You will monitor and advise on information security issues to ensure internal IT security controls operate as intended.
Responsibilities
Assess the effectiveness of enterprise data security policies, processes, and controls against established standards to identify necessary improvements.
Perform gap analyses of security requirements within agency applications according to statutes, regulations, and state policies.
Provide guidance and standard interpretation of NIST controls and other regulatory requirements to agency staff.
Support the enterprise risk management process and assist with the State of Michigan risk assessment process.
Lead and mentor others within the Risk and Compliance Division as a subject matter expert.
Required Skills
6+ years of experience in IT security and audit.
Extensive knowledge of NIST, PCI, CJIS, CMS, ISO, SOX, HIPAA, and HITECH standards.
Experience performing security assessments and reviews.
Proficiency in risk management and gap analysis.
Ability to interpret security statutory and regulatory requirements.
Experience with enterprise risk management processes.
Preferred Skills
Experience working with Key light or Mi SAP risk assessment processes.