Project Security Lead
My3Tech
Role: Project Security Lead
Location: Remote (occasional travel to SD as required)
Type: W2 only
Duration: Long-term
Client: State of South Dakota
Position Summary:
My3Tech is seeking an experienced Project Security Lead to provide security leadership, governance, technical oversight, and security certification for the South Dakota Rural Health Data Atlas.
The Project Security Lead will be responsible for the security of the solution throughout the project lifecycle, including application development, Microsoft Azure configuration, data integration, identity and access management, testing, deployment, updates, vulnerability remediation, and production readiness.
The Project Security Lead will work closely with the South Dakota Department of Health, the South Dakota Bureau of Information and Technology, the Consultant Project Manager, Solution/Azure Architect, Data Engineering Team, Application Development Team, Quality Assurance resources, and other project stakeholders to ensure that security requirements are incorporated into the solution from design through operations.
The individual will also serve as My3Tech's designated security-certification authority for the project and will certify in writing that applicable deliverables satisfy required security controls prior to State acceptance or production deployment . This directly supports the RFP's Project Security Lead and Secure Product Development requirements.
Key Responsibilities
Security Governance and Certification
- Serve as My3Tech's primary security lead for the Rural Health Data Atlas.
- Certify in writing the security of each applicable project deliverable , consistent with State requirements.
- Maintain responsibility for security of the application development, management, configuration, deployment, and update processes throughout the contract period.
- Translate applicable State, Bureau of Information and Technology, contractual, regulatory, and project security requirements into actionable technical and operational controls.
- Participate in project-status and governance meetings and provide security-status reporting, risks, decisions, findings, and required actions.
- Recommend corrective actions or adjustments to deliverables, schedule, resources, or implementation activities when security requirements could affect project performance or State milestones.
- Coordinate security-related decisions with the Consultant Project Manager, State stakeholders, and Bureau of Information and Technology representatives.
Secure Architecture and Microsoft Azure Oversight
- Review solution, application, data, network, integration, and Microsoft Azure architecture for compliance with State security requirements.
- Support security design and configuration of the State-owned Microsoft Azure environment .
- Review environment separation, secure configuration, encryption, secrets management, logging, monitoring, network controls, and access pathways.
- Verify that security-relevant configuration guidance, platform dependencies, and secure configuration requirements are documented.
- Confirm that unsupported or prohibited technologies, components, libraries, hardware, or services are not introduced into the solution.
- Review third-party and open-source components for security risk, known vulnerabilities, support status, and applicable licensing implications.
Identity and Access Management
- Oversee implementation and validation of the State's identity and access-management requirements.
- Ensure application authentication integrates with the State's Single Sign-On environment using OAuth 2.0 and OpenID Connect .
- Support implementation and validation of:
- Role-Based Access Control;
- Multi-Factor Authentication;
- least-privilege access;
- administrator access;
- public, authenticated, and restricted-user access;
- user provisioning and de-provisioning;
- session timeout and session termination requirements.
- Review access requests for My3Tech personnel and subcontractor personnel and ensure access is limited to approved project responsibilities.
The RFP states that failure to meet the State's identity-management standard can result in rejection of the proposal, making this a critical responsibility for the role.
Data Security and Privacy
- Support classification and protection of State data based on applicable State data-classification requirements.
- Ensure appropriate safeguards are applied to public, sensitive, Personally Identifiable Information, Protected Health Information, and other regulated information, where applicable.
- Review encryption controls for data at rest and in transit.
- Ensure State data is used only for authorized project purposes.
- Support secure handling, retention, sanitization, and disposal requirements.
- Review data-access pathways, data transfers, secure file-transfer processes, and external data-source connections.
- Support controls that preserve confidentiality, integrity, availability, and State ownership of project data.
API and Integration Security
- Review security controls for Application Programming Interfaces, data integrations, external services, secure file transfers, and system-to-system communications.
- Coordinate with the Solution/Azure Architect and Bureau of Information and Technology to ensure that required interfaces comply with the State's API Management requirements .
- Validate authentication, authorization, logging, monitoring, throttling, and applicable API security policies.
- Ensure no required production API bypasses the State's approved API Management layer.
The RFP requires system-to-system integrations and API traffic to use the State's API Management platform as the authoritative broker.
Secure Software Development
- Incorporate security controls throughout the software-development lifecycle rather than treating security as a final pre-production activity.
- Support secure coding practices and ensure development personnel receive appropriate secure-development training.
- Review security architecture and security-design documentation.
- Ensure source-code and configuration changes are maintained through approved source-control processes with appropriate authentication and auditability.
- Coordinate use of static and dynamic software-security-analysis tools and dependency-scanning tools where applicable.
- Review scan findings with security and development personnel and ensure remediation is appropriately prioritized and tracked.
- Verify that application code contains no unnecessary, malicious, unsupported, or unauthorized components.
Vulnerability Management and Security Testing
- Plan security scanning and remediation activities into the project schedule.
- Coordinate with the State and Bureau of Information and Technology for required web application and network vulnerability scans .
- Ensure appropriate non-production environments are available for State security testing.
- Review findings related to the Open Worldwide Application Security Project Top Ten, Common Vulnerabilities and Exposures, Common Weakness Enumerations, configuration weaknesses, and other identified security risks.
- Coordinate penetration testing and security validation, where applicable.
- Assign and track vulnerability remediation actions.
- Ensure corrective actions are retested and closure evidence is maintained.
- Confirm that unresolved security issues that could prevent User Acceptance Testing or production deployment are addressed before advancement.
The RFP explicitly states that products failing State security requirements may be barred from User Acceptance Testing or production until issues are resolved to the State's satisfaction .
Security Incident and Threat Management
- Establish and maintain project security-incident response, investigation, escalation, and reporting procedures.
- Coordinate with My3Tech leadership, the Consultant Project Manager, and State/Bureau security stakeholders when credible threats or security incidents are identified.
- Ensure security events, vulnerabilities, and incidents are appropriately logged, prioritized, investigated, remediated, and documented.
- Support preservation of evidence, root-cause analysis, corrective actions, and post-incident review when required.
- Ensure project procedures support applicable State notification requirements for security incidents.
Security Logging, Monitoring, and Auditability
- Define security logging and monitoring requirements for the solution.
- Verify that appropriate application, authentication, administration, integration, and security events are captured.
- Support protection of audit logs from unauthorized modification.
- Ensure security evidence is retained in accordance with applicable State and contractual requirements.
- Provide security evidence and documentation required to support State reviews, audits, security assessments, and acceptance activities.
Artificial Intelligence Security and Compliance
Where Artificial Intelligence or Generative Artificial Intelligence is used in the solution or development lifecycle, the Project Security Lead will:
- review proposed Artificial Intelligence functionality and tools for compliance with State requirements;
- confirm disclosure of applicable Artificial Intelligence components;
- assess data classification, privacy, security, residency, retention, logging, and access-control implications;
- ensure State data is not used to train or tune Artificial Intelligence models unless explicitly authorized in writing;
- review third-party Artificial Intelligence services for data sovereignty and security risk;
- verify that applicable Artificial Intelligence functionality can be restricted or disabled when required; and
- support auditability, human oversight, and security documentation.
The RFP applies its Artificial Intelligence requirements not only to embedded functionality but also to Artificial Intelligence used in the development and delivery of the solution .
Production Security Readiness
- Participate in production-readiness and Go-Live/Cutover reviews.
- Verify that required security controls have been implemented and validated before production deployment.
- Confirm readiness of:
- identity and access management;
- vulnerability remediation;
- logging and monitoring;
- data protection;
- API security;
- security configuration;
- incident-response procedures; and
- operational security documentation.
- Provide security-certification evidence required to support State production authorization.
- Support post-launch monitoring and remediation during hypercare and Year 1 operations.
Primary Security Deliverables and Work Products
The Project Security Lead will develop, review, approve, or contribute to applicable security artifacts, including:
- Written Security Certification for applicable deliverables
- Security and Privacy Controls Package
- Security Architecture Review
- Azure Security Configuration
- Secure Configuration Guidelines
- Identity and Access Management Design
- Role-Based Access Control Matrix
- Security Risk Register
- Vulnerability Scan Findings and Remediation Records
- Penetration Testing Evidence
- Security Test Results
- Security Requirements Traceability
- API and Integration Security Review
- Third-Party/Open-Source Security Review
- Logging and Monitoring Requirements
- Security Incident and Escalation Procedures
- Production Security Readiness Checklist
- Go-Live Security Approval Evidence
- Security Operations Documentation
- Security Knowledge-Transfer Materials
Reporting Relationship
The Project Security Lead will coordinate daily with the Consultant Project Manager and relevant My3Tech Team technical leads.
In accordance with the RFP, the Project Security Lead will report security status, findings, risks, recommendations, and required decisions to the Agency Project Sponsor as part of project status meetings . When security matters arise, the Project Security Lead must be able to recommend amendments or changes affecting deliverables, schedule, resources, or budget.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related discipline, or equivalent relevant professional experience.
- Demonstrated professional experience in information security, cybersecurity, application security, cloud security, or security architecture.
- Experience securing cloud-based enterprise applications, preferably within Microsoft Azure.
- Experience with secure software-development lifecycle practices.
- Experience reviewing application, data, integration, API, and cloud architectures from a security perspective.
- Knowledge of:
- OAuth 2.0;
- OpenID Connect;
- Single Sign-On;
- Multi-Factor Authentication;
- Role-Based Access Control;
- encryption;
- secrets management;
- audit logging;
- vulnerability management;
- secure configuration; and
- incident response.
- Experience coordinating vulnerability scanning, security testing, remediation, and retesting.
- Understanding of the Open Worldwide Application Security Project Top Ten, Common Vulnerabilities and Exposures, and secure coding principles.
- Ability to assess security findings and determine their effect on production readiness, State milestones, and project risk.
- Strong written communication skills and the ability to prepare formal security certifications, findings, recommendations, and supporting evidence.
- Ability to work effectively with State technical personnel, project managers, architects, developers, data engineers, testing teams, and business stakeholders.
Preferred Qualifications
The following are My3Tech-preferred qualifications and are not represented as mandatory RFP requirements :
- 7+ years of progressive information-security or cybersecurity experience.
- State, Local, and Education government technology experience.
- Experience supporting healthcare, Medicaid, public health, social-services, or other regulated environments.
- Microsoft Azure security experience.
- Experience with government security assessments and production-authorization processes.
- Familiarity with National Institute of Standards and Technology security frameworks and standards.
- Familiarity with Health Insurance Portability and Accountability Act security requirements where applicable.
- Relevant certifications such as:
- Certified Information Systems Security Professional;
- Certified Information Security Manager;
- Certified Cloud Security Professional;
- Microsoft Azure Security Engineer Associate; or
- equivalent security certifications.
Background and Security Requirements
The Project Security Lead must comply with all applicable State security requirements, including required security acknowledgments and access controls.
Because this role may configure State-owned technology, access source code, or access protected State information, the individual must be prepared to undergo the State-required fingerprint-based background investigation . The RFP states that these investigations may require approximately two to four weeks , which should be accounted for in project planning.
Role Objective
The Project Security Lead will ensure that security is embedded throughout the Rural Health Data Atlas lifecycle-from architecture and development through testing, State acceptance, production deployment, and operations-and will provide the formal security accountability and written certification required by the State .
Primary success measure: the Atlas progresses through State security review, User Acceptance Testing, production readiness, and launch with required security controls implemented, documented, validated, and accepted.
$60k
...federal partner supporting mission-critical programs across national security, defense, and public service delivery. Our work focuses on... ...including coordinating and executing directed cyber activities. Lead and support containment and restoration efforts during security...SuggestedContract workRemote workShift work$30 per hour
...environment. We meet and exceed each customer's security and compliance requirements, such as... ...problems is desired. Experience as a project manager, or in a technical leadership... ...all. Discover your potential at a company leading the way in AI and cloud solutions that impact...SuggestedHourly payTemporary workInternshipLocal areaFlexible hours$115k - $150k
...Hagerty Consulting, Inc. (Hagerty) is the nation's leading emergency management and homeland security consulting firm. Known for its public spirit, innovative... ...for the FEMA Comprehensive Disaster Recovery Project Manager position will be considered for our internal...SuggestedPermanent employmentTemporary workLocal areaImmediate startRemote workFlexible hours$60k
...mission‑critical programs across national security, defense, and public service delivery.... ...This role is remote. The Technical Project Coordinator supports IT operations by coordinating... ...mitigation strategies with delivery team leads and leadership. Coordinate with...SuggestedContract workWork experience placementRemote workFlexible hours- ...Project Manager Pierre, SD 10 months contract with possibility to extension Client is seeking a qualified individual to assist... ...adheres to time and budgetary constraints. Arrange, organize, and lead regular project status meetings at suitable intervals as...SuggestedContract work
- ...Technical Project ManagerLocation: Pierre, SDDuration: Long-termJob Duties:Actively monitor, track and manage project tasks, timelines, attainment of established milestones and overall quality of project activities, and deliverables across various software projects in...
- ...IT Project ManagerLocation: Pierre, SDDuration: 2.5 YearsMinimum Qualifications:Knowledge of eligibility and enrollment system technical... ..., interface development, user acceptance testing, and security solution design, development and implementationAbility to identify...
$200k - $213k
...As a Project Development Manager here at Honeywell, you will lead the analysis, development, and advancement of Distributed Energy Resource (DER), energy efficiency, electrification, resilience, and decarbonization projects tailored for commercial and industrial customers...Contract workTemporary workWork experience placementFlexible hours$211.72k
...to offering an unmatched employee experience. Where you work on projects that are meaningful to you. Where you play an active part in shaping... ...to CDM Smith's mission by: • Managing and serving as the lead Project Manager on water/wastewater projects • Providing technical...Work experience placementH1bWork at office$140k
...Maximus is currently seeking a Senior Technology Project Manager to lead and track the development and implementation of a complex, strategic... ...functional coordination among business operations, engineering, security, and senior leadership to ensure requirements, priorities,...Contract workWork experience placementFor subcontractorWork at officeRemote work$184.14k
...to offering an unmatched employee experience. Where you work on projects that are meaningful to you. Where you play an active part in shaping... .... *** CDM Smith is seeking a Data Center Project Manager to lead the successful delivery of complex, mission-critical data center...Contract workWork experience placementH1bWork at office$102.3k - $209.5k
...Job Description As a Special Project Manager, Data Center Facilities Remediation Projects , you will lead the execution of complex remediation, upgrade, and retrofit... ..., Commissioning, Procurement, Finance, Security, and site leadership. Translate requirements...Full timeTemporary workFor contractorsWork at officeRelocation packageFlexible hours- ...Job Description We have a role for a Project Manager this is a remote role with occasional travel to Pierre SC. JOB DESCRIPTION... ...basis. Activities include but are not limited to: • Leading the design, development, and implementation of various information...Work experience placementRemote work
- ...successful planning, execution, and delivery of projects, ranging from mid-size to large... ...initiatives. The individual in this role will lead all aspects of the project lifecycle,... ...Policies and Procedures as well as all data security guidelines established within the Company...For contractorsWork at officeLocal area
- ...Job Description Job Description Now Hiring: Project Superintendent / Project Manager Midwest Construction is looking for an experienced Project Superintendent / Project Manager to lead residential and commercial construction projects from start to finish. Responsibilities...For subcontractorImmediate startFlexible hours
- ...while working from home! We’re looking for a seasoned Regulatory Project Manager who can turn strategy into action and thrive in fast-... ...high-impact role, you’ll partner closely with Global Regulatory Leads to drive globally aligned regulatory plans, guide complex development...Work at officeRemote workWork from homeWorldwide
$91.4k - $187k
...Job Description IC4 - Regional Deployment Project Manager Location: United States (DC/KC/Austin/Nashville highly preferred) Travel... ...and collaborate with senior leadership to drive outcomes. • Lead strategic initiatives that align with program goals and enhance...Temporary workWork at officeVisa sponsorshipFlexible hours$68k - $73.5k
...eligibility criteria. South Dakota Medicaid is seeking two highly qualified individuals to join our policy, projects, and reimbursement team. Duties may include: Leading policy and strategic project initiatives including federal grants management. Manage policy...Full timeContract workWork at officeWork from homeVisa sponsorshipWork visa- ...Digital Marketing Project Manager Anywhere Type: Consulting Category: Program/Project Management Industry: Financial Services... ...teams in maintaining delivery commitments. Partner with pod leads and stakeholders to align priorities and timelines. Encourage...Hourly payContract workLocal areaRemote work
$105k - $115k
...Overview What You'll Be Doing Cadmus is seeking a Technical Project Manager (TPM) with a passion for delivering high quality... ...transformative goals. As a member of our team, you'll collaborate with leading experts to support our clients across the globe. We offer...Permanent employmentWork experience placementLocal areaWorldwide$51.6k - $64.5k
...Eligible Work Locations: Remote - Nationwide, United States Project Coordinator, IT Infrastructure Why WWT? At World Wide Technology... ...Founded in 1990, WWT is a global technology solutions provider leading the AI and Digital Revolution. WWT combines the power of...Full timeRemote workShift work$56.8k - $71k
...Founded in 1990, WWT is a global technology solutions provider leading the AI and Digital Revolution. WWT combines the power of strategy... ...teams? Join WWT today! Role Overview The Staffing Project Analyst (SPA) is responsible for supporting the financial and operational...Hourly payFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Project Security Lead. Be the first to apply!
- projects Pierre, SD
- project controls Pierre, SD
- project intern Pierre, SD
- senior implementation project manager Pierre, SD
- software implementation project manager Pierre, SD
- implementation project manager remote Pierre, SD
- retail project merchandiser part time Pierre, SD
- special projects Pierre, SD
- project finance Pierre, SD
- projects work from home Pierre, SD



