Systems Analyst 3 (Security Engineer) - 26-01683

NavitasPartnersAustin, TX
16hHybrid

About The Position

The Security Engineer (Systems Analyst 3) will lead security governance, compliance, and risk management initiatives with a strong emphasis on System Security & Privacy Plans (SSP/SSPP) . This role bridges technical security operations and regulatory compliance, ensuring audit readiness, effective vulnerability remediation, and secure delivery of public-facing services across complex, multi-platform environments.

Requirements

  • 12+ years in: Governance, Risk, and Compliance (GRC)
  • 12+ years in: Enterprise Security & Security Architecture
  • 12+ years in: Vulnerability Management & Penetration Testing
  • 12+ years in: Cloud Security & Hybrid Environments
  • 10+ years : Owning SSP development end-to-end
  • 10+ years : Hands-on experience with CMS MARS-E v2.2 or comparable federal/state security frameworks
  • 10+ years : Control implementation documentation
  • 10+ years : Audit evidence collection & validation
  • 10+ years : POA&M creation, tracking, and remediation management
  • 8+ years : Translating technical security issues into compliance-aligned remediation actions
  • 8+ years : Stakeholder management across security, infrastructure, and application teams
  • 8+ years : Executive-level written and verbal communication
  • Knowledge of NIST 800-53, NIST RMF, and privacy controls
  • Knowledge of Secure SDLC and DevSecOps practices

Nice To Haves

  • 5+ years operating in multi-vendor, multi-platform environments
  • Proven ability to reduce repeat audit findings and improve compliance maturity
  • Experience mentoring teams on security governance best practices
  • Experience supporting HHSC systems, including SSP development and compliance

Responsibilities

  • Lead end-to-end System Security & Privacy Plan (SSP/SSPP) development, maintenance, and updates for enterprise systems
  • Drive remediation activities through POA&M management , ensuring timely closure of compliance gaps
  • Translate penetration testing and vulnerability findings into actionable remediation work items (EPICs/user stories)
  • Coordinate with application, infrastructure, and security teams to validate remediation via re-testing and documented evidence
  • Oversee risk-based vulnerability management, including prioritization and SLA-driven remediation
  • Provide governance oversight for: Endpoint protection Web application security Cloud security controls
  • Produce assessor-ready documentation, including: Configuration documentation Monitoring evidence Approvals Incident traceability
  • Support continuous audit readiness and reduce repeat findings through disciplined governance and documentation practices
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service