Cybersecurity Analyst Job at TechNix LLC, Colorado

M2hPc1U4a1I4V3BKUUMzSjFjNWtOTkZo
  • TechNix LLC
  • Colorado

Job Description

Position: Cybersecurity Analyst

Duration: 3 months with extension Possible

Remote Work

Job Description:

The Cyber Security Analyst III (CSA3)

within the State's Information Security Office (ISO) will be responsible for evaluating, analyzing, and assessing cybersecurity risks associated with new technologies, proposed solutions, and third-party vendors. This includes reviewing vendor security attestations, assessing architectural designs, validating security controls, and supporting statewide procurement decisions through structured risk assessments.

This role will also support the development and maturation of the State's Third-Party Risk Management (TPRM) program, including the enhancement and operation of tools such as Black Kite. Additionally, the CSA3 will assist with evaluating cybersecurity waiver submissions requiring deeper technical analysis and will help maintain the statewide risk register to ensure tracking and remediation of risks that exceed the State's risk tolerance.

KEY RESPONSIBILITIES:

  • New Technology & Solution Security Reviews:
  • Conduct security reviews for new technologies, cloud services, applications, and proposed solutions.
  • Review architectural diagrams to verify appropriate security controls, configurations, and data-protection mechanisms.
  • Assess alignment with State of Maine security requirements and applicable regulatory or compliance standards.
  • Develop and document risk assessments with actionable recommendations to support procurement and technology-adoption decisions.

Security Attestation & Third-Party Assessment:

  • Review and analyze third-party cybersecurity attestations, including SOC 2 Type II, ISO 27001 certifications, external penetration tests, and security questionnaires.
  • Identify control gaps, inherited risks, and areas requiring additional compensating controls.
  • Coordinate with procurement, legal, and business stakeholders during vendor onboarding and technology evaluation.

Third-Party Risk Management (TPRM) Program Support:

  • Assist in developing, enhancing, and maintaining the statewide TPRM program.
  • Leverage and operationalize TPRM tools, including Black Kite, to support ongoing monitoring, vendor tiering, and risk scoring.
  • Contribute to the creation of policies, processes, templates, and guidelines that mature the third-party risk-evaluation process.

Governance, Risk & Compliance (GRC) Platform Support (Archer IRM):

  • Utilize the Archer GRC platform to document risk assessments, waiver reviews, and remediation tracking activities.
  • Support the continued implementation and refinement of Archer workflows related to enterprise risk management.
  • Contribute to data quality, reporting accuracy, and process improvements to enhance risk visibility and governance maturity.

Waiver Review & Technical Risk Analysis:

  • Support the review of security waiver requests that require deeper technical analysis to evaluate risks of temporary control exceptions.
  • Document findings, risk impacts, and recommended mitigation strategies to inform risk acceptance decisions.

Risk Register Management & Remediation Tracking:

  • Assist in maintaining the statewide security risk register, ensuring risks are documented, categorized, and updated.
  • Track remediation progress and validate completion for risks that exceed established tolerance thresholds.
  • Collaborate with stakeholders to monitor deadlines, escalate overdue items, and verify mitigation plans remain effective.

MINIMUM QUALIFICATIONS:

  • Demonstrated experience in cybersecurity analysis, technology or architecture review, third-party or solution security evaluations, or related security-engineering activities.
  • Familiarity with cybersecurity standards, control frameworks, and risk-management practices applicable to government environments is strongly desired.

KNOWLEDGES, SKILLS, AND ABILITIES REQUIRED:

TOP SKILLS:

  • Strong understanding of cybersecurity principles, best practices, and control frameworks (e.g., NIST CSF, NIST 800-53).
  • Demonstrated ability to interpret SOC 2 Type II reports, ISO 27001 certifications, penetration test reports, and related third-party security documentation.
  • Familiarity with architectural review processes, cloud security concepts, and secure design principles.
  • Experience conducting third-party, vendor, or technology risk assessments and identifying compensating controls.
  • Experience supporting or operating within a Third-Party Risk Management (TPRM) program.

Additional Skills

  • Working knowledge of Governance, Risk, and Compliance (GRC) platforms (e.g., Archer or similar tools) is strongly preferred.
  • Experience leveraging third-party risk monitoring tools (e.g., Black Kite) or similar platforms is desirable.
  • Strong analytical, technical writing, and documentation skills with the ability to clearly communicate risk to both technical and non-technical stakeholders.
  • Ability to manage multiple concurrent assessments while meeting deadlines in a fast-paced environment.
  • Strong organizational skills, attention to detail, and sound professional judgment in evaluating and documenting risk.

Preferred Skills:

  • Working knowledge of Governance, Risk, and Compliance (GRC) platforms (e.g., Archer or similar tools).
  • Experience leveraging third-party risk monitoring tools (e.g., Black Kite).
  • Local, state, or federal government experience.

OPPORTUNITY TO DEVELOP IN THE POSITION BY GAINING:

  • Advanced expertise in technology-security review and third-party risk governance.
  • Hands-on experience building and maturing risk-management processes and tooling for a statewide cybersecurity program.
  • Exposure to procurement-related security evaluations and cross-department collaboration.

Job Tags

Temporary work, Work at office, Local area, Remote work

Similar Jobs

Charlotte Gastroenterology & Hepatology

Triage Clinical Assistant (RN/LPN/CMA/RMA)- Huntersville Office Job at Charlotte Gastroenterology & Hepatology

LOCATION:HuntersvilleSUPERVISION RECEIVED:Reports to Clinical Supervisor or Office ManagerSUPERVISION EXERCISED:NoneESSENTIAL FUNCTIONS:#Review and complete inbox tasks.#Address patient calls/portal in a timely manner.#Assess, address, triage patient issue ...

Hampton Roads International Montessori School

Non-profit Private School Administrator Job at Hampton Roads International Montessori School

 ...Summary Are you an Administrator or Business person who has experience with non-profit administration and facilities and enjoys working...  ...proft administration; who is experienced in working with private schools (Montessori is a great asset) Technology expertise is a plus.... 

Pediatric Developmental Services

School-Based Occupational Therapist Job at Pediatric Developmental Services

 ...Developmental Services (PDS) is seeking to hire a full-time Occupational Therapist . Do you enjoy working with children? Would you like to...  ...lives of children. Setting them up for success both in the school setting and beyond is meaningful work that builds a rewarding... 

Glitters and Grace Signature Mobile Parties & Perfume Bar, L...

Lead Party Hosts - Glitters and Grace Job at Glitters and Grace Signature Mobile Parties & Perfume Bar, L...

Lead Party Host - Glitters and Grace Glitters and Grace, a luxury mobile beauty and fragrance experience based in Chicagoland, is seeking Lead Party Hosts to represent our brand at highend events, bridal showers, weddings, bachelorette parties, corporate activations, and...

Covenant HealthCare

BILLER - UROLOGY Job at Covenant HealthCare

Overview: The biller is responsible for prompt and accurate billing and follow-up for all hospital and related professional services provided to patients covered by third party payers, including: Medicare, Medicaid, Blue Cross, Commercial, Workers Compensation and all ...