Data First Jobs

ATC

Security Analyst

Contract · In Office · Madison, Wisconsin (USA)

Posted Jul 7, 2026

Work Options
Job Type
Position Group
  • REQUIRED SKILLS: (Need Most)
  • • 2+ years of experience applying NIST Cybersecurity Framework, NIST RMF, and
  • other common security standards.
  • • 2+ years of experience in development, approval, and implementation of security
  • documents (policies, standards, etc.).
  • • 2+ years of experience in triaging and analyzing cybersecurity alerts.
  • • 2+ years of experience and working knowledge of common security frameworks
  • and control theories, including current applicable NIST, CJIS, and ISO standards.
  • • 2+ years of experience creating and leading discussions around the
  • implementation and artifact collection of NIST 800-53 controls.
  • • Proficiency in triaging and analyzing cybersecurity alerts using enterprise
  • technologies and tools.
  • • Familiarity with phishing mitigation strategies and email threat analysis.
  • • Incident response forensics and remediation, including CrowdStrike, sandbox
  • evaluation and detonation, phishing evaluation, malicious website identification,
  • and malicious intent identification.
  • • Customer service as it pertains to security incident management and
  • communication with end users about dangerous behavior.
  • • Excellent technical writing and documentation skills, including incident reports
  • and playbook development.
  • • Ability to work independently and as part of a distributed team to achieve shared
  • objectives.
  • • Experience in effective methods of written and oral communication, meeting
  • facilitation, and presenting to both technical and non-technical staff appropriate to
  • audience and scenario.
  • • Experience with techniques used to establish and maintain effective working
  • relationships with peers and customers.
  • • Knowledge of information security risk activities, including risk assessments, risk
  • registers, and risk management.
  • • Knowledge of state and federal laws regarding information security, such as
  • HIPAA Security Rule, and experience with audit and compliance activities in
  • conjunction with state and federal partners/regulators such as the WI Legislative
  • Audit Bureau and the U.S. Department of Justice.
  • • Strong knowledge of threat detection, incident response, and log analysis
  • techniques.
  • • Working knowledge of vulnerability management practices, technologies, and
  • tools.
  • • Ability to analyze threat intelligence and apply it to strengthen detection and
  • response mechanisms.
  • • Ability to collaborate with cross-functional teams, including DOA/DET,
  • infrastructure, and development staff.
  • • Commitment to continuous learning, professional development, and information
  • sharing.

NICE TO HAVE SKILLS:

  • • 2+ years of experience in technical writing and documentation skills, including
  • incident reports and playbook development.
  • • 2+ years of experience in phishing mitigation strategies and email threat analysis.
  • • 2+ years of experience supporting endpoint, network, and cloud-based security
  • controls in large-scale environments.
  • • Capability to tune and optimize SIEM rules and detection logic to reduce noise
  • and improve fidelity.
  • • Strong interpersonal communication skills with the ability to explain complex
  • topics to non-technical audiences.
  • • Experience working as a team member on projects to improve business needs.
  • • Demonstrated ability to adapt to emerging threats, technologies, and evolving
  • operational needs.

INTERVIEW PROCESS:

  •  Teams call with video and audio.
  •  Panel interview.

DESCRIPTION OF ROLE:

  • Under the general supervision of the GRC Manager, this position serves as a Security Analyst
  • responsible for supporting a wide range of compliance and cybersecurity functions across the
  • Wisconsin Department of Correction (DOC). Core responsibilities include providing risk
  • assessment and/or compliance support. Taking part in or leading audits, submitting findings,
  • analyzing risks for specific areas, monitoring corrective actions, and drafting risk reports with
  • metric charts and ongoing effort accountability. This position assesses, documents, and
  • provides guidance to other IT staff and non-IT areas on how to align IT operational and
  • technology processes based on information technology risk assessments and/or with regulatory
  • compliance/audit functions. This position will also provide support in detecting, analyzing, and
  • responding to cybersecurity threats, participating in forensic investigations, and contributing to
  • ongoing vulnerability management efforts. The role may also include supporting cloud security
  • initiatives, assisting with tabletop exercises, and developing security response procedures.
  • The incumbent will work collaboratively with internal stakeholders across DOC, as well as
  • external partners including the Department of Administration’s Division of Enterprise Technology
  • (DOA/DET). The role will utilize a variety of enterprise security tools and platforms.
  • This position may be assigned to focus areas such as incident response, phishing mitigation,
  • threat detection, security awareness, vulnerability scanning, or forensic analysis, depending on
  • organizational needs. The analyst will represent the DOC Information Security Section (ISS)
  • team in technical discussions, project work, and collaborative efforts to improve DOC’s
  • cybersecurity posture.
  • The position requires strong communication and problem-solving skills, the ability to work
  • independently on complex tasks, and a commitment to upholding the security and privacy
  • standards of DOC. Clients and collaborators include information technology (IT) staff,
  • application developers, infrastructure teams, business units, vendor, and external governmental
  • partners. The work environment is dynamic, requiring adaptability, initiative, and a proactive
  • mindset.
  • This position shall comply with the Department’s administrative rules and the agency’s policies
  • and procedures including those related to the Department's overall Reentry philosophy of using evidence-based strategies, practices and programs which target an offender’s individual
  • criminogenic needs and risk level.
  • Goals and Worker Activities
  • 60% - Support cybersecurity policy execution, operational standards, and governance
  • activities.
  • o Review policy, procedures, controls, and standards to ensure DOC and
  • regulatory standards are met.
  • o Address compliance issues with IT security standards; identifying deficiencies
  • and recommending control and risk mitigation measures.
  • o Review documentation to ensure it meets standards and applicable regulatory
  • requirements, standards, or industry best practices.
  • o Assist with the creation of new and updates to policy, process, and technical
  • controls to determine if they are sufficient and functioning as intended.
  • o Report on risks and mitigations as well as following up to verify that adjustments
  • were made.
  • o Interpret NIST or other standards to recommend and implement best practices.
  • o Contribute to the maintenance and operationalization of information security
  • policies, procedures, and response playbooks.
  • o Review new IT projects, systems, and vendor solutions for security risk,
  • documenting and escalating concerns as needed.
  • o Provide technical consulting and security recommendations aligned with DOC
  • standards and DOA/DET architecture.
  • o Participate in enterprise-level risk assessments and contribute data to
  • compliance, audit, or risk reporting needs.
  • o Assist in threat modeling exercises or tabletop simulations designed to improve
  • preparedness and resiliency.
  • 20% - Monitor, detect, respond to, and investigate cybersecurity threats across DOC’s
  • enterprise environment.
  • o Triage, analyze, and respond to cybersecurity alerts using current technologies
  • and tools.
  • o Conduct forensic investigations into suspected security incidents, including
  • phishing, account compromise, and endpoint breaches.
  • o Coordinate with internal teams and DOA/DET to contain, eradicate, and recover
  • from security incidents.
  • o Analyze logs, threat intelligence, and user behavior to identify indicators of
  • compromise (IOCs) and prevent recurrence.
  • o Document incident response actions and create post-incident reports with
  • recommended improvements.
  • o Participate in phishing mitigation, email threat response, and takedown
  • coordination with third-party providers.
  • o Assist in vulnerability validation and risk triage based on vendor and tool security
  • recommendations.
  • o Support the tuning, configuration, and enhancement of security technologies
  • used in DOC’s environment.
  • o Assist with employee forensics, HR/legal investigations, and eDiscovery requests
  • through log and artifact analysis.
  • o Assist with continuous improvement of detection logic, alerts, and response
  • workflows in current technologies and tools.
  • 15% - Contribute to the configuration, deployment, and lifecycle management of security
  • technologies.

WORK ARRANGEMENT:

  • o Hybrid (90% remote to start) from within Wisconsin. Ability to report to the
  • Madison office for training or when required for emergency situations.
  • o Position will be 100% remote after training.
  • o The candidate must be able to commute to Madison as needed
  • o No relocation allowed.

KEYS AMPLIFIED WOULD TARGET IN CANDIDATES:

  •  3+ Years
  •  Current resident of WI with history of jobs for WI based clients
  •  NIST, NIST RMF, CJIS, ISO Standards
  •  800-53 Controls
  •  Crowdstrike
  • Some (ideally all) of the following: Playbook development, Phishing mitigation strategies,
  • Controls (endpoint, network, cloud-based)

Mention you found this on Data First Jobs — it helps us bring you more roles like this.

Security Analyst

ATC

Like this role? Get carefully selected jobs like it, twice a week, straight to your inbox.

Free, no spam. Unsubscribe anytime.