S

IT Security & Compliance Specialist I - EHRA - Early Career

State of North Carolina Department of Information Technology

HybridWake County, NCentry$76k–$90kPosted 3h ago

Job description

Agency

Department of Information Technology

Division

DIT Secretary , CIO

Job Classification Title

IT Security & Compliance Specialist I (NS)

Position Number

65041630

Grade

DT08

About Us

The N.C. Department of Information Technology (NCDIT) serves as the Technology Center for the State of NC. Services that NCDIT provides reach a client base of state and local government agencies, as well as schools, colleges and universities. NCDIT’s mission is to enable trusted business-driven solutions that meet the needs of North Carolinians. NCDIT provides technology services to state agencies and is charged with closing the digital divide by expanding availability of broadband services and promoting the adoption of affordable, high-speed internet.

Description of Work

Salary Range: $75,818 - $90,000

The position is designated Statutory Exempt (EHRA) and is exempt from the State Human Resources Act.

This position may be eligible for hybrid remote work in accordance with state policy and the agency’s remote work program but does require weekly onsite work. Any telework will be under the conditions of the state Teleworking Program Policy and the employer may end any teleworking arrangement at any time in the employer's sole discretion.

The Early Career Associate Program is ideal for recent graduates, early-career professionals, or those looking to transition to a new career seeking broad exposure to state IT operations.

The Early Career Associate Program is a two-year on-the-job training (OJT) program designed for individuals with three years or less of professional experience. After gaining exposure to the role through the development process, participants will have the opportunity to be placed in a permanent role based on mutual fit and career goals.

Are you excited to launch your cybersecurity career and make an immediate impact? As an IT Security & Compliance Specialist I, you’ll work side‑by‑side with experienced security professionals to explore how modern technology is secured across an entire state enterprise. In this role, you’ll get hands‑on experience evaluating security controls, supporting risk‑based decision‑making, and learning core disciplines like Zero Trust, cloud and application security, identity and access management, vulnerability management, and emerging technology risk. If you’re eager to grow, curious about how large‑scale IT environments operate, and ready to help protect critical systems and data, this position offers a unique opportunity to build your skills while contributing to meaningful work.

Key Responsibilities:

  • Conduct security assessments of new and existing applications, systems, cloud services, software, and technology solutions.

  • Review technology and business requests to identify cybersecurity risks, control requirements, and potential security gaps.

  • Assist with the development and maintenance of security assessments, system security documentation, security standards, procedures, and other governance artifacts.

  • Review firewall, network, access, and system configuration requests for alignment with security principles and organizational requirements.

  • Support vulnerability management and threat-informed activities, including vulnerability analysis, threat hunting, remediation tracking, and identification of potential security exposures.

  • Assist with identity and access management reviews, including privileged access, service accounts, authentication, least privilege, and Zero Trust considerations.

  • Participate in cybersecurity audits, control assessments, risk assessments, and remediation activities aligned with applicable security frameworks and organizational requirements.

  • Assist with documenting, evaluating, and tracking cybersecurity risks, security exceptions, compensating controls, and risk acceptance decisions.

  • Collaborate with infrastructure, cloud, application, network, architecture, privacy, and business teams to integrate security requirements into technology initiatives.

  • Research emerging technologies, threats, vulnerabilities, and security practices, including cybersecurity considerations associated with artificial intelligence and cloud technologies.

About the Division:

The Information Security team provides cybersecurity risk management, governance, security assessment, and advisory services that help protect organizational information systems and technology assets while enabling the delivery of business and technology services. The team works collaboratively across technology and business functions to identify and communicate cybersecurity risk, establish security requirements and standards, assess the effectiveness of security controls, and provide practical recommendations for reducing risk.

The work unit supports a broad range of cybersecurity disciplines, including governance, risk and compliance (GRC), security architecture, Zero Trust, identity and access management, application and cloud security, vulnerability and threat management, data protection, third-party risk, and emerging technology security. The team operates with a risk-based approach that seeks to enable innovation and business objectives while ensuring cybersecurity risks are understood, appropriately mitigated, documented, and accepted by the appropriate stakeholders.

Knowledge Skills and Abilities/Management Preferences

The following Management Preferences are not required, but applicants that possess these skills are preferred:

  • Demonstrated knowledge of cybersecurity fundamentals , including at least three of the following areas: network security, identity and access management, vulnerability management, endpoint security, cloud security, data protection, security operations, or governance, risk and compliance (GRC).

• Demonstrated ability to identify and evaluate cybersecurity risks and controls , gained through academic coursework, internships, cybersecurity labs, capstone projects, certifications, volunteer experience, or professional experience.

• Working knowledge of networking, operating systems, and enterprise technology concepts , including foundational understanding of TCP/IP, firewalls, authentication and authorization, Windows and/or Linux operating systems, and common cloud or web-based technologies.

Discover why NCDIT is the ideal destination for your professional growth - Why Work for NCDIT

Minimum Education and Experience

Some state job postings say you can qualify by an “equivalent combination of education and experience.” If that language appears below, then you may qualify through EITHER years of education OR years of directly related experience, OR a combination of both. See the Education and Experience Equivalency Guide for details.

Bachelor’s degree in computer science or a related IT related field or closely related field from an appropriately accredited institution and one year experience in IT Security

or

Associate degree in computer science or a related IT related field or closely related field from an appropriately accredited institution and two years of experience in IT Security; or an equivalent combination of education and experience.

Note: This position requires a fingerprint-based background search. Hires must agree to a fingerprint-based background search prior to being hired.

EEO Statement

T he State of North Carolina is an Equal Employment Opportunity Employer and dedicated to providing employees with a work environment free from all forms of unlawful employment discrimination, harassment, or retaliation. The state provides reasonable accommodation to employees and applicants with disabilities; known limitations related to pregnancy, childbirth, or related medical conditions; and for religious beliefs, observances, and practices.

Recruiter:

Shaun Osborne

Recruiter Email:

dit_hr_recruitment@nc.gov