Project Security Lead
My3Tech
Role: Project Security Lead
Location: Remote (occasional travel to SD as required)
Type: W2 only
Duration: Long-term
Client: State of South Dakota
Position Summary:
My3Tech is seeking an experienced Project Security Lead to provide security leadership, governance, technical oversight, and security certification for the South Dakota Rural Health Data Atlas.
The Project Security Lead will be responsible for the security of the solution throughout the project lifecycle, including application development, Microsoft Azure configuration, data integration, identity and access management, testing, deployment, updates, vulnerability remediation, and production readiness.
The Project Security Lead will work closely with the South Dakota Department of Health, the South Dakota Bureau of Information and Technology, the Consultant Project Manager, Solution/Azure Architect, Data Engineering Team, Application Development Team, Quality Assurance resources, and other project stakeholders to ensure that security requirements are incorporated into the solution from design through operations.
The individual will also serve as My3Tech's designated security-certification authority for the project and will certify in writing that applicable deliverables satisfy required security controls prior to State acceptance or production deployment . This directly supports the RFP's Project Security Lead and Secure Product Development requirements.
Key Responsibilities
Security Governance and Certification
- Serve as My3Tech's primary security lead for the Rural Health Data Atlas.
- Certify in writing the security of each applicable project deliverable , consistent with State requirements.
- Maintain responsibility for security of the application development, management, configuration, deployment, and update processes throughout the contract period.
- Translate applicable State, Bureau of Information and Technology, contractual, regulatory, and project security requirements into actionable technical and operational controls.
- Participate in project-status and governance meetings and provide security-status reporting, risks, decisions, findings, and required actions.
- Recommend corrective actions or adjustments to deliverables, schedule, resources, or implementation activities when security requirements could affect project performance or State milestones.
- Coordinate security-related decisions with the Consultant Project Manager, State stakeholders, and Bureau of Information and Technology representatives.
Secure Architecture and Microsoft Azure Oversight
- Review solution, application, data, network, integration, and Microsoft Azure architecture for compliance with State security requirements.
- Support security design and configuration of the State-owned Microsoft Azure environment .
- Review environment separation, secure configuration, encryption, secrets management, logging, monitoring, network controls, and access pathways.
- Verify that security-relevant configuration guidance, platform dependencies, and secure configuration requirements are documented.
- Confirm that unsupported or prohibited technologies, components, libraries, hardware, or services are not introduced into the solution.
- Review third-party and open-source components for security risk, known vulnerabilities, support status, and applicable licensing implications.
Identity and Access Management
- Oversee implementation and validation of the State's identity and access-management requirements.
- Ensure application authentication integrates with the State's Single Sign-On environment using OAuth 2.0 and OpenID Connect .
- Support implementation and validation of:
- Role-Based Access Control;
- Multi-Factor Authentication;
- least-privilege access;
- administrator access;
- public, authenticated, and restricted-user access;
- user provisioning and de-provisioning;
- session timeout and session termination requirements.
- Review access requests for My3Tech personnel and subcontractor personnel and ensure access is limited to approved project responsibilities.
The RFP states that failure to meet the State's identity-management standard can result in rejection of the proposal, making this a critical responsibility for the role.
Data Security and Privacy
- Support classification and protection of State data based on applicable State data-classification requirements.
- Ensure appropriate safeguards are applied to public, sensitive, Personally Identifiable Information, Protected Health Information, and other regulated information, where applicable.
- Review encryption controls for data at rest and in transit.
- Ensure State data is used only for authorized project purposes.
- Support secure handling, retention, sanitization, and disposal requirements.
- Review data-access pathways, data transfers, secure file-transfer processes, and external data-source connections.
- Support controls that preserve confidentiality, integrity, availability, and State ownership of project data.
API and Integration Security
- Review security controls for Application Programming Interfaces, data integrations, external services, secure file transfers, and system-to-system communications.
- Coordinate with the Solution/Azure Architect and Bureau of Information and Technology to ensure that required interfaces comply with the State's API Management requirements .
- Validate authentication, authorization, logging, monitoring, throttling, and applicable API security policies.
- Ensure no required production API bypasses the State's approved API Management layer.
The RFP requires system-to-system integrations and API traffic to use the State's API Management platform as the authoritative broker.
Secure Software Development
- Incorporate security controls throughout the software-development lifecycle rather than treating security as a final pre-production activity.
- Support secure coding practices and ensure development personnel receive appropriate secure-development training.
- Review security architecture and security-design documentation.
- Ensure source-code and configuration changes are maintained through approved source-control processes with appropriate authentication and auditability.
- Coordinate use of static and dynamic software-security-analysis tools and dependency-scanning tools where applicable.
- Review scan findings with security and development personnel and ensure remediation is appropriately prioritized and tracked.
- Verify that application code contains no unnecessary, malicious, unsupported, or unauthorized components.
Vulnerability Management and Security Testing
- Plan security scanning and remediation activities into the project schedule.
- Coordinate with the State and Bureau of Information and Technology for required web application and network vulnerability scans .
- Ensure appropriate non-production environments are available for State security testing.
- Review findings related to the Open Worldwide Application Security Project Top Ten, Common Vulnerabilities and Exposures, Common Weakness Enumerations, configuration weaknesses, and other identified security risks.
- Coordinate penetration testing and security validation, where applicable.
- Assign and track vulnerability remediation actions.
- Ensure corrective actions are retested and closure evidence is maintained.
- Confirm that unresolved security issues that could prevent User Acceptance Testing or production deployment are addressed before advancement.
The RFP explicitly states that products failing State security requirements may be barred from User Acceptance Testing or production until issues are resolved to the State's satisfaction .
Security Incident and Threat Management
- Establish and maintain project security-incident response, investigation, escalation, and reporting procedures.
- Coordinate with My3Tech leadership, the Consultant Project Manager, and State/Bureau security stakeholders when credible threats or security incidents are identified.
- Ensure security events, vulnerabilities, and incidents are appropriately logged, prioritized, investigated, remediated, and documented.
- Support preservation of evidence, root-cause analysis, corrective actions, and post-incident review when required.
- Ensure project procedures support applicable State notification requirements for security incidents.
Security Logging, Monitoring, and Auditability
- Define security logging and monitoring requirements for the solution.
- Verify that appropriate application, authentication, administration, integration, and security events are captured.
- Support protection of audit logs from unauthorized modification.
- Ensure security evidence is retained in accordance with applicable State and contractual requirements.
- Provide security evidence and documentation required to support State reviews, audits, security assessments, and acceptance activities.
Artificial Intelligence Security and Compliance
Where Artificial Intelligence or Generative Artificial Intelligence is used in the solution or development lifecycle, the Project Security Lead will:
- review proposed Artificial Intelligence functionality and tools for compliance with State requirements;
- confirm disclosure of applicable Artificial Intelligence components;
- assess data classification, privacy, security, residency, retention, logging, and access-control implications;
- ensure State data is not used to train or tune Artificial Intelligence models unless explicitly authorized in writing;
- review third-party Artificial Intelligence services for data sovereignty and security risk;
- verify that applicable Artificial Intelligence functionality can be restricted or disabled when required; and
- support auditability, human oversight, and security documentation.
The RFP applies its Artificial Intelligence requirements not only to embedded functionality but also to Artificial Intelligence used in the development and delivery of the solution .
Production Security Readiness
- Participate in production-readiness and Go-Live/Cutover reviews.
- Verify that required security controls have been implemented and validated before production deployment.
- Confirm readiness of:
- identity and access management;
- vulnerability remediation;
- logging and monitoring;
- data protection;
- API security;
- security configuration;
- incident-response procedures; and
- operational security documentation.
- Provide security-certification evidence required to support State production authorization.
- Support post-launch monitoring and remediation during hypercare and Year 1 operations.
Primary Security Deliverables and Work Products
The Project Security Lead will develop, review, approve, or contribute to applicable security artifacts, including:
- Written Security Certification for applicable deliverables
- Security and Privacy Controls Package
- Security Architecture Review
- Azure Security Configuration
- Secure Configuration Guidelines
- Identity and Access Management Design
- Role-Based Access Control Matrix
- Security Risk Register
- Vulnerability Scan Findings and Remediation Records
- Penetration Testing Evidence
- Security Test Results
- Security Requirements Traceability
- API and Integration Security Review
- Third-Party/Open-Source Security Review
- Logging and Monitoring Requirements
- Security Incident and Escalation Procedures
- Production Security Readiness Checklist
- Go-Live Security Approval Evidence
- Security Operations Documentation
- Security Knowledge-Transfer Materials
Reporting Relationship
The Project Security Lead will coordinate daily with the Consultant Project Manager and relevant My3Tech Team technical leads.
In accordance with the RFP, the Project Security Lead will report security status, findings, risks, recommendations, and required decisions to the Agency Project Sponsor as part of project status meetings . When security matters arise, the Project Security Lead must be able to recommend amendments or changes affecting deliverables, schedule, resources, or budget.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related discipline, or equivalent relevant professional experience.
- Demonstrated professional experience in information security, cybersecurity, application security, cloud security, or security architecture.
- Experience securing cloud-based enterprise applications, preferably within Microsoft Azure.
- Experience with secure software-development lifecycle practices.
- Experience reviewing application, data, integration, API, and cloud architectures from a security perspective.
- Knowledge of:
- OAuth 2.0;
- OpenID Connect;
- Single Sign-On;
- Multi-Factor Authentication;
- Role-Based Access Control;
- encryption;
- secrets management;
- audit logging;
- vulnerability management;
- secure configuration; and
- incident response.
- Experience coordinating vulnerability scanning, security testing, remediation, and retesting.
- Understanding of the Open Worldwide Application Security Project Top Ten, Common Vulnerabilities and Exposures, and secure coding principles.
- Ability to assess security findings and determine their effect on production readiness, State milestones, and project risk.
- Strong written communication skills and the ability to prepare formal security certifications, findings, recommendations, and supporting evidence.
- Ability to work effectively with State technical personnel, project managers, architects, developers, data engineers, testing teams, and business stakeholders.
Preferred Qualifications
The following are My3Tech-preferred qualifications and are not represented as mandatory RFP requirements :
- 7+ years of progressive information-security or cybersecurity experience.
- State, Local, and Education government technology experience.
- Experience supporting healthcare, Medicaid, public health, social-services, or other regulated environments.
- Microsoft Azure security experience.
- Experience with government security assessments and production-authorization processes.
- Familiarity with National Institute of Standards and Technology security frameworks and standards.
- Familiarity with Health Insurance Portability and Accountability Act security requirements where applicable.
- Relevant certifications such as:
- Certified Information Systems Security Professional;
- Certified Information Security Manager;
- Certified Cloud Security Professional;
- Microsoft Azure Security Engineer Associate; or
- equivalent security certifications.
Background and Security Requirements
The Project Security Lead must comply with all applicable State security requirements, including required security acknowledgments and access controls.
Because this role may configure State-owned technology, access source code, or access protected State information, the individual must be prepared to undergo the State-required fingerprint-based background investigation . The RFP states that these investigations may require approximately two to four weeks , which should be accounted for in project planning.
Role Objective
The Project Security Lead will ensure that security is embedded throughout the Rural Health Data Atlas lifecycle-from architecture and development through testing, State acceptance, production deployment, and operations-and will provide the formal security accountability and written certification required by the State .
Primary success measure: the Atlas progresses through State security review, User Acceptance Testing, production readiness, and launch with required security controls implemented, documented, validated, and accepted.
$30 per hour
...environment. We meet and exceed each customer's security and compliance requirements, such as... ...problems is desired. Experience as a project manager, or in a technical leadership... ...all. Discover your potential at a company leading the way in AI and cloud solutions that impact...SuggestedHourly payTemporary workInternshipLocal areaFlexible hours$170k - $190k
...United States Suitability/Public Trust Fully remote Project/Program Management Overview GovCIO is currently hiring for a Lead, Enterprise Clinical Informatics & AI Programs to lead the execution and scaling of AI-enabled clinical informatics initiatives,...SuggestedFull timeCurrently hiringWork at officeRemote workFlexible hours$85k
**About the Role:** **As a CBRE Project Management Consultant, you will be responsible for providing consulting services to an assigned... ...knowledge of several job disciplines within the function.** **· Lead by example and model behaviors that are consistent with CBRE RISE...Suggested- ...Hello We have an urgent requirement from our client Job Title: Project Director Location: Hybrid Duration: 6+months Client: State of SD Job Description: Must have: CCBHC Planning Job Titles # Project Director...SuggestedRemote work
- ...relocation assistance. Implementing software that saves lives. Join our Project Management team and drive impactful projects to improve patient... ...the US (and abroad if you’re interested) as part of a team that leads software installations and ensures the success of newcomers to...SuggestedWork at officeRelocationVisa sponsorshipRelocation package
$178.78k
...to offering an unmatched employee experience. Where you work on projects that are meaningful to you. Where you play an active part in shaping... ...CDM Smith is seeking a Manager, Project Accounting, to lead and oversee the project accounting function for an assigned geographic...Work experience placementH1bWork at officeRemote work- ...Job Description Now Hiring: Project Superintendent / Project Manager Midwest Construction is looking for an experienced Project Superintendent / Project Manager to lead residential and commercial construction projects from start to finish. Responsibilities: Oversee...For subcontractorImmediate startFlexible hours
$68k - $73.5k
...eligibility criteria. South Dakota Medicaid is seeking two highly qualified individuals to join our policy, projects, and reimbursement team. Duties may include: Leading policy and strategic project initiatives including federal grants management. Manage policy...Full timeContract workWork at officeWork from homeVisa sponsorshipWork visa- ...founded to set a new standard in search, career placement and flexible staffing. Key Responsibilities Serve as Scrum Master and Agile Project Manager for two or more Agile delivery pods/ Scrum teams Guide and coach teams to self-organize, deliver business value, and...Flexible hours
- ...experience, preferably MedicaidExperience in managing or working on projects across multiple departments using an SDLC methodology and Agile... ...and/or systems implementations or upgrades.Experience leading teams focusing on professional growth and development and organizational...
$56.8k - $71k
...Founded in 1990, WWT is a global technology solutions provider leading the AI and Digital Revolution. WWT combines the power of strategy... ...teams? Join WWT today! Role Overview The Staffing Project Analyst (SPA) is responsible for supporting the financial and operational...Hourly payFull time- ...Learn more at defisolutions.com and follow us on LinkedIn. About the Role: defi SOLUTIONS is seeking an experienced project manager for its Project Management Office. Candidates must have a strong, demonstrated history of executing successful project management...Flexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Project Security Lead. Be the first to apply!
- projects work from home Pierre, SD
- software implementation project manager Pierre, SD
- retail project merchandiser part time Pierre, SD
- project technician Pierre, SD
- special projects Pierre, SD
- project finance Pierre, SD
- projects Pierre, SD
- implementation project manager remote Pierre, SD
- project controls Pierre, SD
- senior implementation project manager Pierre, SD



