Security Analyst-Project Lead
Listed on 2026-08-05
-
IT/Tech
Cybersecurity, IT Business Analyst, IT Consultant, IT Support
Security Analyst Project Lead
DHEC actively strives to conduct routine, special, and investigative audits to assist the Board and DHEC Management in assessing and improving agency programs and operations. The Security Analyst Project Lead under limited supervision will plan, manage, and conduct Information Technology audits and activities for the Office of Internal Audits. This position will plan and analyze IT systems leveraging COBIT, COSO, ISO, ITIL, NIST, and other relevant frameworks, regulations, and guidelines.
The applicant selected for this opening will be required to travel and conduct routine, special, and/or investigative audits at agency sites located throughout the entire state of South Carolina. The applicant selected will work primarily under the general guidance of the Office of Internal Audits but will also be required to work closely with other teams and Agency staff at all levels.
Applicant should be self-motivated, team-oriented, work under limited supervision, and respond to priority tasks as needed.
DAILY
DUTIES / RESPONSIBILITIES:
The Security Analyst Project Lead will be responsible for planning and conducting Information Technology (IT) audits and activities of the agency for the Office of Internal Audits.
Responsibilities include:
- Identifies risks and evaluates internal controls in information system environments.
- Assist the Internal Audit Director in developing and managing IT Continuous Auditing Programs
- Plans and analyzes IT systems leveraging COBIT, COSO, ISO, ITIL, NIST, and other relevant frameworks, regulations, and guidelines.
- Performs test of design and operating effectiveness over IT general controls.
- Reviews the selection and implementation of IT technical controls.
- Validates baseline security configuration for operating systems, application, networking and telecommunications equipment.
- Prepares working papers and reports to support recommendations and conclusions with related IT standards.
- Develops, builds, and implements tools to analyze data to improve audit efficiency and effectiveness, including risk assessments.
- Provides analytics to be used to incorporate best practices in continuous auditing.
- Performs risk assessments (e.g., data security, IT Governance, Disaster Recovery)
- Provides IT input to Internal Audit Director in development of the Annual Five Year Audit Plan to improve IT compliance and effectiveness of DHEC's information systems environment.
- Follows up on recommendations made by external auditors or outsourced firms on IT external audit reports; as well as recommendations made from IT internal audit reports.
- Utilizes data analytics software to assist OIA with auditing, consulting, and special reviews.
- Performs data extractions, analytical testing and security reviews utilizing Audit Command Language (ACL) and other analytical tools.
- Provides IT technical support for the Office of Internal Audits (e.g., hardware, software, ACL, etc.).
The position will be utilized for 40 hours per week for the duration of this project. The selected candidate should be able to work flexible hours where it may be necessary for work to be completed outside traditional business hours. The applicant will work closely with the Internal Audits team to identify, prioritize, and schedule audits to maintain compliance. The applicant will work closely with customer and subject matter experts for the system design, migration to the new framework, and testing.
This will also include compliance to DHEC internal audits policies and procedures, as well maintaining strict confidentiality of audit results and remediations. Module support of the project.
REQUIRED
EDUCATION:
Bachelor's degree in a related area AND 1-3 years of experience in the field or in a related area.
REQUIRED SKILLS (RANK IN ORDER OF IMPORTANCE):
- Experience in projects involving PCI/NIST security implementations and/or audits.
- Accounting, audit experience.
- Experience working with risk management, ITIL.
- Knowledge of Information Technology field, best practices, organization, and operations.
- Verbal communication skills, written communication skills, organizational skills.
- Flexible and easily adapts to changing priorities.
CERTIFICATIONS:
PREFER A CISA, CIA, OR CPA
PREFERRED SKILLS (RANK IN ORDER OF IMPORTANCE):
- Knowledge of the frameworks and standards for information systems auditing (i.e., COBIT, COSO, ISO, ITIL or NIST) as well as generally accepted government auditing standards (GAGAS) and/or generally accepted accounting principles (GAAP).
- Ability to integrate technical systems with agency goals and objectives.
- Working knowledge of ACL or other auditing software and the ability to analyze and interpret complex accounting.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).