CybersecurityJobs.io
← Back to all jobs

Job Description

Advance the Office of Cybersecurity mission by helping protect information systems and supporting dependable security services across New Mexico. This onsite IT Security Analyst role (Santa Fe, NM) is designed for a security-focused professional who supports governance and compliance, strengthens security posture through technology and process improvements, and helps agencies meet applicable legal, safety, and quality standards.

Working with the State Chief Information Security Officer and a range of public-sector customers, you will contribute to SOC monitoring, risk management, incident response, and security services oversight for state agencies, K-12 public schools, higher education institutions, local governments, and tribal entities.

Compensation: USD 33 to 49 per hour. Experience: 2+ years in IT security or compliance validation.

Responsibilities

  • Assist with implementing proactive cybersecurity compliance strategies and identifying compliance risks
  • Improve technologies and processes to strengthen overall security posture
  • Support threat assessment, monitoring, and incident response strategies
  • Provide consultative and training services with a security-first focus
  • Manage cybersecurity services delivered to state agencies, K-12 public schools, higher education institutions, local governments, and tribal entities
  • Oversee the Code-Stack Vulnerability Scanning Program, including technical on-boarding, scoping, scanning operations, and coordination with agency development teams
  • Assist with creation and review of cybersecurity documentation, including security policies and procedures, plus configuration and change management plans
  • Ensure compliance with NIST 800 series and other applicable frameworks, and interpret regulatory requirements for stakeholders
  • Monitor systems and logs using SIEM tools to detect and respond to anomalies
  • Conduct threat hunting and analyze indicators of compromise (IOCs)
  • Review and update security tools to block malicious IPs and signatures
  • Escalate incidents and coordinate with state agencies and third-party partners; maintain documentation of investigative actions
  • Develop chat bots and data visualizations; automate and standardize SO C activities using SOAR for efficiency, precision, and scalability
  • Develop and implement automated response playbooks for SOC tasks such as alert triage, enrichment, correlation, containment, and notification
  • Provide oversight for risk assessments, audits, and vulnerability scans, and support investigations into cybersecurity incidents
  • Coordinate with internal and external teams to resolve incidents in line with policy; recommend and implement technical solutions to mitigate risks
  • Oversee services including VMaaS, Attack Surface Management (ASM), penetration testing, and user security awareness training
  • Participate in designing secure infrastructure and application solutions; deliver security awareness training and track participation
  • Respond to security inquiries from agencies and subscribers, and build trusted relationships with subscribers and partners

Requirements

  • Bachelor’s degree in Computer Science, Management Information Systems (MIS), Information Technology, Engineering, or similar technical field
  • Two (2) years of experience in IT security or compliance validation (for example: HIPAA, PCI)
  • Education and/or direct experience totaling six (6) years may substitute for the education and experience requirement
  • Certificate in IT security/forensics (e.g., CISSP, CEH, CCFP, CCSP, HCISPP, SSCP) or regulated compliance (e.g., PCIP, ASV, ISA, QSA) can substitute for one (1) year of experience
  • Must possess and maintain a current ID or Driver’s License
  • Pre-employment background investigation is required; employment is conditional pending results

Working Conditions

  • Primarily office-based, with extensive computer and phone use
  • Comfort working at a desk for extended periods and proficiency with standard computer equipment (keyboard, mouse, display)
  • Direct client interaction, meetings, and occasional travel
  • Physical requirements include the ability to lift up to 25 lbs and perform basic movements such as sitting, standing, bending, and reaching

Key Technologies

  • Code-Stack Vulnerability Scanning Program
  • SIEM tools
  • SOAR
  • NIST 800 series
  • VMaaS, Attack Surface Management (ASM)
  • HIPAA, PCI
  • Certifications listed include CISSP, CEH, CCFP, CCSP, HCISPP, SSCP, PCIP, ASV, ISA, QSA

Bargaining unit: This position is not covered by a collective bargaining agreement.

Similar Jobs