Duration: 18 months to start
Job Description
- The Technical Security Analyst will work for the Deputy Program Manager and Solution Technical Lead to support the adoption of the future state end user security solution and protocols. Together with the PMO and Phase 2 Technical Lead, Phase 2 Risk and Compliance Lead, Risk Management Team, Product Vendor, Systems Integrator (SI), and Office of the Comptroller staff to deploy technical controls to meet specific end-user security requirements, enable processes and standards to ensure that security configurations are maintained in the new Human Resource Management and Payroll solution.
- The Technical Security Analyst will be a part of the Technical Implementation team and work closely with the other members of the team to develop and implement a comprehensive information security program. This includes:
- Implementing security policies, processes and standards related to end user roles, data access for application users and how users will be provisioned and de-provisioned.
- Providing operational support for the team, product vendors, and CMW users.
- The Technical Security Analyst will work with the Team, agencies, and SI and product vendors to identify the end-user roles and permissions that will be needed to implement the new Human Resource Management and Payroll solution in multiple agencies and across multiple user types in a manner that ensures appropriate access.
- Procedures for rolling out user security will be developed in conjunction with the SI and product vendors, office of the comptroller, EOTSS, and agency staff currently responsible for provisioning and de-provisioning users to the application.
- Partner with the Team, SI, and product vendors to identify security requirements, using methods that may include risk and business impact assessments. Components of this activity include but are not limited to:
- Provide operational support as defined by SLA requirements agreed to by the client, the product vendor, and SI.
- Implementation of IT policies related to user security and data security.
- Work with the Risk Management Office in their assessments and recommended controls regarding data security and security operations.
- Conduct additional business system analysis as needed.
- Facilitate Communication between users and vendors using issue management software.
- Support development of the operational support playbook for “day 2” operations.
- Ensure the completion of information security operational documentation.
- Works with information security leadership to develop strategies, procedures and recommended roles and responsibilities to enforce security requirements and address identified risks related to the use of the new solution.
- Performs configuration updates and execution role in application development and implementation related to security requirements and controls, ensures that security controls are implemented as planned and that security and access needs are addressed throughout the User life cycle.
- Participates and supports the data conversion of end users from the legacy system to the new system.
- Works with the Risk Management Office to identify, select and implement technical controls related to data security and to implement security processes and procedures
- that ensure security controls are managed and maintained both centrally through the new solution, and within agencies if certain security management tasks are decentralized. • Advises the Team and SI and product vendors regarding end user security roles and groups, data access controls and security role provisioning and de-provisioning protocols to ensure that data are accessed appropriately in the new solution.
- Supports the Team and agencies in identifying approved end users of the new solution and coordinating provisioning of users for Day One go live.
- Supports the definition and implementation of the security needs along with the Security Workstream.
- Supports the Maintenance and Operations Workstream.
- Advises security administrators on normal and exception-based processing of security authorization requests including the use of SI or product vendor provided tools that monitor system use and data access irregularities.
- Assists security administrators and IT staff in the resolution of reported security incidents.
- Acts as a liaison between incident response leads and subject matter experts.
- Monitor daily or weekly reports and security logs for unusual events.
- Maintain an awareness of existing and proposed security-standard-setting groups, state and federal legislation and regulations pertaining to information security. Identifies regulatory changes that will affect information security policy, standards, and procedures, and recommends appropriate changes.
- Research and assess new threats and security alerts and recommend remedial actions.
- Support the implementation of new solution complete security profile, including, but not limited to:
- Azure Active Directory (AD) entry
- Single Sign-on (SSO) integration between EOTSS and Workday
- New Solution User Security Role
- New Solution User Workflow Role
- Extensive experience providing operational security support to end users
- Experience working with modern issue tracking systems (JIRA)
- Understanding of enterprise security best practices, including but not limited to IAM, RBAC, Network Security, SaaS, Cloud Security, Data Security, Encryption, and File transfer management.
- In depth exposure to defining and implementing end user security protocols in a large public or private sector entity comparable in size to the client.
- Exposure to technical configurations, technologies, and processing environments in one or more projects of similar size and complexity to the client.
- Understanding of information risk concepts and principles as a means of relating business needs to security controls.
- Experience with common information security management frameworks, such as [International Organization for Standardization (ISO) 2700x and the ITIL, COBIT and National Institute of Standards and Technology (NIST)] frameworks.
- In-depth knowledge of risk assessment methods and technologies.
- Understanding of Human Resource and Payroll systems security requirements.
- Excellent technical knowledge of mainstream operating systems and a wide range of security technologies, such as network security appliances, identity, and access management (IAM) systems, anti-malware solutions, automated policy compliance tools, and desktop security tools.
- More than 3 years of experience in developing, documenting, and maintaining security policies, processes, procedures, and standards.
- Knowledge of network infrastructure, including routers, switches, firewalls, and the associated network protocols and concepts.
- Strong analytical skills to analyze security requirements and relate them to appropriate security controls.
- Ability to interact with personnel at all levels and across all business units and organizations, and to comprehend business imperatives.
- Excellent written and verbal communication skills.
- Experience with Software-as-a-Service cloud implementations particularly those in which legacy on premise applications have been migrated to cloud delivery options.
- Demonstrated operational security support experience in a Software as a Service (SaaS) solution.
- Experience with WorkDay Human Resource and Payroll solution.
- Experience with WorkDay Prism data and reporting solution.
- Experience with WorkDay user security management as a member of a business (non-IT) team.
- Experience in transitioning traditional IT security functions to business teams.
- Exposure to operating end user security protocols, policies, and other in a large public or private sector entity comparable in size to the client.
- Audit, compliance, or governance experience is preferred.
- Experience with Audit, compliance, or governance actions.
- Experience with Microsoft security tools and functions
- Experience with Snowflake security functions
- Bachelor's degree in computer science, system analysis or a related study, or equivalent experience in the field of audit compliance and security risk and compliance management.
- Minimum of five years of implementation and operational experience in IT, with a knowledge in the following technical disciplines: application development, audit compliance, database management, infrastructure and network design, security risk and compliance management, and cloud solutions.




