Information System Security Officer
Current• Overseeing continuous monitoring for State Windows and Linux systems and maintaining their ATO’s and FISMA compliance• Develop and implement information system security policies and procedures in accordance with NIST (National Institute of Standards and Technology) for Linux and windows systems. Guidelines, the Risk Management Framework (RMF), and relevant regulatory frameworks such as HIPAA (Health Insurance Portability and Accountability Act) for healthcare data security and IRS (Internal Revenue Service) guidelines for tax-related information security.• Conduct risk assessments and vulnerability assessments using the RMF framework, CMS (Centers for Medicare & Medicaid Services) guidelines, and HIPAA requirements to identify and mitigate potential security threats and vulnerabilities in information systems handling sensitive healthcare and tax-related data.• Utilize a Governance, Risk, and Compliance (GRC) tool to manage and track security controls, compliance requirements, and risk mitigation activities, ensuring alignment with NIST, RMF, FISMA, HIPAA, and IRS standards.• Monitor and analyze security logs and event data to identify and respond to security incidents and breaches, following NIST incident response guidelines and specific reporting requirements outlined by CMS and IRS.• Manage access control systems and processes, including user provisioning, authentication, and authorization, in compliance with NIST, RMF, HIPAA, CMS, and IRS regulations to safeguard sensitive healthcare and tax-related information.• Collaborate with IT teams to design, implement, and maintain security measures aligned with NIST, RMF, HIPAA, CMS, and IRS guidelines, such as firewalls, intrusion detection systems, and encryption technologies, to protect information assets.