Demo

Information Technology Security Specialist

Capital Technology Alliance
Tallahassee, FL Full Time
POSTED ON 7/24/2026
AVAILABLE BEFORE 8/21/2026

About Capital Technology Alliance

At Capital Technology Alliance, we believe changing the future of technology means valuing people. We are committed to building a collaborative, high-performing environment where professionals are empowered to deliver meaningful impact. Our teams work on challenging, often high-visibility initiatives that support mission-critical systems, enterprise modernization efforts, and data-driven decision-making.


CTA is proud to demonstrate a high renewal rate with our employees and contractors. We place a high value on expertise. That's why CTA is committed to paying top rates in the industry and connecting you with positions and flexible engagement options that match your skills and professional goals.


Job Duties:

Governance, Policy, and Standards

  • Draft, revise, and maintain Department information security policies and standards, including the 420-series, with established periodic review cycles.
  • Develop procedures supporting Department security policies in accordance with Rule 60GG-2.002 and Rule 60GG-2.003, Florida Administrative Code (F.A.C.).
  • Develop and maintain control mappings and crosswalks between NIST SP 800-53, NIST Cybersecurity Framework (CSF), and Rule 60GG-2, F.A.C.
  • Maintain documentation, version control, and review evidence to support internal and external audits.

Risk Management and Assessment

  • Conduct security risk assessments and control gap analyses against applicable security frameworks.
  • Develop, track, and maintain Plans of Action and Milestones (POA&Ms) and corrective action plans.
  • Perform third-party and vendor security risk reviews, including assessments of vendor security documentation, contract security requirements, identity federation, transaction attribution, and audit logging.

Security Operations and Engineering Support

  • Support the configuration, hardening, and monitoring of Microsoft 365 and Microsoft Defender technologies, including Defender for Endpoint, Defender Vulnerability Management, and Microsoft Purview, in accordance with Department standards.
  • Support vulnerability management activities, including triage, tracking, and remediation coordination.
  • Support incident response activities in accordance with the Department’s Cybersecurity Incident Response Policy (420.01), including documentation and post-incident analysis.
  • Support identity and access management (IAM) activities, including access reviews and provisioning integrity controls.

Audit, Compliance, and Reporting

  • Support responses to Office of Inspector General (IG) and external audit findings, including evidence collection, control testing, and management response development.
  • Support compliance with the Criminal Justice Information Services (CJIS) Security Policy and the protection of Protected Health Information (PHI) and other confidential information.
  • Develop security metrics, status reports, and security awareness materials.
  • Support security governance meetings and working groups.

Contract Deliverables

  • Develop and maintain drafted and revised security policies and standards with documented review cycles.
  • Produce control mapping crosswalks for NIST SP 800-53, NIST CSF, and Rule 60GG-2, F.A.C.
  • Deliver security risk assessment reports and control gap analyses.
  • Develop and maintain Plans of Action and Milestones (POA&Ms) and corrective action plans.
  • Prepare third-party and vendor security review memoranda and diagnostic questionnaires.
  • Produce vulnerability management tracking and remediation status reports.
  • Document security incidents and prepare post-incident Root Cause Analysis (RCA) reports.
  • Prepare audit evidence packages and draft management responses for IG and external audit findings.
  • Develop security metrics and periodic status reports.
  • Submit monthly time reports detailing tasks performed and hours worked, no later than the fifth day of the following month, using the Department-approved timesheet.

Required Qualifications:

  • A minimum of four (4) years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, and database design and administration, including one to two (1–2) years of experience with information security, and knowledge of security issues, techniques, and implications across all existing computer platforms.
  • Minimum of seven (7) years across information security disciplines, with demonstrated experience in both security governance/compliance (GRC) and hands-on security operations.
  • Demonstrated experience drafting information security policy and standards and implementing NIST SP 800-53 and/or NIST CSF controls.
  • Demonstrated experience performing security risk assessments and supporting internal or external audits.
  • Broad mastery of information security across governance and operations — able to both author policy and standards and perform the hands-on technical work to implement and validate controls.
  • Fluency in security control frameworks (NIST SP 800-53, NIST CSF) and the ability to map and crosswalk controls to the Florida Cybersecurity Standards (Rule 60GG-2, F.A.C.).
  • Risk-based judgment, able to assess control gaps, prioritize remediation, and document risk decisions for management review.
  • Clear technical writing, able to produce audit-ready policy, procedure, assessment, and management-response documentation.
  • Operational competence in a Microsoft 365 / Microsoft Defender environment, including endpoint security, vulnerability management, identity and access controls, and incident response support.
  • Ability to explain security risks, trade-offs, and remediation options to non-security stakeholders, including executives and counsel.


Preferred Qualifications:

  • Experience working in Florida state government or public-sector information security.
  • Working knowledge of Rule 60GG-2, Florida Administrative Code (F.A.C.), and Section 282.318, Florida Statutes.
  • Experience implementing or auditing the Criminal Justice Information Services (CJIS) Security Policy.
  • Experience with the Health Insurance Portability and Accountability Act (HIPAA) Security Rule and Protected Health Information (PHI) handling.
  • Hands-on experience with Microsoft 365 G5, Microsoft Defender for Endpoint, Microsoft Defender Vulnerability Management, and Microsoft Purview.
  • Experience with vulnerability management tools and remediation coordination.
  • Experience developing Identity and Access Management (IAM) and access control standards, including provisioning integrity controls.
  • Experience using PowerShell or comparable scripting languages for security automation and reporting.


Education and Certifications:

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent work experience.
  • Possess at least one current industry certification, such as:
  • Certified Information Systems Auditor (CISA).
  • Certified in Risk and Information Systems Control (CRISC).
  • Certified in Governance, Risk and Compliance (CGRC), formerly Certified Authorization Professional (CAP).
  • Certified Information Security Manager (CISM).
  • Certified Information Systems Security Professional (CISSP).


Salary : $135,000 - $140,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Information Technology Security Specialist?

Sign up to receive alerts about other jobs on the Information Technology Security Specialist career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Capital Technology Alliance

  • Capital Technology Alliance Tallahassee, FL
  • About Capital Technology Alliance At Capital Technology Alliance, we believe changing the future of technology means valuing people. We are committed to bu... more
  • 10 Days Ago


Not the job you're looking for? Here are some other Information Technology Security Specialist jobs in the Tallahassee, FL area that may be a better fit.

  • Capital Technology Alliance Tallahassee, FL
  • About Capital Technology Alliance At Capital Technology Alliance, we believe changing the future of technology means valuing people. We are committed to bu... more
  • 10 Days Ago

  • State of Florida Tallahassee, FL
  • Requisition No: 879575 Agency: Department of Law Enforcement Working Title: INFORMATION SECURITY SPECIALIST - 71001212 1 Pay Plan: Career Service Position ... more
  • 1 Day Ago

AI Assistant is available now!

Feel free to start your new journey!