Cybersecurity Security Analyst - SecOps ; Contracted/Temporary
Listed on 2026-01-16
-
IT/Tech
Cybersecurity, Information Security, Data Security, IT Consultant
Cybersecurity Security Analyst – Sec Ops Support (Contracted/Temporary)
This is a 4‑month contracted/temporary position.
About the OrganizationThe Commonwealth of Massachusetts Executive Office of Economic Development (EOED) supports economic growth by fostering business development, infrastructure investment, industry advancement, and consumer confidence. EOED operates through nine state agencies and five quasi‑public agencies (QPAs) that deliver essential public programs and services. The office embraces a culture of equity, inclusion, and collaboration—values that inform all aspects of its work.
About the RoleThe EOED is seeking a junior‑level Cybersecurity Security Analyst (Contractor) to support day‑to‑day Security Operations (Sec Ops), governance, risk, and compliance activities under the direction of the EOED Chief Information Security Officer (CISO) and in coordination with the Commonwealth’s Executive Office of Technology Services and Security (EOTSS). The contractor will work in a fast‑paced public‑sector environment supporting EOED’s mission‑critical systems, data, and users, with a strong emphasis on vulnerability management, identity and access controls, and compliance execution.
Dutiesand Responsibilities Security Operations & Vulnerability Management
- Support EOED’s vulnerability management program, including reviewing vulnerability scan results, tracking remediation activities, coordinating with IT and application owners, assisting with tooling workflows (e.g., Tenable, Veracode), reporting, and documentation.
- Update the Application Inventory records with security metadata and coordinate stakeholder input.
- Validate remediation actions and update tracking systems accordingly.
- Provide hands‑on support for GRC and compliance activities: evidence collection, documentation, control mapping, and impact tracking.
- Assist with maintaining compliance artifacts aligned with NIST Cybersecurity Framework (CSF), NIST Risk Management Framework (RMF), and Commonwealth of Massachusetts / EOTSS Enterprise Information Security Policies.
- Support tracking of risks, findings, and remediation plans in Service Now, Jira, and other EOED‑approved systems.
- Assist with user access reviews, role validation, and privileged access reviews.
- Support identity lifecycle activities including onboarding, off‑boarding, and access changes.
- Help ensure access controls align with least privilege and Commonwealth security standards.
- Execute tasks and assignments documented in Jira, Service Now, AIRS, email, and other tracking tools.
- Maintain clear, accurate, and timely documentation of work performed.
- Communicate effectively with technical and non‑technical stakeholders.
- Escalate issues, risks, or blockers appropriately to the EOED CISO.
- Assist with other Sec Ops activities as needed, including incident response support, security awareness initiatives, and ad‑hoc security projects.
- Develop familiarity with EOED systems, data, and business processes, including emerging areas such as AI risk and data security.
- Foundational understanding of information security principles and practices.
- Strong analytical skills with the ability to follow documented instructions and execute tasks accurately.
- Excellent written and verbal communication skills.
- Ability to manage multiple tasks and priorities in a structured, regulated environment.
- Proficiency with Microsoft Office (Word, Excel, PowerPoint, Outlook).
- Ability to work independently while collaborating effectively as part of a security team.
- Strong attention to detail and accountability.
- Exposure to or familiarity with vulnerability management tools (e.g., Tenable, Veracode), GRC activities, and IAM processes.
- Awareness of or willingness to learn NIST CSF, NIST RMF, Commonwealth of Massachusetts / EOTSS security policies and standards, data security, and emerging AI risk management considerations.
- Prior experience in a public sector, government, or regulated environment is a plus.
- Timely…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).