Security Analyst
Listed on 2026-08-27
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Madison, United States | Posted on 08/24/2026
The Department of Health Services (DHS) is one of the largest and most diverse state agencies in Wisconsin. DHS
employs more than 7,000 staff spanning ten divisions and offices and seven 24/7 institutions located throughout
Wisconsin. Programs and services administered by DHS include Medicaid and other human service programs, alcohol
and other drug abuse prevention services, mental health, public health, and long-term care.
The Information Security Section (ISS) serves the Department by creating an information security culture and enabling
the business. We are metrics minded, employee focused, and view security as a service. ISS is responsible for
- Identifying and continuously assessing risk
- Developing, institutionalizing, and improving strategies to mitigate risk
- Limiting the potential effects of information security events
- The selection, assessment, authorization, and monitoring of security controls while contributing to the overall information security plan.
The Information Security Section (ISS) is functionally organized into Security Awareness and Governance, Compliance, Architecture, and Portfolio Management. Cross-team collaboration is essential to our success.
The DHS Liaison serves the Division of Medicaid Services and is the champion for security initiatives integrating
information security into program operations. This work is completed by engaging other security staff, communicating
risk, and developing strategies to reduce risk. To successfully do this work, one must possess strong communication and
interpersonal skills capable of presenting to diverse audiences including executive and non-technical individuals.
A federally recognized (ANSI) information security certification must be obtained within 6 months of the start date and
maintained for this position. The Department of Defense (DOD) 8570 Baseline Certifications defined by Defense
Information Systems Agency (DISA) is the baseline to consider when reviewing the relevance of the certification.
Goals and Worker Activities1. Integrate security into program operations
- Partner with organizational leaders to incorporate information security best-practices into technical and
- Provide recommendations on how to improve the information security posture of programs and reduce risk.
- Communicate risks in simple and comprehensible terms. Provide options to mitigate risk considering business impact.
- Draft security requirements to be included into charters, scope documents, procurements.
- Document and communicate analysis. Answer clarifying questions.
- Escalate to ISS leadership if an acceptable level of risk cannot be achieved
- Be a solutions-focused advocate.
- Intake projects and other program initiatives and champion them through the appropriate ISS workstream
- Gather information as needed so that security team can perform thorough analysis
- Communicate workstream deliverables to the customer. Verify that the deliverable meets the customer need, follow-up on any clarifications.
- Coordinate across ISS meeting their security-focused needs
- Coordinate with other BITS staff, Office of Legal Counsel, Bureau of Procurement and Contracting, and other program staff as needed in order to arrive to an outcome
- Responsibility and authority will vary based on the use case and customer need.
- Request and/or gather artifacts demonstrating compliance.
- Schedule/facilitate communications between auditor/incident response, vendors, technical teams, and other program stakeholders.
- In partnership with ISS, assess audit results and develop corrective action plans/plans of action and milestone.
- Provide oversight to the resolution, test for compliance, and request authority to close.
- Respond to regulatory inquiry and draft documents as needed
- Back-up other security liaison roles
- Draft and deliver status reports
- Establish and maintain positive working relationships with stakeholders
- Establish and documents standard operations for…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).