Technical Security Risk & Governance Analyst

Adept Consulting Services, Inc.
Harrisburg, PA

Adept Consulting Services is expanding its team and is in search of a Technical Security Risk & Governance Analyst . Our goal is to ensure that our clients not only meet their current IT requirements but also anticipate and manage future challenges effectively.

In this role, you will be responsible for identifying, assessing, and mitigating technical security risks while supporting the governance framework for our client. You will analyze security policies and practices, ensuring they comply with industry standards and applicable regulations. Your expertise will be critical in developing and implementing security strategies that protect sensitive data and maintain the integrity of IT systems.

As a Technical Security Risk & Governance Analyst, you will work closely with cross-functional teams, conducting regular risk assessments, audits, and security reviews. Your strong analytical skills combined with excellent communication abilities will enable you to convey complex security concepts to both technical and non-technical stakeholders.

Requirements

Key Responsibilities

Risk Assessment & Control Assurance

·Conduct technical security risk assessments for on‑prem, cloud (IaaS/PaaS/SaaS), and hybrid solutions; document risks, likelihood/impact, and recommended mitigations.

·Perform control design/operating‑effectiveness testing against NIST CSF/800‑53, CIS Controls, ISO/IEC 27001, and agency security standards.

·Support Authority to Operate (ATO) processes,security attestations, and continuous monitoring.

·Facilitate threat modeling and security architecture reviews; advise on secure patterns (network segmentation, IAM,least privilege, encryption, logging).

Governance & Compliance

·Maintain security policies, standards,procedures, and control libraries; align updates with legislative or regulatory changes.

·Map agency controls to relevant mandates (e.g.,CJIS, IRS 1075, HIPAA, FERPA, PCI DSS, state statutes/policies) and track compliance gaps.

·Coordinate internal/external audits; lead evidence collection, responses, and remediation plans.

·Administer or contribute to GRC tooling for issues, exceptions, and risk registers.

Vulnerability& Third‑Party Risk

·Establish governance for vulnerability management (SLAs, exception management, risk acceptance); monitor patching and remediation progress.

·Perform vendor/security reviews (SaaS, MSPs,cloud providers), evaluate SOC 2/ISO certifications, and negotiate security clauses with procurement/legal.

·Review data protection, encryption, and privacy risks in new procurements and major system changes.

Metrics, Reporting & Communication

·Develop and maintain dashboards and performance indicators (risk posture, control maturity, vulnerability closure rates); brief leadership on trends and priorities.

·Produce clear, actionable reports for technical teams and non‑technical stakeholders.

·Promote security awareness and targeted training(e.g., secure configuration, privacy by design, third‑party onboarding).

Incident& Change Advisory Support

·Provide risk-informed guidance during incident response (root cause, control gaps, corrective actions).

·Review change requests for security impacts;ensure appropriate testing, logging, and rollback plans.

Required Qualifications

·Bachelor’s degree in Information Security,Computer Science, Information Systems, or related field; OR equivalent experience.

·1–3 years in information security, risk management, audit, or related technical role.

Preferred Qualifications (not required)

·CISSP, CISM, CRISC, CGRC (CAP), Security+, CCSK/CCSP,CISA

·Vendor/cloud certs (AWS/Azure/GCP security specialty) are a plus.

Knowledge

·Security frameworks and regulations: NIST CSF/800‑53, CIS Controls, ISO 27001; familiarity with CJIS, IRS Pub 1075,HIPAA, FERPA, PCI DSS, and state policy.

·Core security domains: identity and access management (IAM), network security, endpoint security, vulnerability management, logging/SIEM, encryption/PKI, secure DevOps.

·Cloud security concepts (shared responsibility, CSPM, workload protection, KMS/CMKs, conditional access, zero trust).

Skills

·Technical assessment and control testing;ability to validate configurations and interpret scan results

·Risk analysis and documentation; creating practical risk treatment plans and exceptions with compensating controls.

·Using GRC platforms; building workflows, control libraries, and risk registers.

·Data analysis and dashboarding (Excel/Power BI),concise report writing, and presentation to executives.

Abilities

·Translate technical findings into business risk terms and prioritized actions.

·Collaborate across IT, operations, legal,procurement, and program areas; influence without authority.

·Handle multiple assessments and deadlines;maintain confidentiality and sound judgment.

·Continuous learning and adapting to new threats,technologies, and mandates.

Work Conditions & Requirements

·Background check per state policy; may require CJIS/IRS Pub 1075 clearance depending on data systems.

·Occasional travel to agency sites or data centers.

·Participation in after‑hours change windows or incident support as needed.

·Hybrid/telework eligibility per agency policy.

Performance Measures

·On‑time completion of risk assessments and control tests.

·Reduction in high/critical findings; SLA adherence for remediation.

·Audit outcomes (deficiency reduction, timely corrective actions).

·Governance deliverables (policy refresh cycle,control library currency).

·Stakeholder satisfaction and effectiveness of risk communications.

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan
  • Paid Time Off
Posted 2026-02-19

Recommended Jobs

Sr Dir, Financial Controller

Pennsylvania

Sr. Director Financial Controller The Sr Director, Financial Controller provides enterprise‑level leadership for global accounting operations across the U.S., UK, Philippines, and Chile. This ro…

View Details
Posted 2026-01-17

Project Controls Manager

Otak
Philadelphia, PA

Project Controls Manager establishes and operates the integrated project controls framework to manage overall project performance across Scope, Schedule, Cost, Risk and interfaces. He/She leads th…

View Details
Posted 2026-02-10

Cathodic Protection Technician

KTA-Tator, Inc.
Philadelphia, PA

: Elzly Technology Corporation (Elzly) is seeking a full-time employee to assist in performing cathodic protection inspections within the city of Philadelphia extending through South Jersey. Work…

View Details
Posted 2026-02-09

Human Resource (HR)

Accela Healthcare
Philadelphia, PA

Accela Rehab & Care Center at Somerton Address: 650 Edison Ave, Philadelphia, PA 19116 Now Hiring: Human Resources Coordinator Overview: We are currently seeking a dedicated and experience…

View Details
Posted 2026-01-29

Assistant Medical Director in Erie, PA

St. Vincent Health System - Erie
Erie, PA

Advance your career in leadership as an assistant facility medical director in Northwestern Pennsylvania. Are you a board-certified anesthesiologist with a strong background in leadership, ready to e…

View Details
Posted 2026-02-18

Optician/Customer Service

Gettysburg, PA

Optician/Customer Service Join our team as an Optician providing expert eyewear guidance and exceptional patient-focused vision care daily. Company Profile Long established eyewear supplier …

View Details
Posted 2026-02-12

Over the Road - Truck Driver

Lion Freight Systems Inc
Pennsylvania

Now Hiring CDL-A Dry Van Drivers! Job Details: This OTR dry van position offers strong weekly pay between $1,800 and $2,300 , based on $0.60 per mile with 3,000–5,000 paid miles each week . …

View Details
Posted 2026-01-19

Truck Driver - CDL A (Mon-Fri 2:30am-4:30am Start)

John Vena Inc.
Philadelphia, PA

​ ​ ​  Truck Driver - CDL A Shift: Monday - Friday, 2:30am - 4:30am start Type: Full-Time Pay Rate: $24 - $28 per hour depending on experience Start Date: ASAP Job Overview Brin…

View Details
Posted 2026-02-18

Milieu Internship (Master's Level)

Elwyn
Media, PA

Overview: Join a Team That Changes Lives For more than 170 years, Elwyn has been leading the way in supporting children, teens, and adults with autism, intellectual and developmental disabilities,…

View Details
Posted 2026-02-11

Experienced A or B Automotive Technician

Stuckey Ford
Hollidaysburg, PA

Looking for a rewarding career? A place you can grow and learn while on the job? Stuckey Automotive is looking for enthusiastic, skilled and certified automotive technicians who want to take the next …

View Details
Posted 2025-08-29