Senior Security Compliance Analyst
quantamEast Lansing, MI
Senior Security Compliance Analyst
quantamEast Lansing, MI
yesterday
Occupations
Information Security AnalystsSecurity Management SpecialistsInformation Security EngineersIndustries
Computer Systems Design ServicesOther Management Consulting ServicesAdministrative Management and General Management Consulting ServicesAbout the role
Quantam Solutions provides IT solutions and consulting for various clients. We offer competitive hourly wages, health benefits, paid time off, and a 401(k) plan. We are currently seeking a System Security Analyst. Candidates must be located within 90 miles of Lansing, MI. Interviews will be held in person in Lansing, MI. There is no option for a video interview. The work schedule is hybrid with two days onsite in Lansing, MI and three days remote. There is no option for a fully remote work schedule.
Job Description:
Our client is seeking a Senior System Security Analyst / IT Business Compliance Analyst to serve as a senior resource responsible for the oversight, guidance, and strategic direction of system security and compliance activities. This position will focus heavily on completing, updating, and maintaining System Security Plans (SSPs) and Disaster Recovery Plans (DRPs) for critical enterprise applications. The primary responsibility of this role is to serve as a compliance authority and liaison between business partners, technical teams, security groups, vendors, auditors, project managers, analysts, and management. The Senior System Security Analyst will ensure that security requirements, processes, controls, and documentation align with organizational standards, NIST frameworks and controls, and enterprise security governance requirements.
Job Responsibilities:
Provide leadership and oversight for maintaining and updating System Security Plans (SSPs), ensuring documentation is accurate, complete, and aligned with NIST protocols and organizational compliance standards. Lead and coordinate the Authority to Operate (ATO) renewal process, including planning, preparation of required materials, timeline management, and ensuring successful approval and continued compliance. Ensure supported applications maintain a valid ATO on the required three-year cycle. Validate and maintain accurate security controls throughout each ATO renewal period. Review security risk assessment results and provide management with recommended corrective actions. Assess the risk and scope of mid- to high-level security incidents. Develop management reports based on security and compliance metrics and conduct trend analysis. Work with stakeholders to address and track Plans of Action and Milestones (POA&Ms) and other compliance requirements. Ensure timely reporting, remediation, and closure of identified security and compliance issues. Provide senior-level support across multiple business areas with a focus on standardized security plan updates, documentation improvements, and process consistency. Analyze existing compliance documentation and identify security gaps, risks, and required corrective actions. Coordinate with technical teams, business owners, enterprise security personnel, vendors, auditors, project managers, and leadership. Ensure all evidence and documentation required for SSP and ATO processes is properly completed and maintained. Oversee the review, updating, and remediation of security controls. Track, communicate, and help resolve security control deficiencies. Identify procedural gaps, security risks, and required updates during compliance and renewal cycles. Support enterprise security governance by maintaining accurate records, providing guidance, mentoring team members, and driving completion of compliance activities. Lead mid- to high-level Incident Response activities. Serve as a subject matter resource for cyber event detection, correlation, response, and recovery.
Job Qualifications:
Bachelor’s degree in Cybersecurity, Information Assurance, Business Analytics, Information Technology, or a related field, or 5 years of relevant professional experience in lieu of a degree. Advanced degree preferred, including a Master’s degree in Cybersecurity, Information Assurance, Information Systems, IT Leadership, or an MBA with an IT or Security concentration. Knowledge of the NIST Framework and security controls is required. Strong written and verbal communication skills. Strong documentation skills. Ability to collaborate effectively across business, technical, security, and leadership teams.
Required Skills and Experience:
5 years required: Experience providing audit evidence to demonstrate compliance with security standards such as NIST, PCI, HIPAA, and FERPA.5 years required: Experience working with complex IT web applications within the past five years.5 years required: Experience leading meetings and preparing oral and written reports.5 years required: Experience serving as a liaison between business and IT teams.2 years highly desired: Knowledge or experience creating supporting documentation for IT system audits.2 years highly desired: Experience creating Disaster Recovery Plans, Business Continuity Plans, and Incident Response Plans.
Matching similar jobs
JOB OVERVIEW
Experience level
Lead
Location
East Lansing, MI
Occupation
Information Security Analysts
Industry
Computer Systems Design Services
Posted
yesterday
Tired of running searches?
Rank the roles you'd take once, and matches like these arrive on their own.
CREATE PROFILE