You are viewing a preview of this job. Log in or register to view more details about this job.

IT Security Audit Compliance Specialist

Job Title: IT Security Audit Compliance Specialist

Job Requisition ID: 39824

Closing Date: 07/25/2024

Salary: $6,005-$8,678

Work Hours: M-F 8:30 AM-5:00 PM

Work Location: (Hybrid) 100 South Grand Ave E, Springfield, Illinois, 62762  

Union Position: Yes

Work Authorization: The State of Illinois does not provide sponsorship for employment visa status and cannot accept F1 OPT/CPT. To be considered for permanent employment with the State of Illinois, applicants must be legally authorized to work in the United States without the need for employer sponsorship now or at any time in the future.

 

Are you looking for a rewarding career with an organization that values their staff? The Department of Innovation & Technology (DoIT) is seeking to hire qualified candidates with the opportunity to work in a dynamic, creative thinking, problem solving environment. 

This position serves as an IT Security Audit Compliance Specialist supporting the Illinois Department of Human Services (DHS).  

In this role, you will design and modify data processing system and operations documentation and investigate internal and external information security risks and exception assessments.  

In addition, you will program, test and code moderately difficult programs. 

If you possess these knowledges, skills, abilities, and experience, we invite you to apply for this position to join the DoIT Team!

 

As a State of Illinois employee, you receive a comprehensive benefits package including:

  • Competitive Group Insurance benefits including health, life, dental and vision plans.
  • Flexible work schedules (when available and dependent upon position)
  • 10 -25 days of paid vacation time annually (10 days for first year of state employment)
  • 12 days of paid sick time annually which carryover year to year
  • 3 paid personal business days per year
  • 13-14 paid holidays per year dependent on election years
  • 12 weeks of paid parental leave
  • Pension plan through the State Employees Retirement System
  • Deferred Compensation Program – voluntary supplemental retirement plan
  • Optional pre-tax programs -Medical Care Assistance Plan (MCAP) & Dependent Care Assistant Plan (DCAP)
  • Tuition Reimbursement Program and Federal Public Service Loan Forgiveness Program eligibility

 

For more information regarding State of Illinois Benefits follow this link: https://www2.illinois.gov/cms/benefits/Pages/default.aspx
 

Essential Functions

35% Under general supervision, serves as an IT Security Audit Compliance Specialist for the Department of Innovation & Technology (DoIT) supporting the Department of Human Services (DHS):

  • Designs and modifies data processing system and operations documentation.
  • Develops logic to produce a specific task or series of tasks.
  • Creates written programming specifications using Excel, Word, SQL or other programming languages and coordinates the assignments of tasks.
  • Implements processes, such as GRC (governance, risk and compliance), to automate and continuously monitor information security controls, exceptions, risks, testing.
  • Compiles reporting metrics, dashboards, and evidence artifacts.
  • Performs cross-checks and auditing procedures to ensure accurate and reliable information services practices.
  • Utilizes regulatory frameworks such as PCI DSS, HIPAA, MARS-E, NIST 800-53, or IRS Pub 1075 in performance of duties.

 

30% Confers with Unit Supervisor and co-workers to determine requirements for individual tasks or projects of limited size:

  • Analyzes and revises agency work procedures to adapt to changes of the user and data processing procedures.
  • Investigates internal and external information security risks and exception assessments
  • Assesses incidents, vulnerability management, scans, patching status, secure baselines, penetration test result, phishing, and social engineering tests and attacks.
  • Makes recommendations on the feasibility of revising existing operations or adapting new applications.
  • Interviews users to determine the technical requirements for complying with specific requests and quality assurance reviews.

 

25% Programs, tests, and codes moderately difficult programs:

  • Determines and corrects program deviations.
  • Assists in detailed studies and analysis of data processing functions, methods, and procedures.
  • Prepares system and program flowcharts, creates system production documentation, and analyzes program test materials, output reports, file dumps, etc. to ensure accurate program results.

 

5% Keeps abreast of new developments in the development of detailed systems design and programming field:

  • Continues education by attending meetings, training sessions, seminars, and conferences to increase familiarity with and remain current on products, vendors, techniques, and procedures.
  • Attends demonstrations and exhibitions related to assigned operations.

 

5% Performs other duties as required or assigned which are reasonably within the scope of the duties enumerated above.

 

Minimum Qualifications

  1. Requires knowledge, skill, and mental development equivalent to completion of two (2) years of college with course work in computer science or directly related fields.
  2. Requires one (1) year of professional experience in Application Services or related Information Technology experience.

Preferred Qualifications

  1. One (1) year of related Information Technology experience in cyber security, security programs, or compliance assurance.
  2. One (1) year of professional experience working in an audit environment that includes coding to retrieve audit data.
  3. One (1) year of professional experience creating metrics (KPI/KRI) and reporting, including creating and displaying reports.
  4. One (1) year of professional experience conducting technology and cybersecurity risk assessments and creating risk profiles.
  5. One (1) year of professional experience identifying and mitigating security vulnerabilities.
  6. Working knowledge of the major regulatory frameworks such as PCI DSS, HIPAA, MARS-E, NIST 800-53, or IRS Pub 1075.
  7. Working knowledge of information security best practices.
  8. Ability to analyze data logically and exercise sound judgement in defining and evaluating problems of an operational or procedural nature.
  9. Developed verbal and written communication skills to present technical information to others with clarity and precision.

Conditions of Employment

NOTE: Applicants must possess the ability to meet ALL of the following conditions of employment, with or without reasonable accommodation, to be considered for this position. 

  1. Requires the ability to verify identity.
  2. Requires employment authorization to accept permanent full-time position with the State of Illinois.
  3. Requires the ability to pass a position specific, agency required background check.
  4. Requires self-disclosure of criminal history.
  5. Requires the ability to use agency supplied equipment such as laptop, personal computer, work cell phone and any other required equipment or devices.
  6. Requires the ability to travel in performance of duties.
  7. Requires the ability to serve in an on-call capacity.
  8. Requires the ability to work overtime including scheduled, unscheduled, short notice, evenings, weekends, and holidays.
  9. Requires the ability to attend seminars, conferences, and training to remain current on methods, tools, ideologies, or other industry related topics relevant to job duties.
  10. Requires the ability to lift and carry objects or equipment weighing up to 20 pounds.  This is considered light work as defined by the U.S. Department of Labor (20 CFR 404.1567(b)). Light work involves lifting no more than 20 pounds at a time with frequent lifting or carrying of objects weighing up to 10 pounds.

The conditions of employment listed are incorporated and/or related to any duties included in the position description.