Performs advanced (mid-level) information security analysis work, with a strong focus on cloud security and web application protection. Work involves assisting and monitoring security controls for on-premises and cloud-based information systems and infrastructure to regulate access to information resources and to prevent unauthorized modification, destruction, or disclosure of information. Researches, evaluates, and recommends security controls and procedures for the appropriate protection and reduction of risk for information resources. Evaluates business objectives and advises business partners on the security and compliance requirements and risks within various business initiatives, particularly those involving cloud migration and web application deployments. Develops, recommends, and evaluates the implementation of plans designed to safeguard information systems and information resources against accidental or unauthorized modification, destruction, or disclosure for agency-administered systems and third-party administered systems, including the configuration and management of Web Application Firewalls (WAF). Assists with developing system security plans and corrective action plans to protect information systems and information resources from unauthorized users. Independently interfaces with executive management throughout the agency and enterprise to assist the CISO in delivering the Information Security Program. Works under limited supervision, with considerable latitude for initiative and independent judgment. This position is open to permanent residents or US citizens only.