Information Security Analyst
Job Description
Seminole County, FL is seeking an Information Security Analyst to help protect the County’s digital assets, infrastructure, and data. This onsite role in Sanford, FL focuses on building and sustaining practical security standards and procedures aligned to the NIST framework and NIST CSF, supporting compliance, strengthening risk management, and improving the County’s incident response readiness.
What you’ll do
- Establish, develop, monitor, and maintain information security standards, procedures, and practices based on the NIST framework to support a more secure enterprise environment.
- Maintain compliance with security policies and standards, and ensure controls are implemented, monitored, administered, and maintained.
- Support audits and risk assessments, including assisting with documentation for external audits and regulatory bodies.
- Conduct risk assessments and recommend mitigation strategies for existing and new systems.
- Perform vendor risk and access reviews, including security assessments of third-party vendors and service providers.
- Review vendor security questionnaires and evaluate risk related to data handling practices, access controls, and compliance posture.
- Collaborate with procurement, legal, and risk teams to ensure contracts include appropriate security and data protection clauses.
- Maintain a vendor risk register, track remediation efforts, and reassess vendor risk periodically while monitoring changes in exposure.
- Support incident response efforts, including participating in security investigations and helping coordinate remediation or recovery.
- Enforce security measures that support the confidentiality, integrity, and availability of information assets.
- Lead and evolve security awareness and education initiatives through training programs and educational materials such as newsletters, phishing simulations, and policy guides.
- Track training participation and effectiveness, and adjust content based on emerging threats and County needs.
- Continually improve job knowledge by tracking emerging security threats, standards, practices, and security products.
- Act as a security liaison across departments and agencies, promoting security best practices and helping interpret security framework and regulatory or policy implications.
- Review, test compliance, and recommend remediation for security practices, policies, and procedures.
- Recommend processes and technologies that improve the County’s security posture.
- Perform other related work as required.
What you bring
- Bachelor’s Degree in an associated field.
- 3 years of experience in enterprise Information Technology security and cybersecurity roles.
- Preference for candidates with information security or cybersecurity certifications.
- Ability to work with a high degree of teamwork, coordinate with customer departments, and use independent judgment.
- Experience with information security or cybersecurity technologies, processes, and policies, plus general knowledge of information technology infrastructure and systems.
- Effective communication skills for working with team members, customers, citizens, executive leadership, and elected officials.
- Ability to learn new concepts quickly and resolve complex technical problems effectively.
- Excellent oral and written communication skills, with the ability to organize and prioritize tasks successfully.
- Must possess and maintain a valid Florida Driver’s license.
Compensation: USD 30 to 36 per hour.
Technologies: NIST framework, NIST CSF.