SLED Security Analyst, Information Security
Listed on 2026-09-12
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Presidio, Where Teamwork and Innovation Shape the Future
At Presidio, we're at the forefront of a global technology revolution, transforming industries through cutting-edge digital solutions and next-generation AI. We empower businesses - and their internal customers - to achieve more through innovation, automation, and intelligent insights.
This position is responsible for managing and maintaining all documentation, governance activities, compliance initiatives, and operational processes necessary to attain and maintain security authorizations and certifications supporting State, Local, Education, and Government (SLED) customers. The individual will possess strong knowledge of NIST-based security frameworks, including NIST SP 800-53 Moderate, FedRAMP, GovRAMP, StateRAMP, CJIS Security Policy, NIST Cybersecurity Framework (CSF), NIST SP 800-171, HIPAA, and related regulatory requirements.
The individual will be experienced in information security governance, risk management, compliance, authorization package development, audit readiness, security documentation, incident response planning, business continuity planning, and continuous monitoring activities. The position requires strong technical writing skills, the ability to analyze risk, develop policies and procedures, coordinate with technical and business stakeholders, and support enterprise-wide compliance initiatives.
Responsibilities Include:- Leads the development and maintenance of security architecture, governance frameworks, policies, standards, procedures, and control implementation guidance.
- Supports security authorization initiatives aligned to NIST SP 800-53 Moderate, FedRAMP Moderate, GovRAMP, StateRAMP, CJIS Security Policy, HIPAA, NIST SP 800-171, and related regulatory frameworks.
- Assembles, develops, maintains, and updates System Security Plans (SSP), supporting documentation, and authorization package artifacts.
- Maps implemented security control requirements to NIST SP 800-53 Moderate baselines, CJIS Security Policy, FedRAMP, GovRAMP, and other applicable control overlays.
- Documents implemented, inherited, hybrid, and customer-responsibility controls within authorization packages.
- Collects, validates, organizes, and maintains technical, administrative, and procedural evidence supporting compliance and assessment activities.
- Establishes and maintains centralized control evidence repositories utilizing governance and compliance management platforms such as Vanta or equivalent technologies.
- Supports independent assessors, auditors, regulators, customers, and internal stakeholders during assessments, walkthroughs, interviews, demonstrations, and evidence reviews.
- Develops, maintains, and tracks Plan of Action and Milestones (POA&M) documentation, remediation activities, corrective action plans, and risk mitigation efforts.
- Tracks security findings, compliance gaps, remediation activities, risk acceptances, and corrective action plans through closure.
- Evaluates existing information security policies, standards, procedures, and governance documentation and recommends improvements ensuring compliance with applicable frameworks.
- Develops, maintains, and updates compliance-aligned policies, standards, procedures, and governance documentation supporting authorization readiness.
- Defines roles, responsibilities, accountability requirements, and separation-of-duty controls supporting governance and compliance programs.
- Establishes processes supporting risk management, control assessment, continuous monitoring, and control validation.
- Aligns organizational security policies and governance requirements with implemented technical controls and operational practices.
- Develops and maintains governance framework documentation, security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).