Senior IT Business/Compliance Analyst / IT Security Analyst
- Full-time
- Quick Apply
Senior IT Business/Compliance Analyst / IT Security Analyst
Location: Lansing, MI
Work Arrangement: Hybrid Onsite 2 Days/Week
Duration: 12 Months+
Interview: Virtual First Round | Potential In-Person Second Round Job Summary
STAFFXPERT LLC is seeking a Senior IT Business/Compliance Analyst / IT Security Analyst on behalf of our client in Lansing, MI to provide senior-level leadership in IT security compliance, governance, risk management, and security documentation.
The role will focus on maintaining System Security Plans (SSPs), Disaster Recovery Plans (DRPs), Authority to Operate (ATO) processes, security controls, compliance documentation, and incident response while serving as a key liaison between business stakeholders, technical teams, security groups, and management.
Key Responsibilities
-
Provide senior-level oversight for maintaining and updating System Security Plans (SSPs).
-
Lead and coordinate Authority to Operate (ATO) renewal activities, including planning, documentation, timelines, and approvals.
-
Ensure security controls remain accurate, documented, and aligned with applicable security standards.
-
Review security risk assessments and recommend corrective actions.
-
Track and manage Plans of Action & Milestones (POA&Ms) and other compliance requirements.
-
Analyze compliance documentation, identify gaps and risks, and coordinate remediation activities.
-
Coordinate with technical teams, business owners, security personnel, auditors, vendors, project managers, and other stakeholders.
-
Ensure required security evidence and artifacts are properly completed and maintained.
-
Oversee the review, update, and remediation of security controls.
-
Identify procedural gaps and recommend improvements to strengthen security governance.
-
Develop security metrics, management reports, and trend analysis related to risks and incidents.
-
Provide guidance and mentoring to stakeholders and team members.
-
Support mid- to high-level incident response activities.
-
Contribute to cyber event detection, correlation, response, and recovery initiatives.
-
Drive consistency and continuous improvement across security compliance processes.
Required Qualifications
-
5+ years of experience providing audit evidence to comply with security standards such as NIST, PCI, HIPAA, or FERPA.
-
5+ years of professional experience with the NIST Framework and security controls.
-
Experience working with complex IT web applications within the past 5 years.
-
5+ years of experience leading meetings and preparing oral and written reports.
-
5+ years of experience serving as a liaison between business and IT teams.
-
Bachelor's degree in Cybersecurity, Information Assurance, Business Analytics, Information Technology, or a related field.
-
Strong understanding of security compliance, governance, risk management, and security documentation.
-
Excellent communication, analytical, organizational, and stakeholder-management skills.
Preferred Qualifications
-
2+ years of experience creating documentation supporting IT system audits.
-
Experience developing Disaster Recovery Plans (DRPs).
-
Experience developing Business Continuity Plans (BCPs).
-
Experience developing Incident Response Plans (IRPs).
-
Experience with ATO processes, SSPs, POA&Ms, and security control remediation.
-
Advanced degree in:
-
Cybersecurity
-
Information Assurance
-
Information Systems / IT Leadership
-
MBA with an IT or Security concentration
-
-
Experience supporting enterprise security governance and incident response programs.
Work Environment
-
Hybrid position based in Lansing, Michigan.
-
Onsite from Day 1, two days per week.
-
Candidates must be local to the Lansing area.
-
Candidates must be available for an in-person interview if requested.