We are GDIT. We support and secure some of the most complex government, defense, and intelligence projects across the country. At GDIT, cyber security is not just a singular part of our mission—it connects every one of us because it’s embedded into every aspect of what we do.
GDIT is your place. You make it your own by bringing your ideas and unique perspective to our culture. By owning your opportunity at GDIT, you are helping us ensure today is safe and tomorrow is smarter. Our work depends on an Information Security Analyst Expert joining our team to support New York State Department of Heath Medicaid Management Information System activities at Riverview Center in Menands, NY.
At GDIT, people are our differentiator. As an Information Security Analyst Expert supporting the eMedNY CISO team, you will be trusted to work on developing technical solutions to a wide range of difficult problems. The successful candidate should have experience in or knowledge of regulatory compliance, NIST SP 800-53, Medicaid Management Information Systems and CMS. Also required, a comprehensive understanding and wide application of technical principles, theories, and concepts related to information security, with particular focus on vulnerability management and an emphasis on effective security and compliance management of vulnerabilities and security patches. General knowledge of other related disciplines such as systems development, configuration management, change management, network security and asset management. Solutions are imaginative, thorough, practicable and consistent with organization objectives.
In this role, a typical day will include:
Reviewing and documenting security and privacy controls, documenting plans of action and milestones, and performing security risk analyses.
Experience in policy, procedure and standards development and review, and experience in developing and reviewing System Security Plans (SSPs) and other security documentation.
Reviewing development processes for Application Security best practices and review application artifacts in each environment.
Providing application-scanning, penetration testing and programming/coding for security tooling and scripts.
Advising the development team on how to remediate vulnerabilities, perform application security best practices, and address application security vulnerabilities.
Experience in Governance Risk and Compliance (GRC)
Demonstrating flexibility and the ability to handle other areas of information security, including business continuity, operations security, cryptography, forensics, regulatory compliance, insider threat detection and mitigation, and physical security analysis (including facilities analysis, and security management).
Validating system security requirements definition and analysis; establish system security designs; and implement security designs in hardware, software, data, and procedures.
Validating security requirements and perform system certification and accreditation planning and testing along with liaison activities.
Secure systems operations and maintenance.
WHAT YOU’LL NEED:
Bachelor’s degree or equivalent in Computer Science, Mathematics, Engineering or a related discipline, plus 15+ years related experience in Information Assurance. Currently hold a security certification or obtain one within 12 months of hire.
An understanding of Privacy and familiarity with the NIST 800-53 Privacy controls
Experience with Security Control families in NIST SP 800-53, Rev5 and Rev 5 or Centers for Medicaid and Medicare Services (CMS)
Experience in DevSecOPS and Development in Agile environments
A working knowledge of container security
Familiarity with vulnerability assessment and scanning as well as other security tools, such as, Tenable Nessus, SAST, DAST
To work in a collaborative team environment as well as individually. Must be able to prioritize and multi-task.
Strong interpersonal and communication skills are required to communicate with customers, support personnel, application development personnel and management
To exercise considerable latitude in determining technical objectives of assignment. Work is performed with minimal direction. Completed work is reviewed from a relatively long-term perspective for desired results.
Experience with Galvanize GRC tools
Experience with Privacy
Experience in Secure Systems Development Life Cycle
Ability to Script using Python or other scripting languages
Familiarity with JAVA
Working knowledge of OWASP
New York State Medicaid Management Information Systems experience preferred
Security Certifications such as Information Systems Certification and Accreditation Professional (ISCAP) or INFOSEC Assessment Methodology Certification (IAM
Certification as an ISSO
WHAT GDIT CAN OFFER YOU:
Full-flex work week
401K with company match
Internal mobility team dedicated to helping you own your career
Collaborative teams of highly motivated critical thinkers and innovators
About Our Work
We are GDIT. The people supporting some of the most complex government, defense, and intelligence projects across the country. We deliver. Bringing the expertise needed to understand and advance critical missions. We transform. Shifting the ways clients invest in, integrate, and innovate technology solutions. We ensure today is safe and tomorrow is smarter. We are there. On the ground, beside our clients, in the lab, and everywhere in between. Offering the technology transformations, strategy, and mission services needed to get the job done.
GDIT does not have a vaccination mandate applicable to all employees. To protect the health and safety of its employees and to comply with customer requirements, however, GDIT may require employees in certain positions to be fully vaccinated against COVID-19. Vaccination requirements will depend on the status of the federal contractor mandate and customer site requirements.
GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.