Senior IT Security Analyst
Job Description
The State of New Mexico is hiring a Senior IT Security Analyst for an onsite role in Santa Fe, NM with the New Mexico Health Care Authority (HCA). In this position, you will function as a Governance and Compliance Analyst, supporting audit readiness, cybersecurity governance policy development, and compliance activities tied to federal and state IT security requirements.
This role partners with staff, technical teams, vendors, regulatory auditors, and third-party security assessors to drive IT audit execution and continuous compliance. You will also contribute to risk analysis support, security documentation, and compliance training initiatives to help maintain an effective governance, risk, and compliance (GRC) posture for HCA and other state agencies.
Key Responsibilities
- Serve as the Governance and Compliance Analyst for the New Mexico Health Care Authority (HCA).
- Coordinate with staff, technical teams, and vendors to help ensure HCA compliance with federal and state IT security laws, regulations, policies, and procedures.
- Lead all IT related audits, including drafting, reviewing, and submitting audit correspondence, plans, and required documentation.
- Develop security and compliance policies and procedures for review by the Chief Information Security Officer (CISO) and Chief Information Officer (CIO).
- Coordinate and manage workflow tasks associated with cybersecurity compliance and training initiatives, including:
- Coordinating tasks for ongoing audits.
- Cybersecurity policy development and lifecycle management.
- Co-administering the Governance, Risk and Compliance (GRC) program.
- Develop cybersecurity governance policies, procedures, standards, and guidelines.
- Perform audits and monitoring to verify compliance with security policies, standards, and procedures.
- Coordinate and collaborate with internal teams, regulatory auditors, and third-party security assessors.
- Provide input into developing, reviewing, and implementing enterprise wide security policies and standards.
- Participate in defining project requirements and designing secure infrastructure solutions.
- Support risk analysis and risk management processes, including identifying acceptable residual risk.
- Conduct impact analysis and analyze security reports to recommend mitigation strategies.
- Create, update, and maintain documentation for security risks, controls, and remediation activities.
- Review user accounts and access requests against authorized permissions.
- Assist with data classification, disaster recovery planning, and forensic investigations.
- Review and report security procedure violations and monitor emerging security threats.
- Assist in developing safeguards to protect system configurations and prevent unauthorized changes.
- Provide expertise for security awareness training to support continued compliance.
- Develop and report Corrective Action Plans (CAP) and maintain Plans of Actions and Milestones (POAM).
Requirements
- Bachelor’s degree in Computer Science, Management Information Systems (MIS), Information Technology, Engineering, or a similar technical degree, plus three (3) years of experience in IT security or compliance validation (for example HIPAA, PCI).
- Any combination of related education and/or direct experience in this occupation totaling seven (7) years may substitute for required education and experience.
- A certificate in IT security/forensics (e.g., CISSP, CEH, CCFP, CCSP, HCISPP, SSCP) or regulated compliance (e.g., PCIP, ASV, ISA, QSA) can substitute one (1) year of experience.
- Must possess and maintain a valid Driver’s License.
- Must obtain a Defensive Driving Certificate.
- Employment is subject to a pre-employment criminal background investigation and is conditional pending results.
Working Conditions
- Office environment.
- Many requests arrive by phone or in-person, requiring clear speaking and response to requesters.
- Extended periods seated in front of a computer.
- Ability to operate a computer, keyboard, and mouse.
- Occasional travel, occasional night/weekend/holiday work, and call-back work.
Agency / Customer Information
- Health Care Authority (HCA)
- Other State Agencies
Pay and Location
- Location: Santa Fe, NM (onsite)
- Salary: USD 36 - 54 per hourly
Additional Information
- Bargaining unit position: This position is not covered by a collective bargaining agreement.
- Agency contact: Theresa Romero, (505) 394-2977. Email