Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Project Security Lead

My3Tech

Role: Project Security Lead

Location: Remote (occasional travel to SD as required)

Type: W2 only

Duration: Long-term

Client: State of South Dakota

Position Summary:

My3Tech is seeking an experienced Project Security Lead to provide security leadership, governance, technical oversight, and security certification for the South Dakota Rural Health Data Atlas.

The Project Security Lead will be responsible for the security of the solution throughout the project lifecycle, including application development, Microsoft Azure configuration, data integration, identity and access management, testing, deployment, updates, vulnerability remediation, and production readiness.

The Project Security Lead will work closely with the South Dakota Department of Health, the South Dakota Bureau of Information and Technology, the Consultant Project Manager, Solution/Azure Architect, Data Engineering Team, Application Development Team, Quality Assurance resources, and other project stakeholders to ensure that security requirements are incorporated into the solution from design through operations.

The individual will also serve as My3Tech's designated security-certification authority for the project and will certify in writing that applicable deliverables satisfy required security controls prior to State acceptance or production deployment . This directly supports the RFP's Project Security Lead and Secure Product Development requirements.

Key Responsibilities

Security Governance and Certification

  • Serve as My3Tech's primary security lead for the Rural Health Data Atlas.
  • Certify in writing the security of each applicable project deliverable , consistent with State requirements.
  • Maintain responsibility for security of the application development, management, configuration, deployment, and update processes throughout the contract period.
  • Translate applicable State, Bureau of Information and Technology, contractual, regulatory, and project security requirements into actionable technical and operational controls.
  • Participate in project-status and governance meetings and provide security-status reporting, risks, decisions, findings, and required actions.
  • Recommend corrective actions or adjustments to deliverables, schedule, resources, or implementation activities when security requirements could affect project performance or State milestones.
  • Coordinate security-related decisions with the Consultant Project Manager, State stakeholders, and Bureau of Information and Technology representatives.

Secure Architecture and Microsoft Azure Oversight

  • Review solution, application, data, network, integration, and Microsoft Azure architecture for compliance with State security requirements.
  • Support security design and configuration of the State-owned Microsoft Azure environment .
  • Review environment separation, secure configuration, encryption, secrets management, logging, monitoring, network controls, and access pathways.
  • Verify that security-relevant configuration guidance, platform dependencies, and secure configuration requirements are documented.
  • Confirm that unsupported or prohibited technologies, components, libraries, hardware, or services are not introduced into the solution.
  • Review third-party and open-source components for security risk, known vulnerabilities, support status, and applicable licensing implications.

Identity and Access Management

  • Oversee implementation and validation of the State's identity and access-management requirements.
  • Ensure application authentication integrates with the State's Single Sign-On environment using OAuth 2.0 and OpenID Connect .
  • Support implementation and validation of:
    • Role-Based Access Control;
    • Multi-Factor Authentication;
    • least-privilege access;
    • administrator access;
    • public, authenticated, and restricted-user access;
    • user provisioning and de-provisioning;
    • session timeout and session termination requirements.
  • Review access requests for My3Tech personnel and subcontractor personnel and ensure access is limited to approved project responsibilities.

The RFP states that failure to meet the State's identity-management standard can result in rejection of the proposal, making this a critical responsibility for the role.

Data Security and Privacy

  • Support classification and protection of State data based on applicable State data-classification requirements.
  • Ensure appropriate safeguards are applied to public, sensitive, Personally Identifiable Information, Protected Health Information, and other regulated information, where applicable.
  • Review encryption controls for data at rest and in transit.
  • Ensure State data is used only for authorized project purposes.
  • Support secure handling, retention, sanitization, and disposal requirements.
  • Review data-access pathways, data transfers, secure file-transfer processes, and external data-source connections.
  • Support controls that preserve confidentiality, integrity, availability, and State ownership of project data.

API and Integration Security

  • Review security controls for Application Programming Interfaces, data integrations, external services, secure file transfers, and system-to-system communications.
  • Coordinate with the Solution/Azure Architect and Bureau of Information and Technology to ensure that required interfaces comply with the State's API Management requirements .
  • Validate authentication, authorization, logging, monitoring, throttling, and applicable API security policies.
  • Ensure no required production API bypasses the State's approved API Management layer.

The RFP requires system-to-system integrations and API traffic to use the State's API Management platform as the authoritative broker.

Secure Software Development

  • Incorporate security controls throughout the software-development lifecycle rather than treating security as a final pre-production activity.
  • Support secure coding practices and ensure development personnel receive appropriate secure-development training.
  • Review security architecture and security-design documentation.
  • Ensure source-code and configuration changes are maintained through approved source-control processes with appropriate authentication and auditability.
  • Coordinate use of static and dynamic software-security-analysis tools and dependency-scanning tools where applicable.
  • Review scan findings with security and development personnel and ensure remediation is appropriately prioritized and tracked.
  • Verify that application code contains no unnecessary, malicious, unsupported, or unauthorized components.

Vulnerability Management and Security Testing

  • Plan security scanning and remediation activities into the project schedule.
  • Coordinate with the State and Bureau of Information and Technology for required web application and network vulnerability scans .
  • Ensure appropriate non-production environments are available for State security testing.
  • Review findings related to the Open Worldwide Application Security Project Top Ten, Common Vulnerabilities and Exposures, Common Weakness Enumerations, configuration weaknesses, and other identified security risks.
  • Coordinate penetration testing and security validation, where applicable.
  • Assign and track vulnerability remediation actions.
  • Ensure corrective actions are retested and closure evidence is maintained.
  • Confirm that unresolved security issues that could prevent User Acceptance Testing or production deployment are addressed before advancement.

The RFP explicitly states that products failing State security requirements may be barred from User Acceptance Testing or production until issues are resolved to the State's satisfaction .

Security Incident and Threat Management

  • Establish and maintain project security-incident response, investigation, escalation, and reporting procedures.
  • Coordinate with My3Tech leadership, the Consultant Project Manager, and State/Bureau security stakeholders when credible threats or security incidents are identified.
  • Ensure security events, vulnerabilities, and incidents are appropriately logged, prioritized, investigated, remediated, and documented.
  • Support preservation of evidence, root-cause analysis, corrective actions, and post-incident review when required.
  • Ensure project procedures support applicable State notification requirements for security incidents.

Security Logging, Monitoring, and Auditability

  • Define security logging and monitoring requirements for the solution.
  • Verify that appropriate application, authentication, administration, integration, and security events are captured.
  • Support protection of audit logs from unauthorized modification.
  • Ensure security evidence is retained in accordance with applicable State and contractual requirements.
  • Provide security evidence and documentation required to support State reviews, audits, security assessments, and acceptance activities.

Artificial Intelligence Security and Compliance

Where Artificial Intelligence or Generative Artificial Intelligence is used in the solution or development lifecycle, the Project Security Lead will:

  • review proposed Artificial Intelligence functionality and tools for compliance with State requirements;
  • confirm disclosure of applicable Artificial Intelligence components;
  • assess data classification, privacy, security, residency, retention, logging, and access-control implications;
  • ensure State data is not used to train or tune Artificial Intelligence models unless explicitly authorized in writing;
  • review third-party Artificial Intelligence services for data sovereignty and security risk;
  • verify that applicable Artificial Intelligence functionality can be restricted or disabled when required; and
  • support auditability, human oversight, and security documentation.

The RFP applies its Artificial Intelligence requirements not only to embedded functionality but also to Artificial Intelligence used in the development and delivery of the solution .

Production Security Readiness

  • Participate in production-readiness and Go-Live/Cutover reviews.
  • Verify that required security controls have been implemented and validated before production deployment.
  • Confirm readiness of:
    • identity and access management;
    • vulnerability remediation;
    • logging and monitoring;
    • data protection;
    • API security;
    • security configuration;
    • incident-response procedures; and
    • operational security documentation.
  • Provide security-certification evidence required to support State production authorization.
  • Support post-launch monitoring and remediation during hypercare and Year 1 operations.

Primary Security Deliverables and Work Products

The Project Security Lead will develop, review, approve, or contribute to applicable security artifacts, including:

  • Written Security Certification for applicable deliverables
  • Security and Privacy Controls Package
  • Security Architecture Review
  • Azure Security Configuration
  • Secure Configuration Guidelines
  • Identity and Access Management Design
  • Role-Based Access Control Matrix
  • Security Risk Register
  • Vulnerability Scan Findings and Remediation Records
  • Penetration Testing Evidence
  • Security Test Results
  • Security Requirements Traceability
  • API and Integration Security Review
  • Third-Party/Open-Source Security Review
  • Logging and Monitoring Requirements
  • Security Incident and Escalation Procedures
  • Production Security Readiness Checklist
  • Go-Live Security Approval Evidence
  • Security Operations Documentation
  • Security Knowledge-Transfer Materials

Reporting Relationship

The Project Security Lead will coordinate daily with the Consultant Project Manager and relevant My3Tech Team technical leads.

In accordance with the RFP, the Project Security Lead will report security status, findings, risks, recommendations, and required decisions to the Agency Project Sponsor as part of project status meetings . When security matters arise, the Project Security Lead must be able to recommend amendments or changes affecting deliverables, schedule, resources, or budget.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related discipline, or equivalent relevant professional experience.
  • Demonstrated professional experience in information security, cybersecurity, application security, cloud security, or security architecture.
  • Experience securing cloud-based enterprise applications, preferably within Microsoft Azure.
  • Experience with secure software-development lifecycle practices.
  • Experience reviewing application, data, integration, API, and cloud architectures from a security perspective.
  • Knowledge of:
    • OAuth 2.0;
    • OpenID Connect;
    • Single Sign-On;
    • Multi-Factor Authentication;
    • Role-Based Access Control;
    • encryption;
    • secrets management;
    • audit logging;
    • vulnerability management;
    • secure configuration; and
    • incident response.
  • Experience coordinating vulnerability scanning, security testing, remediation, and retesting.
  • Understanding of the Open Worldwide Application Security Project Top Ten, Common Vulnerabilities and Exposures, and secure coding principles.
  • Ability to assess security findings and determine their effect on production readiness, State milestones, and project risk.
  • Strong written communication skills and the ability to prepare formal security certifications, findings, recommendations, and supporting evidence.
  • Ability to work effectively with State technical personnel, project managers, architects, developers, data engineers, testing teams, and business stakeholders.

Preferred Qualifications

The following are My3Tech-preferred qualifications and are not represented as mandatory RFP requirements :

  • 7+ years of progressive information-security or cybersecurity experience.
  • State, Local, and Education government technology experience.
  • Experience supporting healthcare, Medicaid, public health, social-services, or other regulated environments.
  • Microsoft Azure security experience.
  • Experience with government security assessments and production-authorization processes.
  • Familiarity with National Institute of Standards and Technology security frameworks and standards.
  • Familiarity with Health Insurance Portability and Accountability Act security requirements where applicable.
  • Relevant certifications such as:
    • Certified Information Systems Security Professional;
    • Certified Information Security Manager;
    • Certified Cloud Security Professional;
    • Microsoft Azure Security Engineer Associate; or
    • equivalent security certifications.

Background and Security Requirements

The Project Security Lead must comply with all applicable State security requirements, including required security acknowledgments and access controls.

Because this role may configure State-owned technology, access source code, or access protected State information, the individual must be prepared to undergo the State-required fingerprint-based background investigation . The RFP states that these investigations may require approximately two to four weeks , which should be accounted for in project planning.

Role Objective

The Project Security Lead will ensure that security is embedded throughout the Rural Health Data Atlas lifecycle-from architecture and development through testing, State acceptance, production deployment, and operations-and will provide the formal security accountability and written certification required by the State .

Primary success measure: the Atlas progresses through State security review, User Acceptance Testing, production readiness, and launch with required security controls implemented, documented, validated, and accepted.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Project Security Lead in Pierre, SD vacancy
  • $30 per hour

     ...environment. We meet and exceed each customer's security and compliance requirements, such as...  ...problems is desired. Experience as a project manager, or in a technical leadership...  ...all. Discover your potential at a company leading the way in AI and cloud solutions that impact... 
    Suggested
    Hourly pay
    Temporary work
    Internship
    Local area
    Flexible hours

    Oracle

    Pierre, SD
    4 days ago
  • $170k - $190k

     ...United States Suitability/Public Trust Fully remote Project/Program Management Overview GovCIO is currently hiring for a Lead, Enterprise Clinical Informatics & AI Programs to lead the execution and scaling of AI-enabled clinical informatics initiatives,... 
    Suggested
    Full time
    Currently hiring
    Work at office
    Remote work
    Flexible hours

    GovCIO

    Pierre, SD
    2 days ago
  • $85k

    **About the Role:** **As a CBRE Project Management Consultant, you will be responsible for providing consulting services to an assigned...  ...knowledge of several job disciplines within the function.** **· Lead by example and model behaviors that are consistent with CBRE RISE... 
    Suggested

    CBRE

    Pierre, SD
    4 days ago
  •  ...Hello We have an urgent requirement from our client Job Title: Project Director Location: Hybrid Duration: 6+months Client: State of SD Job Description: Must have: CCBHC Planning Job Titles # Project Director... 
    Suggested
    Remote work

    My3Tech Inc

    Pierre, SD
    1 day ago
  •  ...relocation assistance. Implementing software that saves lives. Join our Project Management team and drive impactful projects to improve patient...  ...the US (and abroad if you’re interested) as part of a team that leads software installations and ensures the success of newcomers to... 
    Suggested
    Work at office
    Relocation
    Visa sponsorship
    Relocation package

    Epic

    Pierre, SD
    4 days ago
  • $178.78k

     ...to offering an unmatched employee experience. Where you work on projects that are meaningful to you. Where you play an active part in shaping...  ...CDM Smith is seeking a Manager, Project Accounting, to lead and oversee the project accounting function for an assigned geographic... 
    Work experience placement
    H1b
    Work at office
    Remote work

    CDM Smith

    Pierre, SD
    4 days ago
  •  ...Job Description Now Hiring: Project Superintendent / Project Manager Midwest Construction is looking for an experienced Project Superintendent / Project Manager to lead residential and commercial construction projects from start to finish. Responsibilities: Oversee... 
    For subcontractor
    Immediate start
    Flexible hours

    Midwest Construction Inc.

    Pierre, SD
    4 days ago
  • $68k - $73.5k

     ...eligibility criteria. South Dakota Medicaid is seeking two highly qualified individuals to join our policy, projects, and reimbursement team. Duties may include: Leading policy and strategic project initiatives including federal grants management. Manage policy... 
    Full time
    Contract work
    Work at office
    Work from home
    Visa sponsorship
    Work visa

    South Dakota State Government

    Pierre, SD
    18 days ago
  •  ...founded to set a new standard in search, career placement and flexible staffing. Key Responsibilities Serve as Scrum Master and Agile Project Manager for two or more Agile delivery pods/ Scrum teams Guide and coach teams to self-organize, deliver business value, and... 
    Flexible hours

    Beacon Hill Staffing Group

    Pierre, SD
    2 days ago
  •  ...experience, preferably MedicaidExperience in managing or working on projects across multiple departments using an SDLC methodology and Agile...  ...and/or systems implementations or upgrades.Experience leading teams focusing on professional growth and development and organizational... 

    My3Tech

    Pierre, SD
    3 days ago
  • $56.8k - $71k

     ...Founded in 1990, WWT is a global technology solutions provider leading the AI and Digital Revolution. WWT combines the power of strategy...  ...teams? Join WWT today! Role Overview The Staffing Project Analyst (SPA) is responsible for supporting the financial and operational... 
    Hourly pay
    Full time

    World Wide Technology

    Pierre, SD
    15 hours ago
  •  ...Learn more at defisolutions.com and follow us on LinkedIn. About the Role: defi SOLUTIONS is seeking an experienced project manager for its Project Management Office. Candidates must have a strong, demonstrated history of executing successful project management... 
    Flexible hours

    defi AUTO LLC

    Pierre, SD
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Project Security Lead. Be the first to apply!