Job type
- Full-time
Job description
Senior It Security Compliance Analyst
We're looking for a Senior IT Security Compliance Analyst to lead security planning and authorization work for a portfolio of public-sector applications. You'll be the compliance authority for several business areas: keeping System Security Plans current, guiding systems through Authority to Operate (ATO) renewals, and making sure security controls, documentation and processes line up with NIST standards.
This is a senior, hands-on role. You'll work across business owners, technical teams, enterprise security, vendors, auditors and project managers, and you'll mentor other analysts on the team.
What You'll Do
- Lead the maintenance and updating of System Security Plans (SSPs), making sure they're accurate, complete and aligned with NIST controls.
- Plan and run the ATO renewal process on a three-year cycle, from preparing materials and managing timelines through approval and continuous compliance.
- Validate and maintain security controls throughout each authorization period, and oversee remediation of control gaps.
- Track Plans of Action & Milestones (POA&Ms) and other compliance requirements with stakeholders through to closure.
- Review risk assessment results, brief management, and recommend corrective actions.
- Assess the risk and scope of high-level security incidents, lead mid- to high-level incident response, and support detection, response and recovery.
- Develop metrics-based reports and trend analysis for management across multiple business areas.
- Create and maintain Disaster Recovery Plans, and contribute to business continuity and incident response planning.
- Find gaps in existing compliance documentation and drive consistent practices across all supported systems.
- Coordinate with technical teams, business owners and security staff so that all evidence and artifacts for SSP and ATO work are complete and current.