Jobs and Careers
CR

Systems Security Specialist (Senior) – Baltimore, MD

Creative Information Technology, Inc.
Falls Church, United StatescontractVerifiedPosted 29 Jan 2026

About the role


Systems Security Specialist (Senior) – Baltimore, MD

About us 

Creative Information Technology Inc (CITI) is an esteemed IT enterprise renowned for its exceptional customer service and innovation. We serve both government and commercial sectors, offering a range of solutions such as Healthcare IT, Human Services, Identity Credentialing, Cloud Computing, and Big Data Analytics. With clients in the US and abroad, we hold key contract vehicles including GSA IT Schedule 70, NIH CIO-SP3, GSA Alliant, and DHS-Eagle II.

 

Join us in driving growth and seizing new business opportunities.

Background 

An independent state-level health services organization provides accessible and affordable health coverage through a public health insurance marketplace. The platform enables residents to explore and compare health insurance plans, determine eligibility for premium assistance and cost-sharing programs, and access public assistance initiatives such as state Medicaid and children’s health coverage programs.

 

The organization is seeking two (2) Senior Systems Security Specialists to plan, design, develop, administer, monitor, and govern enterprise security policies, controls, and systems supporting the health insurance marketplace and related platforms.

 

Note: The candidate must be flexible to work overtime as needed, including weekends, holidays, and off-hours.

Role and Responsibilities 

 

  • Develop and implement cloud security controls, cloud-based processes and tools, and cloud security task automation.
  • Perform security assessments, working closely with DevOps and Developer teams on identifying security and privacy issues in AWS or Azure and finding solutions to provide required functionality securely.
  • Continuously monitor the Client and ancillary systems, not limited to cloud security operations, responding to security issues and escalating as necessary.
  • Conduct security impact analysis of controls on proposed system changes.
  • Conduct cloud security assessments and Penetration testing.
  • Perform Incident Response and Forensics evaluation using security information and event management (SIEM) tools.
  • Ensure that the Client system security requirements are addressed during all phases of the system development life cycle.
  • Review and update systems security documentation and artifacts such as Systems Security Plan, Information Security Risk Assessment, Privacy Impact Assessment, Systems Security Report, Correction Action Plan, Plan of Action & Milestones (POA&M).
  • Create and track POA&M requirements for resolving security findings.
  • Administer cloud-based and physical firewalls.
  • Deploy and administer Identity and Access Management products in various operating systems.
  • Perform monitoring and operations of Identity and Access Management implementation.
  • Design enhancements in Identity and Access Management products ForgeRock and SailPoint.
  • Maintain, monitor, and provide operational support for IAM products, computer programs, systems, and other security technologies and revise system design and quality standards.
  • Make changes to IAM and underline applications for enhancing enterprise security and ensure safe and secure operation to enable access to our systems for our employees, contractors, consumers, and stakeholders.
  • Perform Security Incident Response and Forensics evaluation using security information and event management (SIEM) tools.
  • Provide operational support for other security technologies.
  • Perform account/access management with IAM and other security tools.
  • Adhere to all security, change control, and Client Project Management Office (PMO) policies, processes, and methodologies.

Minimum Qualification

 

  • A minimum of eight (8) years of experience analyzing, defining, deploying, monitoring, and administering security requirements and controls for large and mission-critical IT systems. 
  • A minimum of five (5) years performing day-to-day security operations functions, including administration, troubleshooting, and resolution of various security components.
  • A minimum of four (4) years of hands-on experience in performing cloud security functions.<

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Creative Information Technology, Inc.

View company profile →