BEST Program Security Analyst
Location: Boston, MA
Duration: 6 Months
Position Summary
The BEST Technical Security Analyst will work with the BEST Deputy Program Manager and Solution Technical Lead to support the adoption and implementation of the future-state end-user security solution and protocols.
The Security Analyst will collaborate with the BEST PMO, Phase 2 Technical Lead, Phase 2 Risk and Compliance Lead, CTR Risk Management Team, product vendors, Systems Integrator (SI), Office of the Comptroller, Executive Office of Technology Services and Security (EOTSS), and participating agencies to implement technical controls that meet end-user security requirements and ensure security configurations are properly maintained within the new Human Resource Management and Payroll solution.
As a member of the BEST Technical Implementation Team, this role will provide operational security support, assist with security configuration and implementation, support user access management, and contribute to the development and maintenance of information security processes and procedures.
Key Responsibilities End-User Security & Access Management
- Implement security policies, processes, and standards related to:
- End-user roles
- Application user data access
- User provisioning and de-provisioning
- Security roles and groups
- Work with BEST teams, agencies, SI, and product vendors to identify end-user roles and permissions required for the new HR and Payroll solution.
- Ensure appropriate access is provided across multiple agencies and user types.
- Support the development and implementation of procedures for user security rollout.
- Advise BEST teams, SI, and product vendors regarding:
- End-user security roles and groups
- Data access controls
- Security role provisioning
- Security role de-provisioning
- Support identification of approved end users and coordinate user provisioning for Day One go-live.
- Support security administrators with standard and exception-based authorization requests.
- Help ensure security and access requirements are addressed throughout the user lifecycle.
Security Implementation & Configuration
- Support identification and implementation of security requirements using risk and business impact assessments.
- Perform configuration updates related to security requirements and controls.
- Support application development and implementation activities to ensure security controls are implemented as planned.
- Work with security leadership to develop strategies, procedures, roles, and responsibilities for enforcing security requirements.
- Support implementation of technical controls related to data security.
- Ensure security controls are managed and maintained centrally through the new solution and within agencies where security responsibilities are decentralized.
- Support implementation of the complete solution security profile, including:
- Azure Active Directory (AD) entry
- Single Sign-On (SSO) integration between EOTSS and Workday
- Solution user security roles
- Solution user workflow roles
Operational Security Support
- Provide operational security support to the BEST team, product vendors, SI, and users in accordance with applicable SLA requirements.
- Support development of the operational support playbook for Day 2 operations.
- Provide ongoing operational support for the new SaaS solution.
- Facilitate communication between users, vendors, and technical teams through issue-management software.
- Support the BEST Maintenance and Operations Workstream.
- Support the BEST Security Workstream.
- Ensure information security operational documentation is completed and maintained.
Incident Response & Monitoring
- Assist security administrators and IT staff in resolving reported security incidents.
- Act as a liaison between incident response leads and subject matter experts.
- Monitor daily and weekly reports and security logs for unusual or potentially suspicious activity.
- Advise security administrators regarding tools used to monitor system activity and data-access irregularities.
- Research and assess new threats and security alerts.
- Recommend appropriate remedial actions for identified security issues.
Data Conversion & Go-Live Support
- Support the conversion of end users from the legacy system to the new solution.
- Provide security guidance during data conversion activities.
- Support identification and approval of users for the new solution.
- Coordinate user provisioning activities for Day One go-live.
- Support end-to-end implementation of security requirements during the transition to the new system.
Risk, Compliance & Governance
- Work with the Commonwealth Risk Management Office on security assessments and recommended controls.
- Support implementation of applicable IT, security, and data-security policies.
- Maintain awareness of information security standards, regulations, and legislation.
- Identify regulatory changes that may affect information security policies, standards, and procedures.
- Recommend appropriate changes based on regulatory and security requirements.
- Support audit, compliance, and governance activities as required.
Required Skills & Experience
- Extensive experience providing operational security support to end users.
- Experience working with modern issue-tracking systems, particularly JIRA.
- Strong understanding of enterprise security best practices, including:
- Identity and Access Management (IAM)
- Role-Based Access Control (RBAC)
- Network Security
- SaaS Security
- Cloud Security
- Data Security
- Encryption
- File Transfer Management
- In-depth experience defining and implementing end-user security protocols within a large public- or private-sector organization.
- Experience working with technical configurations, technologies, and processing environments on projects of similar size and complexity.
- Understanding of information risk concepts and principles and their relationship to business requirements and security controls.
- Experience with common information security management frameworks, including:
- In-depth knowledge of risk assessment methods and technologies.
- Understanding of Human Resources and Payroll systems security requirements.
- Strong technical knowledge of mainstream operating systems and security technologies, including:
- Network security appliances
- Identity and Access Management (IAM)
- Anti-malware solutions
- Automated policy compliance tools
- Desktop security tools
- More than 3 years of experience developing, documenting, and maintaining security policies, processes, procedures, and standards.
- Knowledge of network infrastructure, including routers, switches, firewalls, network protocols, and related concepts.
- Strong analytical skills with the ability to analyze security requirements and map them to appropriate security controls.
- Ability to interact effectively with personnel at all organizational levels and across multiple business units and organizations.
- Strong understanding of business requirements and organizational imperatives.
- Excellent written and verbal communication skills.
Preferred Qualifications
- Experience with Software-as-a-Service (SaaS) cloud implementations, particularly migrations from legacy on-premises applications to cloud platforms.
- Demonstrated operational security support experience within a SaaS environment.
- Experience with Workday Human Resource and Payroll solutions.
- Experience with Workday Prism data and reporting solutions.
- Experience managing Workday user security as part of a business/non-IT team.
- Experience transitioning traditional IT security functions to business teams.
- Experience operating end-user security protocols and policies within a large public- or private-sector organization.
- Experience with audit, compliance, or governance activities.
- Experience with Microsoft security tools and functions.
- Experience with Snowflake security functions.
Minimum Entrance Requirements
- Bachelor's degree in Computer Science, Systems Analysis, or a related field, or equivalent experience in audit, compliance, security risk, and compliance management.
- Minimum of 5 years of IT implementation and operational experience.
- Knowledge and experience across technical disciplines including:
- Application development
- Audit and compliance
- Database management
- Infrastructure and network design
- Security risk and compliance management
- Cloud solutions