Negotiable
Outside
Hybrid
USA
Summary: DPP is seeking a Cloud Senior Security Risk Analyst to ensure the security and compliance of CMS's cloud infrastructure in Columbia, SC. The role involves hands-on work with Microsoft Azure, monitoring security events, and applying federal compliance standards. The Analyst will collaborate with engineering teams and conduct audits to strengthen security posture. This position is primarily onsite but open to remote arrangements.
Key Responsibilities:
- Hands-on work with key technologies to ensure security and compliance of CMS's cloud infrastructure.
- Review and administer security configurations, manage Azure Active Directory roles, and apply policies through Azure Policy and Security Center.
- Monitor and analyze security events using SIEM tools like Splunk or Microsoft Sentinel.
- Apply NIST 800-53 and FedRAMP controls by reviewing cloud architecture.
- Manage Identity and Access Management (IAM) by updating and auditing access permissions.
- Collaborate with engineering teams to integrate security into cloud deployments.
- Perform independent cloud information systems audits and evaluations.
Key Skills:
- Agile experience.
- Identity and Access Management (IAM).
- Proficiency with Splunk.
- Experience with Cloud Security tools associated with AWS and/or Microsoft Azure.
- Security and Compliance Frameworks (NIST 800-53, FedRAMP).
- Good understanding of Systems Development Life Cycle methodologies.
- Excellent analytical and decision-making skills.
- Strong communication skills in presenting results both verbally and in writing.
- Bachelor's degree in Computer Science, Information Technology, or other job-related degree.
Salary (Rate): undetermined
City: Columbia
Country: USA
Working Arrangements: hybrid
IR35 Status: outside IR35
Seniority Level: undetermined
Industry: IT
DPP is seeking a Cloud Senior Security Risk Analyst for an opportunity in Columbia, SC.
Work arrangement:
- Onsite highly preferred, but open to remote
- W2 position; 6 months
- Candidates who are foreign nationals must have resided in the US for at least three (3) of the last five (5) years prior to assignment to the client s applicable government contract.
Position summary:
- A typical day for a Cloud Senior Security Risk Analyst involves hands-on work with key technologies to ensure the security and compliance of CMS s cloud infrastructure.
- The Analyst actively uses Microsoft Azure to review and administer security configurations, manage Azure Active Directory roles, and apply policies through Azure Policy and Security Center.
- They regularly monitor and analyze security events using SIEM tools like Splunk or Microsoft Sentinel, investigating anomalies and escalating potential threats.
- The role also requires applying NIST 800-53 and FedRAMP controls by reviewing cloud architecture and ensuring that all systems meet federal compliance standards.
- Additionally, the Analyst manages Identity and Access Management (IAM) by updating and auditing access permissions, ensuring least-privilege principles are enforced.
- Their day often includes collaborating with engineering teams to integrate security into cloud deployments, supporting audits, and documenting risk mitigation strategies.
- They also perform independent, objective cloud information systems audits and evaluations, providing actionable recommendations to strengthen security posture and ensure regulatory compliance.
Required technologies:
- Agile experience
- Identity and Access Management (IAM)
- Proficiency with Splunk
- Experience with Cloud Security tools associated with AWS and/or Microsoft Azure
- Security and Compliance Frameworks (NIST 800-53, FedRAMP)
Nice to have:
- FedRAMP/NIST 800-53 Compliance Frameworks
- Familiarity with federal compliance standards, particularly FedRAMP and NIST 800-53, is crucial for aligning cloud security controls with CMS requirements.
Minimum required work experience:
- 6 years of I/T experience including 4 years of IT security, risk assessment and/or compliance experience.
- Successful completion of the client s I/S Entry Level Training Program (ELTP) may be substituted for 2 years of I/T experience.
Job/class description:
- Plan and perform compliance and risk assessment activities for information systems and related processes. Communicate and escalate compliance and risk issues to the appropriate department and/or level of management. Act as a change agent to influence the I/S and corporate compliance culture.
- Independently monitor remediation of new and outstanding issues, including Information Security Risk Exception process, to ensure identification of areas of non-compliance. Utilize tools to track and report on compliance posture.
- Independently conduct formal risk analysis and self-assessments to determine effectiveness of controls and ensure creation of action plans to remediate identified risks.
- Facilitate development, implementation and documentation of Information Security policies, procedures, processes and programs to guide organization toward continuous compliance. Independently analyze and interpret security regulations and controls to advise on security compliance at a broad perspective across multiple business areas. Consult on organizational impacts of compliance and risk management decisions.
- Serve as an interface with external entities for governance and compliance reviews regarding information security risk across multiple business areas and controls.
- Independently investigate, document and resolve Information Security Incidents. Advise senior management of critical issues that may affect organization.
- Research emerging security topics, threats and capabilities to create/update policy and governance. Promote organizational security awareness by developing security training, Security Council bulletins, security policies, standards and best practices.
Required knowledge, skills, and abilities:
- Good understanding of Systems Development Life Cycle methodologies.
- Subject Matter Expert in government or private risk frameworks and control implementations.
- Good understanding of risk management, information system security and compliance standards.
- Excellent analytical and decision-making skills.
- Proven ability to interpret and apply knowledge of regulatory/accreditation requirements.
- Ability to independently solve problems often spanning multiple environments and business areas.
- Ability to effect change and bring security, risk and compliance knowledge to the organization through the use of positive influence.
- Understanding of infrastructure and networking architecture WANs, LANs, Internet, intranets and communication protocols.
- Strong communication skills in presenting results both verbally and in writing.
- Possess excellent collaboration skills with a wide variety of internal matrix and management staff.
Required education/equivalencies:
- Bachelor s degree in Computer Science, Information Technology, or other job-related degree;
- OR, Associates degree in CS, IT, or other job-related degree plus 2 years of work-related experience;
- OR, 4 years job-related work experience (total 10 years without a degree)
Interested? Learn more: Authorized US Worker - s and those authorized to work in the US are encouraged to apply. We are unable to sponsor at this time. EOE/AA/V/D DPP offers a range of compensation and benefits packages to our employees and their eligible dependents. Call today to learn more about working with DPP.
Click the apply button or contact our recruiter Kenny at to learn more about this position (#25-00375).