Security Lead and EOHHS and EOTSS enterprise security organizations to identify and remediate infrastructure and application code vulnerabilities and facilitate the operational process of continuous monitoring, remediation based on objective industry standards, measures of risk impact and probability, and reporting to stakeholders.
- Participate in efforts to integrate Static Application Security, Dynamic Application Security and Software Composition Analysis Tools (SAST, DAST & SCA) into MMIS Software Development Lifecycle (SDLC) emphasizing 'Shift Left” early detection and remediation of potential threats and vulnerabilities, and automation, and process integration.
- Participate in efforts to implement security standards and secure common frameworks.
- Participate in efforts to produce developer documentation and educational materials as well as create and update learning resources for application security.
- Participate in efforts to present and explain threat modelling; as well as institute risk detection and risk mitigation strategies to business and IT stakeholders (including leadership) and effectively defend recommendations, where necessary.
- Participate in efforts to define MMIS technical security software environment requirements.
QUALIFICATIONS: Preferred Skills and Abilities:
- Extensive hands-on experience with implementing security best practices for AWS cloud-hosted applications including the appropriate utilization of AWS security and monitoring tools and resources.
- Experience with DevOps practices and Continuous Integration/Continuous Development (CI/CD) using GitLab and pipelines.
- Experience with web and API development technologies.
- Knowledge of current development practices, including containerized applications, microservice architectures, serverless architectures, etc.
- Experience with Medicaid systems or in IT healthcare settings desired.
EDUCATION AND EXPERIENCE:
- Associate degree in Computer Science, Information Systems/Technology, Business Administration, or other related field, or equivalent work experience.
- Professional security certification: CompTIA Security+, AWS Security Specialty, (ISC)2 CCSP, GIAC GSEC or GWEB, or other similar credentials a plus.
- 3+ years of experience working in application and infrastructure security roles.
- Strong technical knowledge of internet security issues, cloud architectures, and threat landscape.
- Strong technical understanding of application and cloud security threats and vulnerabilities, including Common Vulnerabilities & Exposures (CVE), Common Weakness Enumeration (CWE), OWASP top 10, SANS top 25, etc.
- Extensive knowledge of and experience with security standards such as NIST- 800-53, FEDRamp, and ISO 27xxx.
- Strong understanding of AWS networking and security tools and resources.
- Strong technical knowledge of AWS security and network management tools and resources.
- Strong background in web application development and/or code auditing.
- Strong consensus building and interpersonal communications skills
- Strong analytical abilities.
- Strong writing and technical documentation skills.
#TB_EN