{"id":1469449,"url":"https://alion.io/job/aca-it-security-analyst-iii-information-technology-services","title":"IT Security Analyst III (Information Technology Services)","company":{"id":1921492,"name":"ACA","domain":"aca.org","url":"https://alion.io/company/aca-org","size_band":"1-10","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":{"grade":"B","score":75,"open_postings":31,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-30T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"middle","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Memphis, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":72000,"max_usd":151000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":237},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"DLP","optional":false},{"name":"HIPAA","optional":false},{"name":"ITIL","optional":false},{"name":"NIST CSF","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"PCI DSS","optional":false},{"name":"SIEM","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-07-07T16:03:44Z","employer_posted_date":"2026-07-07","last_verified_at":"2026-09-30T10:13:41Z","board_verified":true,"closed_at":null,"days_open":85,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":85},"description":"Position Summary\nWorks under the direction of the Systems Security Officer to execute, monitor, and assess the Shelby County Government (SCG) Information Security Program. Acts in a lead capacity to plan, research, specify, engineer, and implement highly complex security solutions. Administers and maintains systems critical to the function of the Information Security Program and develops procedures and policies for implemented solutions. Responsible for carrying out comprehensive security processes, risk assessments, and assessments of third-party vendors, and works with groups inside and outside of SCG to ensure the successful operation of the Information Security Program.\nPay Grade: 57\nSalary Commensurate with Experience and Education\nMinimum Qualifications\nFive (5) years of cybersecurity/compliance experience, including three years of cybersecurity experience within a medium to large organization; AND \nBachelor’s degree from an accredited college or university in cybersecurity, computer \nscience, or a closely related field; OR \nAn equivalent combination of related education, and/or experience. \nSecurity credentials such as ISC2 CISSP, ISC2 CCSP, ISACA CISA, ISACA CISM, or closely related certifications are preferred. \nPROOF OF EDUCATION, TRAINING, AND/OR EXPERIENCE IS REQUIRED.\nDuties and Responsibilities\nLeads proactive threat-hunting initiatives using advanced security tools and methodologies, while overseeing daily monitoring of system audit log feeds. \nManages the generation and analysis of detailed incident reports, threat analysis reports, and compliance status reports to facilitate strategic decision-making and risk management. \nOversees the processing of security office requests, including user access requests, access control changes, and responses to security advisories, ensuring timely and efficient resolution of security concerns. \nDevelops and oversees the organization's cybersecurity training program, tailored to different roles and departments, ensuring its effectiveness, relevance, and compliance with industry standards. \nLeads the management of security incidents using the approved IT incident response solution, coordinating remediation efforts across IT sections, and enhancing incident response plans through regular tabletop exercises and risk assessment updates. \nCreates, updates, and maintains comprehensive cybersecurity incident response playbooks, outlining steps for identifying, analyzing, and responding to security incidents effectively. \nProvides leadership in supporting IT Application Services by conducting security quality assurance reviews, vulnerability scans, and collaborating with DevOps and Applications Services to integrate secure coding practices into the development lifecycle. \nStays abreast of new security technology developments relevant to business and IT requirements, lead the evaluation and recommendation of security solutions, and oversee pilot tests to enhance the organizational security posture. \nLeads the development, deployment, and regular update of IT security policies and procedures, ensuring alignment with current best practices, legal requirements, and compliance standards. \nDemonstrates strong interpersonal and communication skills to foster collaboration with management, peers, customers, and non-IT departments, promoting a culture of security awareness and cooperation across the organization. \nExemplifies a strong passion for information technology and cybersecurity, driving continuous exploration, learning, and adoption of new technologies and security practices within the team and organization. \nUpholds strict adherence to ethical guidelines and legal requirements in all cybersecurity activities, including compliance with privacy laws, data protection regulations, and ethical hacking standards. \nProvides leadership and mentorship to junior security analysts, fostering their professional growth and development within the team and organization. \nPerforms other related duties as assigned or directed.\nKSAs\nAdvanced knowledge of cybersecurity principles, including risk management, threat modeling, security architectures, and incident response strategies. \nProficiency knowledge in key legal and regulatory requirements such as HIPAA, PCI-DSS, and familiarity with frameworks such as ITIL, NIST CSF, CIS Controls, and zero trust, guiding the organization in compliance efforts. \nProficiency knowledge with a wide range of advanced security technologies and tools, including SIEM, firewalls, IDS/IPS, DLP, endpoint protection, privilege access management, and threat intelligence platforms. \nAdvanced knowledge of key IT infrastructure technologies including virtualization technologies, server architectures, containerization, and network infrastructure, providing strategic guidance for secure implementation. \nProficiency knowledge in secure coding practices, understanding common application security vulnerabilities (OWASP Top 10), and guiding development teams to mitigate risks. \nAbility to identify, analyze, and resolve complex security threats and vulnerabilities, providing strategic direction for incident response. \nSkilled in communicating complex security concepts to nontechnical audiences, fostering collaboration across departments, and providing strategic guidance to senior management. \nAbility to drive innovation and proactive approaches to emerging security challenges. \nAbility to lead enterprise-sized cybersecurity projects from inception to completion.\nDisclaimer\nThis position is subject to a background check for any convictions that have a substantial relationship to potential job duties. Only convictions that are substantially related to potential job duties will be considered and will not automatically disqualify the candidate.\nShelby County Resident Disclaimer\nAll employees hired after September 1, 1986, must be residents of Shelby County and shall continue to reside in the County as a condition of their employment. The residency requirement shall not apply to certain public safety/civil service employees. This means exemption from this policy is in effect for the following departments and positions: (1) Sheriff Deputy Patrol Officers, Deputy Jailers and Dispatchers, employed by the Sheriff Department, (2) Correction Officers employed by the Division of Corrections, (3) Firefighters, Paramedics and Dispatchers employed by the Shelby County Fire Department. The residency exemption for public safety/civil service employees does not include Appointed positions with Sheriff’s Office, Division of Corrections or the Fire Department.","description_format":"text","description_chars":6605,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Law Enforcement","Information Security"],"lifecycle":[{"event":"open","at":"2026-09-29T15:40:57Z"}],"liveness":{"score":7,"band":"cold","label":"Long shot","p_open":1,"p_active":0.255,"p_room":0.28,"age_days":84,"expected_fill_days":25,"reasons":["conf:5","stale_co","win:tail","crowd:"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/aca-it-security-analyst-iii-information-technology-services","json_url":"https://alion.io/job/aca-it-security-analyst-iii-information-technology-services.json","meta":{"generated_at":"2026-10-01T04:55:45Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4501,"day_limit":5000,"remaining_today":499,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}