CAPPS Security Analyst

Remote from
USA flag
USA
Annual salary
Undisclosed
Salary information is not provided for this position. Check our Salary Directory to estimate the average compensation for similar roles.
Department
Cybersecurity
Employment type
Contract,
Job posted
Apply before
7 Jul 2026
Experience level
Midweight
Views / Applies
15 / 5

About Numentica

Enabling companies to succeed with real-time business intelligence and analytics.

Actively Hiring
Verified job posting
This job post has been manually reviewed for authenticity and compliance.

AI Summary

This is a senior-level CAPPS Security Analyst remote position responsible for managing and enforcing role-based access control (RBAC) and segregation of duties (SoD) within the CAPPS HR/Payroll system. The role involves designing security frameworks, monitoring authentication logs, responding to security incidents, and ensuring WCAG 2.1 accessibility compliance. The analyst works under minimal supervision, providing Level 2 service desk support and collaborating with a managed services vendor for Level 3 duties. They must follow ITIL principles and ensure all work aligns with CPA's policies and project timelines. The position requires consultative services, technical assistance, and participation in special projects like fiscal year-end close and legislative system changes.

Role DNA

Job Complexity
Easy Hard
Pace & Pressure
Relaxed Fast-paced
Autonomy Level
Guided Full Ownership
Communication Load
Independent Highly Collaborative
AI Insight The role demands advanced security expertise in CAPPS (PeopleSoft) with RBAC, SoD, incident response, and integration security, which is complex. However, established processes and standards reduce the difficulty slightly, leading to a 4.

Salary Analysis

Median Highly Competitive
USD115,000
US Market
USD90k – 140k
0 USD154k
AI Insight The salary is not specified, but based on US market data for a senior security analyst with specialized CAPPS/PeopleSoft experience, the median is estimated at $115,000. This aligns with roles requiring deep technical skills and minimal supervision.

Key Skills

RBAC Segregation of Duties CAPPS PeopleSoft SAML/OAuth/OIDC Security Incident Response WCAG 2.1 ITIL Access Control Identity Management

I am writing to express my strong interest in the CAPPS Security Analyst position. With over 7 years of experience in security analysis, I have specialized in implementing RBAC and SoD models complex systems, ensuring both security and compliance. My background includes integrating third-party applications via SAML, OAuth, and SCIM, as well as responding to security incidents and conducting audits.

In my previous role, I successfully managed security frameworks for large-scale HR/Payroll systems, which directly aligns with the CPA's CAPPS environment. I am adept at working under minimal supervision while collaborating effectively with cross-functional teams and managed service providers. I also have strong knowledge of WCAG 2.1 accessibility standards and ITIL practices.

I am excited about the opportunity to contribute to CPA's CAPPS Program and ensure the security and accessibility of its digital products. I am confident that my technical expertise and consultative approach would make me a valuable asset to your team.

Thank you for considering my application. I look forward to the possibility of discussing how my skills can support CPA's mission.

How would you design a role-based access control (RBAC) model for a complex HR/Payroll system like CAPPS?
I would start by conducting a thorough analysis of business processes and job functions to define roles based on least privilege. Then, group permissions into roles, ensuring segregation of duties by preventing conflicting roles from being assigned to the same user. I'd implement a process for role review and certification, and use automated tools to detect and remediate SoD conflicts.
Describe your experience with integrating third-party applications using SAML, OAuth, OIDC, and SCIM.
I have integrated multiple third-party apps by configuring identity providers for SAML-based SSO, using OAuth for delegated access, and OIDC for authentication. For user provisioning, I've used SCIM to sync user attributes between systems. I ensure secure token handling and attribute mapping to avoid privilege escalation.
How do you ensure WCAG 2.1 accessibility compliance in digital products?
I review content and interfaces against WCAG 2.1 guidelines, use automated tools to scan for issues, and perform manual testing with assistive technologies. I collaborate with development teams to remediate issues during design and development phases, and conduct regular audits to maintain compliance.
Can you walk through your process for responding to an identity-related security incident such as account compromise?
First, I contain the incident by disabling the compromised account and revoking session tokens. Then, I investigate logs to determine the scope and root cause. I coordinate with the Information Security Office, and after analysis, I implement remediation like password resets and MFA enforcement. Finally, I document lessons learned and update incident response plans.
How do you handle Level 2 service desk tickets for complex security issues?
I triage tickets by severity, then perform in-depth troubleshooting using logs and system analysis. I document findings clearly and follow established processes to resolve or escalate to Level 3. Communication with the user and managed services vendor is key to ensure timely resolution and knowledge transfer.

This is a remote position.

P osition Requirements . The CPA Work includes, but is not limited to, the following:

· Performing highly advanced (senior-level) consultative services and technical assistance work related to supporting the CAPPS Program.

· Responsible for the(CAPPS) security framework, which includes but is not limited to:.

Manage and enforce role‑based access control (RBAC) and least‑privilege models within CAPPS and connected systems.

Design and maintain segregation‑of‑duties (SoD) rules; identify and remediate SoD conflicts across business processes.

Review and validate security roles, permission sets, and custom authorizations within CAPPS and all ancillary systems.

Monitor and analyze authentication, authorization, and privilege‑escalation logs for suspicious behavior and coordinate any findings with CPA Information Security Office.

Oversee secure integration of third‑party apps via SAML, OAuth, OIDC, SCIM, and custom APIs.

Validate CAPPS application changes, customizations, and workflows for security and compliance impact.

Respond to and investigate identity‑related security incidents, including account compromise, unauthorized access, and fraud indicators.

Maintain standards for security, performance, compliance, and architecture.

· Responsible for ensuring that all digital products and content meet WCAG 2.1 accessibility standards. This includes maintaining perceivable, operable, understandable, and robust experiences for all users, regularly reviewing content for compliance, and implementing updates or remediation whenever accessibility issues are identified.

Reviewing and suggesting approval for all assigned Security Deliverables related to CAPPS Architecture, CAPPS System Development Lifecycle, Disaster Recovery, CAPPS Security Plans (SSP), and all CAPPS related Security plans related to CAPPS applications currently and planning for the future.

Service Desk Support

· Plans, designs, develops, deploys, supports and maintains system configurations and modifications for CPA’s CAPPS HR/Payroll application to ensure the system produces accurate data, performs efficiently, and adheres to applicable policies.

· Performs highly advanced analysis and participates in special projects and cyclic processes in support of CPA’s CAPPS HR/Payroll application which may include but is not limited to production expansion projects (i.e., agency deployments of CAPPS, new agency creation, deployment of new functionality), fiscal year end closer, legislative system changes, third-party integrations, PeopleSoft Image upgrades and/or decommissioning functionality.

· Supports CAPPS agencies with discovery, prototyping, configuration, security, conversion, integration, and acceptance testing for either implementation or post-production support.

· Provides Level 2 Service Desk duties inclusive of, but not limited to ticket handling for complex issues, in-depth troubleshooting, well documented analysis, and basic configurations following an established and auditable process. All work is done in cooperation and collaboration with a Managed Services vendor that is responsible for all Level 3 duties.

· Performs all duties following CPA’s processes, policies, and procedures within project scope and on schedule accordance with milestones, deliverables, and due dates.

· Works under minimal supervision, relying on experience and judgment to plan and accomplish goals, independently performing a variety of complicated tasks. Established processes and procedures must be followed.

· Performs all work in accordance with Information Technology Infrastructure Library (ITIL) principles and practices for IT activities such as IT service management (ITSM) and IT asset management (ITAM) that focus on aligning IT services with the needs of the business.

· Actively responds to and maintains customer ticket requests via the CAPPS Service Desk with current information and statuses, including but not limited to break fixes, incidents, required maintenance, and enhancement requests.

· Actively participates in CPA’s Major Incident Management (MIM) process for P1 and P2 incidents according to module responsibilities.

· Participates in Disaster Recovery and Upgrade Testing activities.

· Assists with expansion activities.

· Makes presentations at CAPPS User Groups.

· Plans, designs, develops, implements, supports, and maintains the information technology security measures to safeguard system information.

· Participates as directed in an annual SOC-1 attestation audit designed to ensure that controls are effectively designed and operated to ensure the accuracy and security of all information contained/processed via CAPPS. Any enhancements, process changes, or system fixes consider security, availability, processing integrity, confidentiality, and privacy as solutions are suggested, approved, and implemented.

· Performing other related Work as assigned.

II. CANDIDATE SKILLS AND QUALIFICATIONS
Minimum Requirements:
Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.

Years Required/Preferred Experience 10 Required Extensive Texas public sector experience, directly working for or supporting a Texas state government agency 10 Required Extensive experience performing technical activities in support of CPA application systems 10 Required Extensive experience creating and managing a strategic roadmap by combining strong planning skills, technical insight, and effective cross functional communication 10 Required Experience preparing materials for and conducting executive-level presentations 10 Required Experience performing technical project management activities in support of CPA’s CAPPS program 10 Required Experience in interpreting contractual language and integrating it into daily workflows, while consistently holding vendors accountable to contractual requirements 10 Required Extensive knowledge of/experience with data integration, data quality, and SDLC processes and methodologies 10 Required Experience in IT security and control practices 10 Required Technical experience with PeopleSoft FSCM or HCM 9.2, PeopleTools, Peoplecode, Application Designer, SQL, PS Query, SQR, Application Engine and Oracle 11 or higher 10 Required Experience with CAPPS Central production and deployment technical support activities for more than 100 agencies and 5 Hub instances. 8 Required Experience with IT service desk functions, knowledge of ITIL framework methodologies and processes. 5 Required Experience serving in a security analyst role with responsibility overseeing a Managed Services provider 5 Required Experience with user role segregation of duties (SoD) in multi-tenant software applications. 10 Preferred Experience with software and hardware management industry best practices 10 Preferred Experience with CPA’s legacy Statewide Financial Systems production support activities 10 Preferred Experience developing technical specifications to support IT procurements

Apply now >

Annual salary information is not provided for this position. Explore salary ranges for similar roles in our Salary Directory ›

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

How to apply

Did you apply? Let us know, and we’ll help you track your application.

See a few more

Similar Cybersecurity remote jobs

Job Search Safety Tips

Here are some tips to help you search and apply for jobs safely:
Watch out for suspicious jobs Don't apply for jobs that offer high pay for little work or offer to hire you without an interview. Read more ›
Check the employer's profile Make sure you're applying for a trustworthy job by visiting the employer's profile and learning more about them. Read more ›
Protect your information Don't share personal details like your bank account or government-issued ID on suspicious websites or messengers. Read more ›
Report jobs that feel unsafe If you see a job that seems misleading, inappropriate or discriminatory, report it for going against our policies and we'll review it.

Share this job

Jobicy+ Subscription

Jobicy

614 professionals pay to access exclusive and experimental features on Jobicy

Free

USD $0/month

For people just getting started

  • • Unlimited applies and searches
  • • Access on web and mobile apps
  • • Weekly job alerts and digest
  • • Access to additional tools like Bookmarks, Applications, and more

Plus

USD $8/month

Everything in Free, and:

  • • Ad-free experience
  • • Daily job alerts and digest
  • • Personal career consultant
  • • AI-powered job advice
Go to account ›