Stafford Gray
Senior IT Security Compliance Analyst
Lansing, Michigan · On-site · Posted yesterday
Opens apply.workable.com
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Contract
- Work mode
- On-site
- Source
- Workable (employer's hiring system)
Skills mentioned
Incident Response, Cybersecurity
About the role
We're looking for a Senior IT Security Compliance Analyst to lead security planning and authorization work for a portfolio of public-sector applications. You'll be the compliance authority for several business areas: keeping System Security Plans current, guiding systems through Authority to Operate (ATO) renewals, and making sure security controls, documentation and processes line up with NIST standards.
This is a senior, hands-on role. You'll work across business owners, technical teams, enterprise security, vendors, auditors and project managers, and you'll mentor other analysts on the team.
What you'll do
- Lead the maintenance and updating of System Security Plans (SSPs), making sure they're accurate, complete and aligned with NIST controls.
- Plan and run the ATO renewal process on a three-year cycle, from preparing materials and managing timelines through approval and continuous compliance.
- Validate and maintain security controls throughout each authorization period, and oversee remediation of control gaps.
- Track Plans of Action & Milestones (POA&Ms) and other compliance requirements with stakeholders through to closure.
- Review risk assessment results, brief management, and recommend corrective actions.
- Assess the risk and scope of high-level security incidents, lead mid- to high-level incident response, and support detection, response and recovery.
- Develop metrics-based reports and trend analysis for management across multiple business areas.
- Create and maintain Disaster Recovery Plans, and contribute to business continuity and incident response planning.
- Find gaps in existing compliance documentation and drive consistent practices across all supported systems.
- Coordinate with technical teams, business owners and security staff so that all evidence and artifacts for SSP and ATO work are complete and current.
Requirements
Required Qualifications:
- 5+ years providing audit evidence to comply with security standards such as NIST, PCI, HIPAA or FERPA.
- 5+ years of exposure to complex IT web applications.
- 5+ years leading meetings and delivering oral and written reports.
- 5+ years working as a liaison between business and IT areas.
- Strong working knowledge of the NIST framework and controls (required).
- Strong writing and documentation skills.
- A bachelor's degree in cybersecurity, information assurance, business analytics or an IT-related field, or 5 years of equivalent experience.
Preferred Qualifications:
- 2+ years creating documentation to support IT system audits.
- 2+ years creating Disaster Recovery, Business Continuity or Incident Response Plans.
- A master's in cybersecurity, information assurance or IT leadership, or an MBA with an IT or security concentration.
- Certifications such as CISSP, CGRC (formerly CAP), CISA or CISM.
Job ID wk-staffordgray-A3830FDB94 · Original posting ↗