×
Register Here to Apply for Jobs or Post Jobs. X

Cyber Security Analyst

Job in Virginia, St. Louis County, Minnesota, 55792, USA
Listing for: Novalink Solutions
Full Time position
Listed on 2026-03-06
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, Data Security, IT Consultant
Salary/Wage Range or Industry Benchmark: 60000 - 80000 USD Yearly USD 60000.00 80000.00 YEAR
Job Description & How to Apply Below

Augusta, United States | Posted on 03/03/2026

  • Actual Job Title Cyber Security Analyst 3
  • Job Type FT Contract
  • Contract duration 1 year
  • Date Opened 03/03/2026
  • Target Date 03/06/2026
  • City Augusta
  • State/Province Maine
  • Country United States
  • Assigned Recruiter(s) Nagaraj Murugan
  • Number of Positions 1
Job Description

Job Description:

The Cyber Security Analyst III (CSA3) within the State’s Information Security Office (ISO) will be responsible for evaluating, analyzing, and assessing cybersecurity risks associated with new technologies, proposed solutions, and third-party vendors. This includes reviewing vendor security attestations, assessing architectural designs, validating security controls, and supporting statewide procurement decisions through structured risk assessments.

This role will also support the development and maturation of the State’s Third-Party Risk Management (TPRM) program, including the enhancement and operation of tools such as Black Kite. Additionally, the CSA3 will assist with evaluating cybersecurity waiver submissions requiring deeper technical analysis and will help maintain the statewide risk register to ensure tracking and remediation of risks that exceed the State’s risk tolerance.

KEY RESPONSIBILITIES:

New Technology & Solution Security Reviews:

Conduct security reviews for new technologies, cloud services, applications, and proposed solutions.

Review architectural diagrams to verify appropriate security controls, configurations, and data-protection mechanisms.

Assess alignment with State of Maine security requirements and applicable regulatory or compliance standards.

Develop and document risk assessments with actionable recommendations to support procurement and technology-adoption decisions.

Security Attestation & Third-Party Assessment:

Review and analyze third-party cybersecurity attestations, including SOC 2 Type II, ISO 27001 certifications, external penetration tests, and security questionnaires.

Identify control gaps, inherited risks, and areas requiring additional compensating controls.

Coordinate with procurement, legal, and business stakeholders during vendor onboarding and technology evaluation.

Third-Party Risk Management (TPRM) Program Support:

Assist in developing, enhancing, and maintaining the statewide TPRM program.

Leverage and operationalize TPRM tools, including Black Kite, to support ongoing monitoring, vendor tiering, and risk scoring.

Contribute to the creation of policies, processes, templates, and guidelines that mature the third-party risk-evaluation process.

Governance, Risk & Compliance (GRC) Platform Support (Archer IRM):

Utilize the Archer GRC platform to document risk assessments, waiver reviews, and remediation tracking activities.

Support the continued implementation and refinement of Archer workflows related to enterprise risk management.

Contribute to data quality, reporting accuracy, and process improvements to enhance risk visibility and governance maturity.

Waiver Review & Technical Risk Analysis:

Support the review of security waiver requests that require deeper technical analysis to evaluate risks of temporary control exceptions.

Document findings, risk impacts, and recommended mitigation strategies to inform risk acceptance decisions.

Assist in maintaining the statewide security risk register, ensuring risks are documented, categorized, and updated.

Track remediation progress and validate completion for risks that exceed established tolerance thresholds.

Collaborate with stakeholders to monitor deadlines, escalate overdue items, and verify mitigation plans remain effective.

MINIMUM QUALIFICATIONS:

Demonstrated experience in cybersecurity analysis, technology or architecture review, third-party or solution security evaluations, or related security-engineering activities. Familiarity with cybersecurity standards, control frameworks, and risk-management practices applicable to government environments is strongly desired.

KNOWLEDGES, SKILLS, AND ABILITIES

REQUIRED:

Strong understanding of cybersecurity principles, best practices, and control frameworks (e.g., NIST CSF, NIST 800-53).

Demonstrated ability to interpret SOC 2 Type II reports, ISO 27001 certifications,…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary