iCST
Location
Augusta, GA | United States
Job description
Skill 1 Information Security
Skill 2 Project ManagementSkill 3 Communication and Stakeholder EngagementThe Cybersecurity Risk Analyst within the State's Information Security Office will be responsible for conducting in-depth risk assessments, aimedat identifying and evaluating threats to the state's information assets and business processes. This role also involves ensuring that all securitymeasures comply with regulatory standards and developing strategies to mitigate identified risks. A significant part of the duties includescollaborating with various teams to provide security recommendations and preparing detailed reports for stakeholders. The position demands staying current with advancements in information security, risk assessment methodologies, and regulatory frameworks to effectively apply thisknowledge in safeguarding state operations.Key ResponsibilitiesRisk Assessment and Analysis:" Conduct comprehensive information security risk assessments acrossvarious State of Maine agencies." Identify, assess, and measure risks in systems, applications, technicalenvironments, networks, and workflows." Clearly document vulnerabilities, including their potential impact,likelihood of exploitation, and affected areas." Prepare detailed risk assessment reports to guide management actionson identified risks.Risk Mitigation And Compliance" Compare current security measures against regulatory expectations andassess the effectiveness of security controls." Collaborate with stakeholders to develop mitigation plans to reduce risksto acceptable levels." Provide consultative advice for the development and implementation ofrisk response plans." Evaluate and recommend improvements in policies, processes, andstandards to bridge security gaps.Stakeholder Engagement And Program Development" Manage relationships with business partners and lead discussions oninformation security risks and mitigation strategies." Assist in the development and deployment of training materials topromote compliance and risk awareness." Contribute to the development of operational practices, procedures, andactivities supporting the Risk Management Program initiatives.Knowledges, Skills, And Abilities Required" Strong understanding of information security principles, concepts, andbest practices." Expertise in risk assessment processes for information technologysystems." Knowledge of security frameworks and standards (e.g., NISTCybersecurity Framework, CIS Controls)" Knowledge of Industry Compliance Standards (e.g., HIPAA, IRS Pub1075, CMS, PCI, CJIS, Social Security Administration)" Ability to analyze technical vulnerabilities and assess their impact onsecurity." Ability to create comprehensive risk assessment reports and presentfindings to stakeholders." Ability to manage risk assessment projects, set priorities, and meetdeadlines." Ability to make decisions, use discretion and display sound judgement." Effective written and oral communication skills." Ability to develop plans, policies, and procedures that meet regulatorycompliance requirements.MINIMUM QUALIFICATIONS: Demonstrated experience in riskmanagement, including the capability to effectively document and presentrisk assessment findings, proficiency in understanding and applyinginformation security principles, and knowledge of relevant laws and policiesJob tags
Salary