Haystack
← Back to Jobs
Technology
GI

On-Site Senior Certified Application Security Analyst (NIST SP 800-53/Cybersecurity/CSF controls/ Microsoft 365/Defender/Purview/ CISA/CRISC/CGRC/CISM/CISSP)

Global Information ServicesTallahassee, FL🇺🇸United StatesPosted Sep 29, 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Tallahassee, FL, United States
Posted
21 hours ago
HIPAAPowerShell

Job Description

Note : Please reply ONLY if you
1) Can work 100% on-site from day one. NO REMOTE option allowed
2) have all the Required skill set and have worked as an " On-Site Senior Certified Application Security Analyst (NIST SP 800-53/Cybersecurity/CSF controls/ Microsoft 365/Defender/Purview/ CISA/CRISC/CGRC/CISM/CISSP)  in a large & Complex enterprise level IT Environment.
3) Minimum of 13-15 years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, and database design and administration, including 7+ years of experience with information security, and knowledge of security issues, techniques, and implications across all existing computer platforms.
4) can provide at least 3 verifiable experience from completed and/or substantially completed jobs that closely match this request (Filling the client provided form) + fill out a skill Matrix + Sign Resume certification form
5) Can go through a background check including fingerprinting + Agree to a Face to face interview OR a WEB CAM Interview
6) A Competitive Rate
7) will be available Nov/Dec 2026 to start at the project.

s and those authorized to work in the US are encouraged to apply.  We are unable to sponsor H1b candidates at this time.
NOTE: GIS will utilize the U.S. Department of Homeland Security's E-Verify system to verify the employment eligibility of all persons employed during the term of the Contract
Note to Consulting Companies : ANY CONSULTANT’S RESUME YOU SEND ME “MUST” BE ON YOUR COMPANY’S PAYROLL, NO H1-VISA TRANSFER, NO PRO-MARKETING, NO SISTER COMPANY RESUMES.
The resume should have the DIRECT contact info and email of the candidate otherwise the candidate will NOT be considered.
ALL H1 candidates including those onWOULD need to provide I-797 + DL copy (no exceptions).

Each staff member assigned to this project must have a background screening that is equivalent to a Level Two (2) screening standard.
This is a fixed fee/hourly based project which is inclusive of travel, lodging, per diem expenses and all other costs associated with the completion of the associated tasks.

Interviews: 
In the event an interview is requested; 1st round interviews will be conducted via web Cam. The client may ask for 2nd round F-2-F and no expenses are paid
Telecommuting: 
Not allowed for this position.

Education: Bachelor’s degree in computer science, information systems, cybersecurity, or a related field, or equivalent work experience; and at least two current industry certification from the following (others may be considered):

BACKGROUND/OVERVIEW
The awarded Contractor must provide one experienced security professional with strong written-communication and documentation skills and demonstrated expertise spanning information security governance, risk, and compliance (GRC); security control framework implementation (NIST SP 800-53 and the NIST Cybersecurity Framework); the Florida Cybersecurity Standards (Rule 60GG-2, F.A.C.); and hands-on security operations within a Microsoft 365 environment.
The Department operates a Microsoft 365 G5 environment with Microsoft Defender deployed. The selected candidate will produce security and compliance work product that is subject to review, verification, and written acceptance by the Department’s Information Security Manager (ISM). The ISM retains responsibility for approval of all work product; the candidate performs the implementation, configuration, and documentation work under that review.

SCOPE OF WORK
4.1  The position is anticipated to be Full-Time contract position.
4.2. On an ongoing basis, the Senior Security & Compliance Analyst will report to the Department’s Information Security Manager (ISM), the designated Contract Manager. The candidate will work closely with the Office of Information Technology, the Office of General Counsel, and Department program areas, and may serve as a liaison with the Florida Digital Service and with solution providers/suppliers on security matters. All work products are subject to ISM review and approval. The candidate must demonstrate the following abilities for consideration:
4.2.1. Broad mastery of information security across governance and operations — able to both author policy and standards and perform the hands-on technical work to implement and validate controls.
4.2.2. Fluency in security control frameworks (NIST SP 800-53, NIST CSF) and the ability to map and crosswalk controls to the Florida Cybersecurity Standards (Rule 60GG-2, F.A.C.).
4.2.3. Risk-based judgment — able to assess control gaps, prioritize remediation, and document risk decisions for management review.
4.2.4. Clear technical writing — able to produce audit-ready policy, procedure, assessment, and management-response documentation.
4.2.5. Operational competence in a Microsoft 365 / Microsoft Defender environment, including endpoint security, vulnerability management, identity and access controls, and incident response support.
4.2.6. Ability to explain security risks, trade-offs, and remediation options to non-security stakeholders,
including executives and counsel.
4.3. The Senior Security & Compliance Analyst will provide, but not be limited to, the following activities and tasks.
4.3.1. Governance, Policy & Standards. The candidate will:
4.3.1.1. Draft, revise, and maintain Department information security policies and standards (including the 420-series), and establish and operate periodic review cycles.
4.3.1.2. Develop procedures supporting Department security policies consistent with Rule 60GG-2.002 and 60GG-2.003, F.A.C.
4.3.1.3. Develop and maintain control mappings and crosswalks among NIST SP 800-53, NIST CSF, and Rule 60GG-2, F.A.C.
4.3.1.4. Maintain documentation, version control, and review evidence sufficient to satisfy internal and external audit.
4.3.2. Risk Management & Assessment. The candidate will:
4.3.2.1. Conduct security risk assessments and control gap analyses against applicable frameworks.
4.3.2.2. Develop, track, and maintain Plans of Action and Milestones (POA&Ms) and corrective action plans.
4.3.2.3. Perform third-party / vendor security risk reviews, including review of vendor security documentation, contract security terms, and integration security (identity federation, per transaction attribution, and audit logging).
4.3.3. Security Operations & Engineering Support. The candidate will:
4.3.3.1. Support configuration, hardening, and monitoring within Microsoft 365 and Microsoft Defender (Defender for Endpoint, Defender Vulnerability Management, Microsoft Purview) consistent with Department standards.
4.3.3.2. Support vulnerability management: triage, tracking, and coordination of remediation.
4.3.3.3. Support incident response consistent with the Department’s Cybersecurity Incident Response Policy (420.01), including documentation and post-incident analysis.
4.3.3.4. Support identity and access management activities, including access reviews and provisioning integrity controls.
4.3.4. Audit, Compliance & Reporting. The candidate will:
4.3.4.1. Support response to Office of Inspector General (IG) and external audit findings, including evidence collection, control testing, and development of management responses.
4.3.4.2. Support compliance with the CJIS Security Policy and protection of PHI and other confidential information.
4.3.4.3. Develop security metrics, status reporting, and security awareness materials; support security governance meetings and working groups.
4.4. Contract Deliverables. The candidate shall provide evidence of performance through documentation including, but not limited to:
4.4.1. Drafted and revised security policies and standards, with documented periodic-review cycles.
4.4.2. Control mapping crosswalks (NIST SP 800-53 / NIST CSF / Rule 60GG-2, F.A.C.).
4.4.3. Security risk assessment reports and control gap analyses.
4.4.4. Plans of Action and Milestones (POA&Ms) and corrective action plans.
4.4.5. Third-party / vendor security review memoranda and diagnostic question sets.
4.4.6. Vulnerability management tracking and remediation status reports.
4.4.7. Incident documentation and post-incident (Root Cause Analysis) reports.
4.4.8. Audit evidence packages and draft management responses to IG / external findings.
4.4.9. Security metrics and periodic status reports.
4.4.10. Time Reports detailing tasks worked and hours spent each day, submitted to the Contract Manager no later than the 5th day of the following month via a mutually agreed timesheet.
4.4.11. Additional Documentation. Any additional documentation required by the Department’s Contract Manager, submitted within the timeframe specified by the Contract Manager.

QUALIFICATION REQUIREMENTS FOR SECURITY ANALYST
The Security Analyst candidate(s) submitted by Contractor to provide these staff augmentation services must possess the following minimum qualifications and experience:
Minimum of 13-15 years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, and database design and administration, including 7+ years of experience with information security, and knowledge of security issues, techniques, and implications across all existing computer platforms.
5.1.2. Minimum of seven (7) years across information security disciplines, with demonstrated experience in both security governance/compliance (GRC) and hands-on security operations.
5.1.3. Demonstrated experience drafting information security policy and standards and implementing NIST SP 800-53 and/or NIST CSF controls.
5.1.4. Demonstrated experience performing security risk assessments and supporting internal or external audits.
5.1.5. Hands-on Microsoft 365 G5, Microsoft Defender (Endpoint, Vulnerability Management), and Microsoft Purview experience.
5.1.6. Vulnerability management tooling and remediation-coordination experience.
5.1.7. Experience developing IAM / access-control standards and provisioning-integrity controls.
5.1.8. PowerShell or comparable scripting for security automation and reporting.
• Strong customer service orientation
• Ability to be creative, to use sound judgment, and to display foresight to identify potential problems and design/specifications and assigned application software systems
• Ability to establish and maintain effective working relationships with others.
• Ability to work independently
• Ability to determine work priorities and ensure proper completion of work assignments
• Excellent interpersonal, collaborative, oral and written communication skills
• Ability to write technical, business, and plain language documents and/or emails, with great attention to detail in all written communications
• Ability to work well under pressure and meet deadlines without sacrificing quality

Education and Certification. The candidate must possess, at a minimum, a Bachelor’s degree in computer science, information systems, cybersecurity, or a related field, or equivalent work experience; and at least One current industry certification from the following (others may be considered):
5.2.1. CISA — Certified Information Systems Auditor (strongly aligned to the GRC/audit core).
5.2.2. CRISC — Certified in Risk and Information Systems Control.
5.2.3. CGRC — Certified in Governance, Risk and Compliance (formerly CAP).
5.2.4. CISM — Certified Information Security Manager.
5.2.5. CISSP — Certified Information Systems Security Professional.

Preferred Qualifications. The following are preferred and will strengthen a candidate’s evaluation:
5.3.1. Florida state government or public-sector information security experience.
5.3.2. Working knowledge of Rule 60GG-2, F.A.C., and Section 282.318, Florida Statutes.
5.3.3. CJIS Security Policy implementation or audit experience.
5.3.4. HIPAA Security Rule and PHI-handling experience.
5.3.5.  Experience with MS Dynamics related Projects

Facilities and Equipment
The Department will provide items such as working facilities, development and testing environments, equipment and software licenses, access to the Department’s network, and internet connectivity, etc. Note: A Contractor Representative with access to the Department’s network is required to complete the Department’s security awareness training.  This training must be completed within fifteen (15) calendar days of the Contractor Representative’s start date.  If the Contractor Representative uses his or her own computer laptop, the equipment must undergo a security review by the Department to ensure it is free of software viruses and does not otherwise pose a security threat, prior to connection to the Department’s network.

"When replying please make sure to list your (All Inclusive) Compensation requirements !!!"

Note : This is a Full time ON SITE Contract Position with no REMOTE options allowed !!

Start date : Nov/Dec 2026
# OF POSITIONS : 1

No phone calls please.
Local Citizens are encouraged to Apply
No relocation assistance provided.
ONLY Candidates with an exact match will be contacted
Candidates should be authorized to work in the US.

Similar jobs