Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior security compliance analyst

$65 - $85 per hour

Randstad

job summary:
SCOPE OF WORK

The candidate will work closely with the Office of Information Technology, the Office of General Counsel, and Department program areas, and may serve as a liaison with the Florida Digital Service and with solution providers/suppliers on security matters. All work products are subject to ISM review and approval as described in Section 4.6.

The candidate must demonstrate the following abilities for consideration:

Broad mastery of information security across governance and operations - able to both author policy and standards and perform the hands-on technical work to implement and validate controls. Fluency in security control frameworks (NIST SP 800-53, NIST CSF) and the ability to map and crosswalk controls to the Florida Cybersecurity Standards (Rule 60GG-2, F.A.C.). Risk-based judgment - able to assess control gaps, prioritize remediation, and document risk decisions for management review. Clear technical writing - able to produce audit-ready policy, procedure, assessment, and management-response documentation. Operational competence in a Microsoft 365 / Microsoft Defender environment, including endpoint security, vulnerability management, identity and access controls, and incident response support. Ability to explain security risks, trade-offs, and remediation options to non-security stakeholders, including executives and counsel.

The Senior Security & Compliance Analyst will provide, but not be limited to, the following activities and tasks.

Governance, Policy & Standards.

The candidate will:

Draft, revise, and maintain Department information security policies and standards (including the 420-series), and establish and operate periodic review cycles.

Develop procedures supporting Department security policies consistent with Rule 60GG-2.002 and 60GG-2.003, F.A.C. Develop and maintain control mappings and crosswalks among NIST SP 800-53, NIST CSF, and Rule 60GG-2, F.A.C.

Maintain documentation, version control, and review evidence sufficient to satisfy internal and external audit.

Risk Management & Assessment.

The candidate will:

Conduct security risk assessments and control gap analyses against applicable frameworks.

Develop, track, and maintain Plans of Action and Milestones (POA&Ms) and corrective action plans.

Perform third-party / vendor security risk reviews, including review of vendor security documentation, contract security terms, and integration security (identity federation, per-transaction attribution, and audit logging).

Security Operations & Engineering Support.

The candidate will:

Support configuration, hardening, and monitoring within Microsoft 365 and Microsoft Defender (Defender for Endpoint, Defender Vulnerability Management, Microsoft Purview) consistent with Department standards.

Support vulnerability management: triage, tracking, and coordination of remediation. Support incident response consistent with the Department's Cybersecurity Incident Response Policy (420.01), including documentation and post-incident analysis.

Support identity and access management activities, including access reviews and provisioning-integrity controls.

Audit, Compliance & Reporting.

The candidate will:

Support response to Office of Inspector General (IG) and external audit findings, including evidence collection, control testing, and development of management responses.

Support compliance with the CJIS Security Policy and protection of PHI and other confidential information.

Develop security metrics, status reporting, and security awareness materials; support security governance meetings and working groups.

Contract Deliverables:

The candidate shall provide evidence of performance through documentation including, but not limited to:

Drafted and revised security policies and standards, with documented periodic-review cycles.

Control mapping crosswalks (NIST SP 800-53 / NIST CSF / Rule 60GG-2, F.A.C.). Security risk assessment reports and control gap analyses.

Plans of Action and Milestones (POA&Ms) and corrective action plans.

Third-party / vendor security review memoranda and diagnostic question sets.

Vulnerability management tracking and remediation status reports.

Incident documentation and post-incident (Root Cause Analysis) reports.

Audit evidence packages and draft management responses to IG / external findings.

Security metrics and periodic status reports.

Education and Certification:

The candidate must possess, at a minimum, a Bachelor's degree in computer science, information systems, cybersecurity, or a related field, or equivalent work experience; and at least one current industry certification from the following (others may be considered): CISA - Certified Information Systems Auditor (strongly aligned to the GRC/audit core). CRISC - Certified in Risk and Information Systems Control. CGRC - Certified in Governance, Risk and Compliance (formerly CAP). CISM - Certified Information Security Manager. CISSP - Certified Information Systems Security Professional.

QUALIFICATION REQUIREMENTS FOR SENIOR SECURITY & COMPLIANCE ANALYST

Minimum Qualifications:

The candidate must possess the minimum qualifications and experience:

a minimum of four (4) years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, and database design and administration, including one to two (1-2) years of experience with information security, and knowledge of security issues, techniques, and implications across all existing computer platforms.

Minimum of seven (7) years across information security disciplines, with demonstrated experience in both security governance/compliance (GRC) and hands-on security operations.

Demonstrated experience drafting information security policy and standards and implementing NIST SP 800-53 and/or NIST CSF controls.

Demonstrated experience performing security risk assessments and supporting internal or external audits.

Preferred Qualifications:

The following are preferred and will strengthen a candidate's evaluation:

Florida state government or public-sector information security experience.

Working knowledge of Rule 60GG-2, F.A.C., and Section 282.318, Florida Statutes. CJIS Security Policy implementation or audit experience.

HIPAA Security Rule and PHI-handling experience.

Hands-on Microsoft 365 G5, Microsoft Defender (Endpoint, Vulnerability Management), and Microsoft Purview experience.

Vulnerability management tooling and remediation-coordination experience.

Experience developing IAM / access-control standards and provisioning-integrity controls.

PowerShell or comparable scripting for security automation and reporting.

location: Tallahassee, Florida
job type: Contract
salary: $65 - 85 per hour
work hours: 8am to 5pm
education: Bachelors


responsibilities:
The Senior Security & Compliance Analyst will provide, but not be limited to, the following activities and tasks.

Governance, Policy & Standards.

The candidate will:

Draft, revise, and maintain Department information security policies and standards (including the 420-series), and establish and operate periodic review cycles.

Develop procedures supporting Department security policies consistent with Rule 60GG-2.002 and 60GG-2.003, F.A.C.

Develop and maintain control mappings and crosswalks among NIST SP 800-53, NIST CSF, and Rule 60GG-2, F.A.C.

Maintain documentation, version control, and review evidence sufficient to satisfy internal and external audit.

Risk Management & Assessment.

The candidate will:

Conduct security risk assessments and control gap analyses against applicable frameworks.

Develop, track, and maintain Plans of Action and Milestones (POA&Ms) and corrective action plans.

Perform third-party / vendor security risk reviews, including review of vendor security documentation, contract security terms, and integration security (identity federation, per-transaction attribution, and audit logging).

Security Operations & Engineering Support.

The candidate will:

Support configuration, hardening, and monitoring within Microsoft 365 and Microsoft Defender (Defender for Endpoint, Defender Vulnerability Management, Microsoft Purview) consistent with Department standards.

Support vulnerability management: triage, tracking, and coordination of remediation.

Support incident response consistent with the Department's Cybersecurity Incident Response Policy (420.01), including documentation and post-incident analysis.

Support identity and access management activities, including access reviews and provisioning-integrity controls.

Audit, Compliance & Reporting.

The candidate will:

Support response to Office of Inspector General (IG) and external audit findings, including evidence collection, control testing, and development of management responses.

Support compliance with the CJIS Security Policy and protection of PHI and other confidential information.

Develop security metrics, status reporting, and security awareness materials; support security governance meetings and working groups.

Contract Deliverables:

The candidate shall provide evidence of performance through documentation including, but not limited to:

Drafted and revised security policies and standards, with documented periodic-review cycles.

Control mapping crosswalks (NIST SP 800-53 / NIST CSF / Rule 60GG-2, F.A.C.).

Security risk assessment reports and control gap analyses.

Plans of Action and Milestones (POA&Ms) and corrective action plans.

Third-party / vendor security review memoranda and diagnostic question sets.

Vulnerability management tracking and remediation status reports.

Incident documentation and post-incident (Root Cause Analysis) reports.

Audit evidence packages and draft management responses to IG / external findings.

Security metrics and periodic status reports.

qualifications:
The candidate must demonstrate the following abilities for consideration:

Broad mastery of information security across governance and operations - able to both author policy and standards and perform the hands-on technical work to implement and validate controls. Fluency in security control frameworks (NIST SP 800-53, NIST CSF) and the ability to map and crosswalk controls to the Florida Cybersecurity Standards (Rule 60GG-2, F.A.C.). Risk-based judgment - able to assess control gaps, prioritize remediation, and document risk decisions for management review. Clear technical writing - able to produce audit-ready policy, procedure, assessment, and management-response documentation. Operational competence in a Microsoft 365 / Microsoft Defender environment, including endpoint security, vulnerability management, identity and access controls, and incident response support. Ability to explain security risks, trade-offs, and remediation options to non-security stakeholders, including executives and counsel.

Education and Certification:

The candidate must possess, at a minimum, a Bachelor's degree in computer science, information systems, cybersecurity, or a related field, or equivalent work experience; and at least one current industry certification from the following (others may be considered): CISA - Certified Information Systems Auditor (strongly aligned to the GRC/audit core). CRISC - Certified in Risk and Information Systems Control. CGRC - Certified in Governance, Risk and Compliance (formerly CAP). CISM - Certified Information Security Manager. CISSP - Certified Information Systems Security Professional.

QUALIFICATION REQUIREMENTS FOR SENIOR SECURITY & COMPLIANCE ANALYST

Minimum Qualifications:

The candidate must possess the minimum qualifications and experience:

a minimum of four (4) years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, and database design and administration, including one to two (1-2) years of experience with information security, and knowledge of security issues, techniques, and implications across all existing computer platforms.

Minimum of seven (7) years across information security disciplines, with demonstrated experience in both security governance/compliance (GRC) and hands-on security operations.

Demonstrated experience drafting information security policy and standards and implementing NIST SP 800-53 and/or NIST CSF controls.

Demonstrated experience performing security risk assessments and supporting internal or external audits.

Preferred Qualifications:

The following are preferred and will strengthen a candidate's evaluation:

Florida state government or public-sector information security experience.

Working knowledge of Rule 60GG-2, F.A.C., and Section 282.318, Florida Statutes. CJIS Security Policy implementation or audit experience.

HIPAA Security Rule and PHI-handling experience.

Hands-on Microsoft 365 G5, Microsoft Defender (Endpoint, Vulnerability Management), and Microsoft Purview experience.

Vulnerability management tooling and remediation-coordination experience.

Experience developing IAM / access-control standards and provisioning-integrity controls.

PowerShell or comparable scripting for security automation and reporting.

Equal Opportunity Employer: Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status.

At Randstad Digital, we welcome people of all abilities and want to ensure that our hiring and interview process meets the needs of all applicants. If you require a reasonable accommodation to make your application or interview experience a great one, please contact View email address on click.appcast.io.


Pay offered to a successful candidate will be based on several factors including the candidate's education, work experience, work location, specific job duties, certifications, etc. In addition, Randstad Digital offers a comprehensive benefits package, including: medical, prescription, dental, vision, AD&D, and life insurance offerings, short-term disability, and a 401K plan (all benefits are based on eligibility).


This posting is open for thirty (30) days.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Senior security compliance analyst in Tallahassee, FL vacancy
  •  ...Job Description Job Description The Senior Security & Compliance Analyst will provide, but not be limited to, the following activities and tasks. # Minimum Qualifications. The candidate must possess the minimum qualifications and experience of the STC Job Family... 
    Senior
    Permanent employment
    Contract work
    Work experience placement
    Second job
    Remote work

    TechArmy

    Tallahassee, FL
    5 days ago
  •  ...IT Security Compliance Analyst Contract: 12-Months (No C2C or Third-Party Vendors) Location: Tallahassee,Florida(5 days, onsite) We are seeking an experienced IT Security Compliance Analyst to support information security governance, risk management, and compliance... 
    Suggested
    Contract work

    Genius Road

    Tallahassee, FL
    4 days ago
  •  ...3) years of experience with information security and five (5) years of combined IT and security...  ...The Advanced Information Security Analyst is responsible for leading the technical...  ...ensure integration of security platforms. Compliance with regulations is critical, as is... 
    Senior
    Work experience placement
    Work at office

    Cogent Infotech Corp

    Tallahassee, FL
    3 days ago
  •  ...Position Summary We are seeking a dedicated Security Analyst to join our team in supporting the configuration, maintenance, and security of end user applications within a comprehensive Office 365 environment. Under the guidance of network and end-user support... 
    Suggested
    Work experience placement
    Work at office
    Worldwide

    Dexian

    Tallahassee, FL
    4 hours ago
  •  ...Security Analyst Assists in developing specifications as well as, overall planning and management of projects. Meets with leadership to provide status reports on a weekly basis and provides monthly written reports which will include accomplishments, areas of concerns... 
    Suggested

    Samprasoft

    Tallahassee, FL
    4 hours ago
  •  ...operations between the Department and the Department's Managed Security Services Provider, Secureworks, as assigned by the Department....  ...4 years experience # Experience working as a security analyst in an environment utilizing a Managed Security Services Provider... 
    For contractors
    For subcontractor
    Remote work
    Monday to Friday
    Night shift
    Weekend work

    Apex Informatics

    Tallahassee, FL
    5 hours ago
  • Security Analyst Location: Tallahassee, FL (Hybrid) Hire Type: Contract (12+ months) Client: State of Florida Job Description Need Security Analyst Skills: Healthcare, NIST, Build & Release Management Experience: 8+ Years
    Contract work

    Argyle Infotech

    Tallahassee, FL
    4 days ago
  •  ...Security Administrator Develops and manages security for more than one IT functional area (e.g., data, systems, network and/or Web)...  ...position primarily focuses on security administration; a more senior level position is involved in developing enterprise security strategies... 
    Work experience placement
    Immediate start

    Connective Business Solution

    Tallahassee, FL
    5 hours ago
  •  ...computing, engineering, mobility, testing, and more. Certified with CMMI Level 3 and ISO standards, V2Soft is committed to quality and security. Beyond our work, we actively support local communities and non-profits, reflecting our core values. Join us to be part of a... 
    Work experience placement
    Work at office
    Local area
    Worldwide

    V2soft

    Tallahassee, FL
    3 days ago
  •  ...Responsibilities will include but are not limited to: Perform security administration to configure and document firewall...  ...position primarily focuses on security administration; a more senior level position is involved in developing enterprise security strategies... 
    Work experience placement
    Work at office

    Kaav Inc.

    Tallahassee, FL
    3 days ago
  •  ...The Security Operations Center (SOC) Analyst II serves as a mid‑level cyber defender responsible for continuous monitoring, investigation, and response...  ...inputs. p]:pt-0 [& p]:mb-2 [& p]:my-0" Support compliance‑driven operations in a highly regulated government environment... 
    Contract work
    Work at office

    ASM Research, An Accenture Federal Services Company

    Tallahassee, FL
    4 days ago
  • The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands‑on penetration testing and adversarial simulation. Working under the guidance of the Exposure... 
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Tallahassee, FL
    2 days ago
  •  ...multi-platform environments. Extensive Experience with Office 365 applications for end users and end user devices with an emphasis on security tools and applications. Extensive experience desktop support of Microsoft products as well as software management used by end user... 
    Work experience placement
    Work at office
    Relocation

    SANROSE Information Services Inc

    Tallahassee, FL
    1 hour ago
  •  ...Job Description • Develops and manages security for more than one IT functional area (e....  ...focuses on security administration; a more senior level position is involved in developing...  ...such as vulnerability management, compliance monitoring, and continuous security monitoring... 
    Work experience placement
    Work at office
    Shift work

    vTech Solution, Inc.

    Tallahassee, FL
    2 days ago
  •  ...Tallahassee, Florida Experience Level Mid–Senior Level (5 or more years of relevant experience) Role Overview The Security Analyst supports enterprise information security...  ...security controls, manage device compliance, remediate vulnerabilities, and support policy... 
    Work experience placement

    SMART TECH SKILLS LLC

    Tallahassee, FL
    15 days ago
  •  ...Understanding Microsoft 365 license tiers (E3, E5, Business Premium) to know what features are available. Ability to evaluate features for secure implementation. Establish applicable security policies, best practices, and baselines to onboard devices. Inventory, remediate... 
    For contractors
    Work experience placement
    Work at office
    Flexible hours

    Capital Technology Alliance

    Tallahassee, FL
    4 days ago
  • We have an onsite opportunity for a Security Analyst (Advanced Information Security Analyst) in Tallahassee, FL . This is a long-term project...  ...response , root cause analysis, and threat detection Ensure compliance with security standards and regulatory frameworks... 
    Work at office

    TalenTech Digital

    Tallahassee, FL
    3 days ago
  •  ...Garmin Ltd. in the United States is seeking a Senior International Trade Compliance Specialist at our U.S. headquarters in the Kansas City area. You...  ...import/export compliance programs, oversee supply chain security, and ensure adherence to CBP, EAR, ITAR, OFAC, and C-... 
    Senior

    Garmin

    Tallahassee, FL
    2 days ago
  •  ...A leading insurance firm is seeking a Senior Actuarial Analyst to develop and support a pricing and reserving framework. The role involves independent project leadership, advanced analytics communication, and potential mentorship of junior analysts. Candidates should... 
    Senior
    Remote work
    Flexible hours

    Ally

    Tallahassee, FL
    2 days ago
  •  ...SummaryAs a Senior Financial Analyst working for Taylor Morrison you will be responsible for Division's financial policies, planning, reporting...  ...reporting of Division financial statements and ensure compliance with company accounting policies and procedures, in accordance... 
    Senior
    Full time
    Work at office

    Taylor Morrison

    Tallahassee, FL
    3 days ago
  • $90.23k

     ...Job Title Senior Financial Analyst (Hybrid Work Options) Business Unit COR Employment Type Regular Job Description CDM Smith is seeking a Senior Financial Analyst to join our Corporate FP&A Team! This role supports financial planning and analysis projects and initiatives... 
    Senior

    CDM Smith

    Tallahassee, FL
    4 days ago
  •  ...Due to continued growth and the ongoing success of our Regulatory Affairs Consulting team, Parexel is seeking an experienced Senior Regulatory Affairs Consultant (Program / Client Partnership Manager) to join our team. In this pivotal role, you will leverage advanced... 
    Senior
    Remote work

    PAREXEL

    Tallahassee, FL
    3 days ago
  • $46.99k - $122.4k

     ...– helping to simplify health care one person, one family and one community at a time. The Financial Planning & Analysis (FP&A) Senior Analyst will play a key role in supporting the financial planning, forecasting, budgeting, and performance management processes for Retail... 
    Senior
    Hourly pay
    Full time
    Temporary work
    Local area

    Hispanic Alliance for Career Enhancement

    Tallahassee, FL
    1 day ago
  • $130.9k - $154k

    Ready to be pushed beyond what you think you’re capable of? At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the...
    Senior
    Local area

    Coinbase

    Tallahassee, FL
    2 days ago
  • $101.3k - $168.7k

     ...Sr Program Financial Analyst demonstrates deep expertise in contract...  ...with the Program Manager, senior technical staff on the contract...  .... Lead contract setup in compliance with contractual terms,...  ...mission. From priority national security initiatives for the DoD to highly... 
    Senior
    Contract work
    Work experience placement
    For subcontractor
    H1b
    Work at office
    Remote work

    SMX Corporation

    Tallahassee, FL
    2 days ago
  • $81.7k - $135k

     ...Tax - Indirect Tax - Global Trade Thomson Reuters ONESOURCE - Senior Opportunity EY’s Global Trade practice, a national group in Indirect...  ...trade costs, identify and address risks to achieve worldwide compliance, as well as enhance and improve trade operations and assist... 
    Senior
    Work experience placement
    Summer holiday
    Worldwide
    Flexible hours

    Ernst & Young Oman

    Tallahassee, FL
    1 day ago
  •  ...Tallahassee, FL. Job Summary and Qualifications Seeking a Senior Financial Analyst who will support the Physician Services Group divisional...  ...other month‑end reporting. You will prepare documents for compliance with regulations. What qualifications you will need Bachelor... 
    Senior
    Full time
    Temporary work
    Work at office
    Flexible hours

    HCA Healthcare

    Tallahassee, FL
    12 hours ago
  • $110k - $120k

     ...pay range $110,000.00/yr - $120,000.00/yr Senior Fund Accountant manages the financial...  ...calculating Net Asset Value (NAV), and ensuring compliance with regulations. They play a crucial...  ...procedures, such accounting records as securities positions, corporate actions related,... 
    Senior
    Full time

    Leeds Professional Resources

    Tallahassee, FL
    12 hours ago
  • $80.2k - $111.3k

     ...Cybersecurity Incident Response Engineer, Senior leads complex incident response efforts...  ...governance, and influences broader security architecture and operations based on emerging...  ...coaching to incident handlers and SOC analysts, elevating investigative techniques, documentation... 
    Senior
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Tallahassee, FL
    2 days ago
  •  ...integrity, reliability, efficiency, and security of applications, platforms, or procedures...  ...or suggestions. - Ensures compliance with IS audit standards, guidelines, and...  ...market and internal value analysis including seniority and merit systems, as well as internal pay... 
    Minimum wage
    Contract work
    Temporary work
    Work experience placement

    MAXIMUS

    Tallahassee, FL
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior security compliance analyst. Be the first to apply!