IT Security ANALYST - GRC
S R INTERNATIONAL INC
Job Description
Job Description
THIS IS CTH ROLE ON W2 ONLY AND FOR CURRENT ARIZONA RESIDENTS.
THIS POSITION IS NOT FOR VISA HOLDERS.This posting will be closed on 8/18/26 @ 3:00pm. This is a 4-month contract to hire. All candidates must be eligible to convert to an FTE. The State is unable to sponsor any visas. This has to be local to Phoenix meaning 1 hour drive max. Please do not submit resources if they were submitted to posting 10482 and 11481.
Only W2 no C2C Job Title: IT Security ANALYST (GRC)
Job ID: 13235
Client: State of Arizona - AZDES - DTS
( contract to hire ) Closing: 8/18/2026
This posting will be closed on 8/18/26 @ 3:00pm. This is a 4-month contract to hire. All candidates must be eligible to convert to an FTE. The State is unable to sponsor any visas. This has to be local to Phoenix meaning 1 hour drive max. Please do not submit resources if they were submitted to posting 10482 and 11481.
Required Skills
- NIST 800-53R5 (Must have)
- Risk Management Framework (RMF)
- Windows/Unix experience
- Project Management experience
- CISSP, CCSP, GSTRT, GSNA, or CAP certification
The Department of Economic Security, Division of Technology Services is seeking an experienced and highly motivated individual to join our team as a Information Security Analyst, (ISA) contractor. This position will work on the Governance Risk and Compliance (GRC) Team to communicate and engage with business units to develop a strong understanding of their reporting, data, and product needs. The team member will work with other personnel across departments to define requirements for projects, identify data dependencies and relationships to develop logical and physical data models, data flows and system activity diagrams, and write specifications for managing enterprise information policies. The team member will help develop plans and materials to support user adoption, training, and customer service, working through direct and regular contact with users from other divisions, programs, and service units to provide regular insight and guidance in prioritizing enhancements for the data systems. The team member will also support technical project managers to ensure that all aspects of the information analysis and requirements gathering process are completed with the highest degree of accuracy and quality, which includes developing and socializing key project artifacts. The state of Arizona strives for a work culture that affords employees flexibility, autonomy, and trust. Across our many agencies, boards, commissions, many State employees participate in the State's Remote Work Program and are able to work remotely in their homes, in offices, and in hoteling spaces. All work, including remote work, should be performed within Arizona unless an exception is properly authorized in advance. Job Duties:
• Perform risk assessments, audit reviews, generate findings reports, and make appropriate recommendations for improvement and track outcomes from those activities for DES reporting requirements. Develop and formulate comprehensive reports detailing the findings, areas of non-compliance, required POA&Ms (Plan of Action and Milestones), environmental observations, and incident reports. • Review, update, and manage security related audit plans, security plans and risk plan documentation for accuracy and consistency, proactively solves problems. • Evaluate data and formulate comprehensive reports detailing the findings, areas of non-compliance, required action plans, and environmental observations. Generates incident reports and investigates suspicious network activity. • Preparing audit documentation that supports audit results, drafting and editing audit findings to adhere to the standards and the agency's writing style. • Research agency and industry IT security practices standards, best practices, laws and regulations, and other applicable resources, ensures compliance with standards Knowledge, Skills & Abilities (Not incompassing)
• Knowledge of security principles, policies, and procedures, and be able to develop effective security policies. • Knowledge of Information Security Risk Management. • Knowledge of laws, regulations, policies, principles, and ethics as they relate to cybersecurity and privacy. (Required: NIST 800-53 R5, IRS Pub1075, IPAA/HITRUST, CJIS and MARS-E)• Expert knowledge of internal auditing, internal controls, and risk management practices and methods. • Knowledge of Selection/Approval, Implementation, and Assessment/Audit of Security and Privacy Controls. • Knowledge of Risk Management Framework (RMF) requirements. • Knowledge of Authorization/Approval of Information Systems. •Knowledge in conducting audits or reviews of technical systems. •Knowledge in comprehensive understanding of internal control environments within the IT function. •Knowledge in multiple technology domains including aspects of Windows, Unix and/or database administration, software development and networking. •Knowledge in identifying cybersecurity and privacy issues that stem from connections with internal and external customers and partner organizations. • Ability to produce high quality work products for both the IT groups and Senior Management. • Ability to perform excellent interpersonal, written and oral communication skills. • Ability to assess, manage, and improve security policies and procedures. • Ability to work collaboratively in teams and across organizations. • Ability to synthesize feedback and adjust plans accordingly, build strong relationships inside and outside the organization and manage large teams. • Ability to ensure security practices are followed throughout all phases of the life cycle of every aspect of business and IT processes. • Ability to develop policy, plans, and strategy in compliance with laws, regulations, policies, and standards in support of organizational cyber activities. • Ability to exercise judgment when policies are not well-defined. • Ability to ensure information security management processes are integrated with strategic and operational planning processes. • Ability to ensure that senior officials within the organization provide information security for the information and systems that support the operations and assets under their control. • Ability to understand technology, management, and leadership issues related to organization processes and problem solving. • Ability to understand the basic concepts and issues related to cyber and its organizational impact.Develop plans and materials to support user adoption, training, and customer service. • Ability to work collaboratively in teams and across organizations. •Develop plans and materials to support user adoption, training, and customer service. •Work directly with users from other divisions, programs, and service units to provide insight and guidance. •Identify risks and suggest improvements to information systems and processes. •Support technical project managers to fulfill information analysis requirements with the highest degree of accuracy and quality. •Develop and maintain key project artifacts.
Flexible work from home options available.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the IT Security ANALYST - GRC in Phoenix, AZ vacancy
- ...Job Description Job Description Job Title: IT Security Analyst Job Code: AZ 13235 Client: State of Arizona – AZDES (Department of... ...experienced IT Security Analyst (Governance, Risk & Compliance - GRC) to support the Division of Technology Services. The selected...SuggestedFull timeContract workLocal areaVisa sponsorshipMonday to Friday
- Company DescriptionIDEALFORCE has a CONTRACT position available immediately for a IT Security Analyst to join our customer in Phoenix Arizona. This is an ONSITE position. Please find below additional details about this job. Kindly respond with your most up to date resume...SuggestedContract workLocal areaImmediate start
- Company DescriptionIDEALFORCE has a Contract position available immediately for a IT Security Risk Analyst to join our customer in Phoenix Arizona. This is an ONSITE position. Please find below additional details about this job. Kindly respond with your most up to date...SuggestedContract workImmediate start
- ...We are seeking an experienced Information Security Analyst with strong expertise in cybersecurity risk management, security audits, compliance... ...and support security incident reporting. Understanding of IT environments including Windows, Unix/Linux, databases, networking...Suggested
- BWH Hotels is seeking an IT Business Analyst for Hotel Security Services (HSS) to develop business solutions for Best Western branded hotels. You will analyze property-level requirements, implement hardware/software solutions, and advise on secure data and payment processing...SuggestedRemote work
- ...with Risk Management Framework (RMF) related activities including Security Control Assessments (SCA) and assisting system owners in the... ...technical management personnel to ascertain the security posture of an IT system Evaluate a wide array of IT devices for Security...For contractorsWork at office
- Best Western is seeking an IT Business Analyst for Hotel Security Services to develop solutions for branded hotels and support secure data and payment environments. You will troubleshoot remotely, implement hardware/software, and advise on system controls for property...Remote work
$76.4k - $138.6k
...systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950... ...business value. The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role...Summer holidayLocal areaFlexible hours- ...Security Analyst â Identity and Access Management (IAM) HIGHLIGHTS Location: REMOTE Position Type: Contract to Hire Hourly / Salary... ...with other security team members, as well as those on other IT teams and operating companies to drive IAM maturity and awareness...Hourly payContract workRemote work
$124.2k - $186.2k
...About the team: The Information Security organization advances the overall state of security at Rubrik through purposeful initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams...Local areaRemote work- Alignerr is seeking an Offensive Security Analyst to bring real-world adversarial thinking to cutting-edge AI training projects. This fully remote hourly contract role focuses on structured adversarial reasoning, not exploit development. You will analyze attack paths,...Remote jobHourly payContract work10 hours per weekFlexible hours
$72k - $90k
...clients' most complex challenges. Position Overview: The Security Analyst supports customer engagements by helping to deliver business... ...functional teams (security engineers, architects, compliance, IT, and business stakeholders) to deliver security projects on time...Full timeRemote workShift work$102k - $112k
...mechanical, lighting, air conditioning, heating, security, fire protection, and power generation... ...EMCOR Group, Inc. seeks a Security Analyst for Identity and Access Management (IAM)... ...and PAM. Collaborate with security and IT teams to enhance IAM maturity and awareness...Flexible hours$80k - $115k
Job Description Role - Info Security Analyst Experience Required -3+ Years Must Have Technical/Functional Skills Knowledge of data classification solutions Strong understanding of Multi-tenant SaaS environments Cloud shared responsibility model - IaaS / PaaS / SaaS differences...- EMCOR Group, Inc. is hiring a Security Analyst for Identity and Access Management (IAM) in Las Vegas, NV. This role supports EMCOR’s Security... ...management, monitoring emerging threats, and collaborating with IT teams to enhance IAM maturity. Competitive compensation and a...
- Redman Equipment & Manufacturing Company is looking for a Security Analyst to enhance their Security Program. The position supports identity systems and involves using Microsoft Sentinel and Microsoft Defender for threat detection and incident response. Candidates should...
$52.47k
...supporting active-duty and veteran employees. Responsibilities As a Security Analyst , you will assist the Subject Matter Expert (SME) and... ...ascertain the security posture of an Information Technology (IT) system Evaluate a wide array of IT devices for Security Technical...For contractorsWork experience placementWork at office- EY seeks an OT Senior Architecture & Governance Solution Analyst to drive architectural integrity, governance compliance, and effective... ...with cross-functional teams to ensure OT systems are secure, compliant, and continuously improved through structured governance...
- ...Information Security Analyst Our mission is simple. We make business travel less complicated for travelers, less costly for employers and more profitable for service providers. Using our industry-leading software solutions, employees book travel and car service and...Work at office
- Republic Services is seeking a Security Operations Analyst who will monitor security events across the RSOC, analyze incidents, and coordinate responses to protect assets across locations in the enterprise. The role requires experience with CCTV, access controls, and incident...Shift workNight shift
- Alignerr is seeking a Security Operations Analyst (AI Training) for a remote hourly contract. Bring 2+ years in SOC, incident response, and security operations to evaluate AI-driven detections and help shape how models detect, triage, and respond to threats. You will work...Remote jobHourly payContract workFreelanceFlexible hours
- CSAA Insurance Group is hiring a Security Analyst IV to support enterprise Data Loss Prevention (DLP) operations across cloud and on-prem environments... ...risks, and coordinating remediation with Cyber Defense, IT, Privacy, Legal, and Compliance teams. A strong background in...Remote job
- Job Title Security Analyst IV - DLP Monitoring & Response Location Remote position available across the United States (except Hawaii and Alaska... .... Partner with Cyber Defense, Security Engineering, IT, Cloud, Privacy, Legal, Compliance and business teams to validate...Remote workVisa sponsorship
- MedAire in Phoenix seeks an Aviation Intelligence professional with at least two years of aviation experience to deliver real-time security assessments for global aviation and maritime clients. You’ll monitor threats, conduct in-depth research, and support crisis...
- Position Summary The Security Operations Analyst will be responsible for monitoring, analyzing, and responding to security events and incidents that... ...Minimum Requirements 2-4 years of experience in Security, IT, Cyber Security, or related fields. Ability to work a...Contract workTemporary workRemote workShift workNight shift
- Empower AI in Fort Huachuca, AZ seeks a Security Analyst to support RMF activities and RMF A&A processes. The role requires active Secret clearance... ...liaison with SMEs and engineers to maintain compliant security controls across DoD IT environments. #J-18808-Ljbffr Empower AI
- Empower AI is hiring an Information Security Analyst I to assist with Risk Management Framework efforts, located in Fort Huachuca, Arizona. The successful candidate will work closely with Project Managers and Cybersecurity Engineers, ensuring compliance and managing cybersecurity...
$84.15k - $105.19k
...Corporate Office: 2355 W Pinnacle Peak Rd, Phoenix, AZ 85027 We are seeking a highly skilled and motivated Senior Information Security Analyst to join our team in the financial services sector. This role performs advanced security monitoring, investigation, platform administration...Permanent employmentWork at office- Tata Consultancy Services in Phoenix, AZ seeks an Info Security Analyst with 3+ years of experience to assess third-party SaaS risk, analyze user traffic, and advise on control effectiveness. The role emphasizes cloud security, SaaS governance, and industry standards compliance...
- Roles & Responsibilities Conduct comprehensive risk assessments of third-party SaaS providers, including evaluating security documentation, reviewing evidence, interviewing technical stakeholders, and assessing both control design and operating effectiveness Analyze user...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Security ANALYST - GRC. Be the first to apply!
Related searches
- application security analyst Phoenix, AZ
- entry level information security analyst Phoenix, AZ
- entry level security analyst Phoenix, AZ
- information security analyst Phoenix, AZ
- senior security analyst Phoenix, AZ
- rate analyst Phoenix, AZ
- IT security analyst Phoenix, AZ
- work from home security analyst Phoenix, AZ
- bond analyst Phoenix, AZ
- information security compliance analyst Phoenix, AZ



