Data First Jobs

Talent Groups

Security Analyst

Contract · In Office · Phoenix, Arizona (USA)

Posted Aug 14, 2026

Work Options
Job Type
Position Group
  • Information Security Analyst – GRC
  • Job Type: Contract-to-Hire - 12+ months Duration
  • Location: Phoenix, AZ — Local candidates only, within approximately a 1-hour commute. Work must be performed within Arizona.
  • Position Overview
  • The Department of Economic Security is seeking an experienced and highly motivated Information Security Analyst to join the Governance, Risk, and Compliance (GRC) team.
  • The Information Security Analyst will work closely with business units, IT teams, project managers, and stakeholders to support information security governance, risk management, compliance, audit activities, requirements gathering, and security documentation. This role will assess risks, conduct audits and reviews, identify areas of non-compliance, develop findings and remediation plans, and ensure security practices align with applicable laws, regulations, policies, and industry standards.
  • The position will also support the development of security policies, project artifacts, data and system documentation, user adoption materials, and training resources.
  • Key Responsibilities
  • Perform security risk assessments, audit reviews, and technical system reviews.
  • Generate findings reports and provide recommendations for security and process improvements.
  • Track remediation activities, outcomes, and Plans of Action and Milestones (POA&Ms).
  • Develop comprehensive reports documenting findings, non-compliance areas, required action plans, environmental observations, and security incidents.
  • Review, update, and maintain security audit plans, security plans, risk plans, and related documentation.
  • Evaluate information and formulate reports detailing security findings and compliance gaps.
  • Investigate suspicious network activity and prepare incident reports as needed.
  • Prepare audit documentation supporting audit results.
  • Draft and edit audit findings in accordance with organizational standards and writing guidelines.
  • Research and evaluate applicable cybersecurity laws, regulations, standards, policies, and industry best practices.
  • Develop and maintain effective information security policies, plans, and procedures.
  • Collaborate with business units and IT teams to understand reporting, data, product, and security requirements.
  • Identify cybersecurity and privacy risks associated with internal and external customers, systems, and partner organizations.
  • Support requirements gathering and development of project documentation.
  • Identify data dependencies and relationships and assist with development of logical and physical data models, data flows, and system activity diagrams.
  • Develop and maintain key project artifacts and technical documentation.
  • Develop plans and materials supporting user adoption, training, and customer service.
  • Work directly with users across divisions, programs, and service units to provide security guidance and support.
  • Identify risks and recommend improvements to information systems and business processes.
  • Support technical project managers in completing information analysis and requirements-gathering activities.
  • Ensure security practices are incorporated throughout the lifecycle of business and IT processes.
  • Collaborate effectively with teams and stakeholders across the organization.
  • Produce high-quality security and compliance deliverables for technical teams and senior management.
  • Required Knowledge & Skills
  • Strong knowledge of information security principles, policies, procedures, and governance.
  • Strong understanding of information security risk management.
  • Knowledge of cybersecurity and privacy laws, regulations, policies, principles, and ethics.
  • Required knowledge of:
  • NIST SP 800-53 Revision 5
  • IRS Publication 1075
  • HIPAA/HITRUST
  • CJIS
  • MARS-E
  • Strong knowledge of internal auditing, internal controls, and risk management practices.
  • Knowledge of the selection, implementation, assessment, and auditing of security and privacy controls.
  • Understanding of Risk Management Framework (RMF) requirements.
  • Knowledge of information system authorization and approval processes.
  • Experience conducting audits or security reviews of technical systems.
  • Strong understanding of IT internal control environments.
  • Broad technical knowledge across areas such as:
  • Windows
  • Unix/Linux
  • Database administration
  • Software development
  • Networking
  • Ability to identify cybersecurity and privacy issues resulting from system integrations and external/internal relationships.
  • Strong analytical, written, and verbal communication skills.
  • Ability to develop and improve security policies and procedures.
  • Ability to work collaboratively across technical and business organizations.
  • Ability to synthesize stakeholder feedback and adjust plans accordingly.
  • Ability to build effective relationships with technical teams, business stakeholders, and management.
  • Ability to exercise sound judgment when policies or procedures are not clearly defined.
  • Ability to develop security policies, plans, and strategies in accordance with applicable laws, regulations, policies, and standards.
  • Understanding of how information security management integrates with strategic and operational planning.
  • Ability to communicate technology, management, cybersecurity, and organizational risk issues to stakeholders and leadership.
  • Ability to develop plans and materials supporting user adoption, training, and customer service.

Mention you found this on Data First Jobs — it helps us bring you more roles like this.

Security Analyst

Talent Groups

Like this role? Get carefully selected jobs like it, twice a week, straight to your inbox.

Free, no spam. Unsubscribe anytime.