IT Security & Compliance Specialist II
$87.62k - $117kNorth Carolina
IT Security & Compliance Specialist II (NS)
The Application Security Penetration Tester is responsible for identifying, analyzing, and mitigating vulnerabilities in software applications and APIs throughout the development lifecycle. This role collaborates closely with development and infrastructure teams to integrate secure coding practices and ensure the security of application from design through deployment. The Application Penetration Tester is responsible to perform deep, manual and automated security assessments of NCDHHS applications. This role goes beyond automated scanning- you will chain vulnerabilities, bypass controls, and emulate real adversary behavior across web apps, APIs, and mobile platforms.
Salary Grade Range: $87,617.00 - $117,000.00
Recruitment Range: $87,617.00 - $117,000.00
Candidates now meet the minimum qualifications of a position if they meet the minimum education and experience listed on the vacancy announcement. The Knowledge, Skills, and Abilities (KSAs)/ Management Preferences are not required. Applicants who possess the following skills are preferred:
- Hands-on experience performing manual penetration testing of web applications, REST and GraphQL APIs, and mobile applications, including static application security testing (SAST), dynamic application security testing (DAST), and threat modeling.
- Skilled in identifying, exploiting, validating, and documenting security vulnerabilities, including SQL Injection (SQLi), Cross-Site Scripting (XSS), Server Side Request Forgery (SSRF), authentication and authorization flaws.
- Proficient in conduction both manual and automated security assessment using industry-standard tools such as burp suite, OWASP ZAP, Nmap, Metasploit, Nessus, Snyk, Veracode and Checkmarx.
- Experience in collaborating with software developers to triage, prioritize, and remediate security findings, while working closely with DevOps and engineering teams to ensure secure application design, configuration, and deployment.
- Assisted in integrating security controls, automated testing, and vulnerability scanning into CI/CD pipelines to secure software development practices and DevSecOps initiatives.
- Produced comprehensive technical assessment reports containing detailed proof-of-concept (PoC) exploits, reproducible attack scenarios.
The posting will close at 11:59 P.M. the night before the end date. This position is funded in part through federal funds. This role is eligible to be hybrid and requires onsite reporting located within Raleigh, NC.
About the NC DHHS Information Technology Division:
In collaboration with our partners, the North Carolina Department of Health and Human Services (DHHS) protects the health and safety of all North Carolinians and provides essential health and human services. The IT division (ITD) is one of the divisions that report to the Operational Excellence portfolio. The ITD division comprises four sections: Implementation and Operations, Strategy and Workforce, Enterprise Technology, and Vendor and Finance. ITD offers the following services but not limited to implementations, operations, project/portfolio management, infrastructure, consulting, business division liaison, digital transformation, IT strategy, enterprise technology, IT contract and vendor management, and data office services.
Compensation and Benefits:
The State of North Carolina offers excellent comprehensive benefits. Employees can participate in health insurance options, standard and supplemental retirement plans, and the NCFlex program (numerous high-quality, low-cost benefits on a pre-tax basis). Employees also receive paid vacation, sick, and community service leave. In addition, paid parental leave is available to eligible employees. Visit the website for State Benefits.
Application Process
- Information should be provided in the appropriate areas, to include the following: Education, including high school and all degrees obtained, Work Experience, and Certificates & Licenses. It is critical to our screening and salary determination process that applications contain comprehensive candidate information.
- Answers to Supplemental Questions are not a substitute for providing all relevant information within the body of your application. To receive credit for the supplemental questions, you must provide supporting information within the "Work Experience" section of the application to support your answers.
- If multiple applications are submitted to an individual posting, only the most recent application received prior to the closing date will be accepted. Applications must be submitted by 11:59 PM on the closing date.
- Applicants may be subject to a criminal background check. All candidates selected for positions considered "Positions of Trust" will be subject to a criminal background check.
- Due to the volume of applications received, we are unable to provide information regarding the status of your application over the phone. To check the status of your application, please log in to your account. Upon the closing date, applications are "Under Review" and will be screened by Human Resources for qualified applicants. The hiring process may take several weeks.
- Degrees must be received from appropriately accredited institutions. Transcripts and degree evaluations may be uploaded with your application. The State of North Carolina/Office of State Human Resources uses the National Association of Credential Evaluation Services (NACES) as a referral resource for applicants who need to have their credentials certified as equivalent.
- For a list of organizations that perform this specialized service, please visit the NACES membership website at
Degree/College Credit Verification
Degrees must be received from appropriately accredited institutions. Transcripts, degree evaluations, and cover letters may be uploaded with your application.
Veterans' and National Guard Preference
- Applicants seeking Veteran's Preference must attach a DD-214 Member-4 Form (Certificate of Release or Discharge from Active Duty) to their applications.
- Applicants seeking National Guard Preference must attach an NGB 23A (RPAS), along with the state application, if they are a current member of the NC National Guard in good standing.
- Applicants who are former members of either the NC Army National Guard or the NC Air National Guard, with honorable discharge and six years of creditable service, must attach a copy of the DD 256 or NGB 22, along with the state application.
ADA Accommodations
Consistent with the Americans with Disabilities Act (ADA) and the Pregnant Workers Fairness Act (PWFA), DHHS is committed to the full inclusion of all qualified individuals. As part of this commitment, DHHS will ensure that people with disabilities, or known limitations covered by the PWFA, are provided with reasonable accommodation. If reasonable accommodation is needed to participate in the job application or interview process, please contact the person indicated below.
CONTACT INFORMATION:
If there are any questions about this posting, please contact Talent Acquisition at View email address on click.appcast.io. Resumes will not be accepted in lieu of completing this application.
Minimum Education and Experience
Some state job postings say you can qualify by an "equivalent combination of education and experience." If that language appears below, then you may qualify through EITHER years of education OR years of directly related experience, OR a combination of both. See the Education and Experience Equivalency Guide for details.
Bachelor's degree in computer science or a related IT field or related degree from an appropriately accredited institution and two years of progressive experience in IT Security or closely related area;
OR
Associate degree in computer science or a related IT field or related degree from an appropriately accredited institution and three years of progressive experience in IT Security or closely related area;
OR
An equivalent combination of education and experience.
EEO Statement
The State of North Carolina is an Equal Employment Opportunity Employer and dedicated to providing employees with a work environment free from all forms of unlawful employment discrimination, harassment, or retaliation. The state provides reasonable accommodation to employees and applicants with disabilities; known limitations related to pregnancy, childbirth, or related medical conditions; and for religious beliefs, observances, and practices.
Recruiter:
Dejah Victoria Seksay
Recruiter Email:
- ...community-focused credit union in North Carolina is seeking a Cyber Security Analyst II to enhance its cybersecurity posture. The role involves... ..., analyzing security incidents, and collaborating with IT teams. Ideal candidates will have a HS Diploma, relevant certifications...Suggested
- Join to apply for the Cyber Security Analyst II role at SECU Join to apply for the Cyber Security... ...incidents, and collaborating with other IT and security teams to ensure effective... ...0.00-$425,500.00 2 weeks ago Technical Specialist- Senior (Epic Security Analyst) We’re unlocking...Suggested16 hoursFull timeInternshipWork from home
- ...education and professional development. Summary Of The Role We are looking for an experienced and dynamic Permitting & Regulatory Compliance Specialist II to join our growing team. In this role you will independently manage a defined caseload of permitting and compliance...SuggestedWork at officeImmediate startRemote workFlexible hours
- ...Technology Consultant II | Procurement Assistance and IT Research, Advisory, and Consulting ProSidian Seeks a Technology Consultant II | Procurement... ...who's authority authority is managing purchasing, compliance, facilities, surplus, and advocacy services statewide. Seeking...SuggestedFull timeContract workH1bWork at officeFlexible hours
- City/StateNorfolk, VAWork ShiftFirst (Days)Overview:Sentara Health Plan is currently hiring a Provider Credentialing Specialist II - Remote!Status: Full-time, permanent position (40 hours)Work hours: 8am to 5pm EST, M-FLocation: Remote opportunities available in the following...SuggestedPermanent employmentFull timeTemporary workWork experience placementCurrently hiringRemote workShift work
- SECU is seeking an IT GRC Analyst II to assess, test, document, and monitor the technology ecosystem to ensure the IT control environment... ...and work with risk owners and auditors. Minimum 5 years of IT security or IT risk management experience is expected. #J-18808-...
- SECU seeks an IT GRC Analyst II to assess, test, document, and monitor the technology ecosystem, ensuring the IT control environment mitigates risks amid a changing threat landscape. The role requires bridging tech and business, with capability to perform risk assessments...
- ...People Helping People,\" join our team! Position Overview: The IT GRC Analyst II assess, tests, documents, and monitors the SECU technology... ...skills - both written and verbal. 5 years of IT Security and/or IT Risk Management experience working in a mid-to-large...
$75.82k - $90k
Agency Department of Information Technology Division DIT Secretary , CIO Job Classification Title IT Security & Compliance Specialist I (NS) Position Number 65041630 Grade DT08 About Us The N.C. Department of Information Technology (NCDIT) serves as the Technology Center...Permanent employmentInternshipLocal areaImmediate startRemote work- Trillium Health Resources is seeking a Systems Engineer II to administer, maintain, and support our enterprise IT infrastructure, including network, server, storage, and data environments. The role ensures reliable, secure operations and partners with stakeholders to meet...Remote job
- Sentara Health Plan is hiring a Provider Credentialing Specialist II - Remote. The role performs credentialing and re-credentialing processing for a managed care organization, ensuring compliance with NCQA and state/federal regulations. Remote opportunities are available...Remote jobMonday to Friday
- ..., procedures, standards, and compliance items. May assists network architecture... ...Network Engineer, II Location: Raleigh, NC Description... ...and distribution layer security measures. • Take an active... ...• CISCO IP Telephony Design Specialist • CISCO IP Communications...Permanent employment
$110.7k - $218.3k
...Recruiting for this role ends on 12/31/2026.Work you'll doAs a Security Engineer II on the Cyber Defense & Resilience Continuous Threat... ...to provide clear guidance to othersThe teamDeloitte’s Cyber Specialists help organizations manage cyber risk through stronger security...Local area- ...InsuranceDivisionAdministrationJob Classification TitleInsurance Regulatory Analyst II (NS)Position Number60013620GradeNC19About UsThe mission of the... ...data, the proper application of rating principles, and compliance with statutes and departmental regulations Their work includes...Work experience placementWork at officeRemote workFlexible hours
$134.5k - $265.1k
...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Position... ...connectors for PIP integration.• Must have strong knowledge of ensuring compliance with internal and external regulations, including SOX, GDPR,...Local areaVisa sponsorship$155.6k - $306.8k
...31/2026.Work you'll doAs an Engineering Manager II on the Cyber Defense & Resilience Continuous Threat... ...guidance to othersThe teamDeloitte’s Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices...Local area$134.5k - $265.1k
...clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll doAs an Engineering Manager II on the Deloitte Cyber team, you will be responsible for:Leading the design and delivery...Local areaVisa sponsorship- ...Security Specialist Location: Raleigh NC 27601 Duration: Long Term The Compliance Officer will be familiar with risk management, comfortable leading internal risk assessments, and possess knowledge of HIPAA and NIST privacy and security requirements for health...Full timeRemote work
- ...IT Security Specialist The NC Department of Health and Human Services seeks a highly experienced IT Security Specialist to manage, assist and assess NCFAST compliance with CMS, USDA, ACF, State of NC and DHHS requirements. This resource must manage and review the RFP...
- Perform SOX IT and cybersecurity compliance testing. Identify and assess Truist’s Corporate cybersecurity legal, regulatory and industry compliance... ...and track the cyber program maturity, serving as a security advisor to business segments and functions. This position...Full timePart timeWork at officeShift workDay shift
$35 per hour
...Job Title: Telecommunications Specialist Location: Raleigh, NC Onsite Duration: 6+ Months Rate: Up to $35.00/hr BOE Public... .... Failure to provide results in a timely manner may delay the security clearance process. • Adherence to a business casual dress code...Permanent employmentContract workFor contractorsCasual workRemote workMonday to FridayFlexible hoursNight shiftWeekend workDay shift- Truist is seeking a data-focused analyst to support regulatory reporting for FRY 9C and Call Reports. The role emphasizes governance, data quality, and accurate delivery of regulatory data to reporting teams in a highly regulated environment. The position requires a strong...
- The Truist Financial Corporation is seeking a data-focused Analyst to join the Finance Regulatory Data team, supporting FRY 9C and Call Reports. The role emphasizes data governance, data quality, and accurate delivery to regulatory bodies. Responsibilities include maintaining...
- ...dependencies across stakeholders. Enterprise Resilience Officer II is a subject matter expert responsible for the development, implementation... ...intelligence & tools. Supports enterprise and business unit compliance with all federal regulations (FFIEC) for BC/DR related planning,...Permanent employmentTemporary workH1bWork at officeWork visaShift workDay shift
- ...Raleigh or Charlotte office***• This team uses automated API security tools like Akamai, Salt Security and ReadyAPI tools to identify... ...area of responsibility, helping maintain regulatory and policy compliance.Shares knowledge and best practices with technical teammates,...Full timePart timeWork at officeShift workDay shift
- ...looking for builders, problem-solvers, and security professionals who thrive in a fast-... ...evidence to support regulatory, audit, and compliance requirements.Offensive Security... ...Directory Penetration Tester, Web Exploitation Specialist, Web Exploitation Expert, Offensive AI...Permanent employmentFull timePart timeH1bWork visaShift workDay shift
$134.5k - $265.1k
...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll... ...rationalization, remediation, renewal automation, and compliance monitoring programsStrong client leadership skills, including executive...Local area$134.5k - $265.1k
...with leading organizations to strengthen security, enable innovation, and reduce threat exposure... ...Work you'll do As an Engineering Manager II on the Cyber Defense & Resilience... ...guidance to others The team Deloitte’s Cyber Specialists help organizations manage cyber risk...Local area- ...Implement and maintain encryption, CSfC, secure network configurations, RMF documentation... ...vulnerability remediation, and security compliance artifacts Engineer monitoring, telemetry... ...GAN programs as a Principal Communications/IT Engineer or equivalent senior technical...
- ...will design, integrate, operate, and optimize SATCOM/baseband, ground gateways, and enterprise transport networks, while leading security, RMF/STIGs, and incident response efforts. Collaborate with TSOs, NOCs, cybersecurity, and program leadership to deliver resilient...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Security & Compliance Specialist II. Be the first to apply!
- cyber security analyst Raleigh, NC
- remote cyber security analyst Raleigh, NC
- information security consultant Raleigh, NC
- entry level cyber security analyst Raleigh, NC
- regulatory compliance analyst Raleigh, NC
- medicare compliance specialist Raleigh, NC
- regulatory analyst Raleigh, NC
- senior compliance officer Raleigh, NC
- legal compliance officer Raleigh, NC
- senior compliance analyst Raleigh, NC

