Haystack
← Back to Jobs
Technology
ME

Lansing, MI - IT - Agency Services - MiLEAP - N/A - IT Security Analyst 3 - MiLEAP, MCSC

Morph Enterprise LLCLansing, MI🇺🇸United StatesPosted Oct 2, 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Lansing, MI, United States
Posted
18 hours ago
Stakeholder Management

Job Description

IT Security Analyst 3

Location: Lansing, MI
Work Arrangement: Hybrid – 2 days onsite per week
Duration: 1 Year Contract + Extension Likely
Interview: 1st Round Virtual; Potential 2nd Round In-Person
Local Candidates Only: Candidates must be located within 90 miles of Lansing, MI.

Position Overview

We are seeking an experienced IT Security Analyst 3 to support enterprise security compliance, risk management, security governance, and documentation activities.

The ideal candidate will have strong experience with NIST security standards, security audits, System Security Plans (SSPs), Authority to Operate (ATO), POA&Ms, security controls, risk assessments, and compliance documentation.

This position will work closely with business stakeholders, technical teams, security teams, management, vendors, auditors, and project teams to ensure security requirements and compliance activities are properly addressed.

Responsibilities

  • Lead the development, maintenance, and updating of System Security Plans (SSPs).

  • Ensure security documentation aligns with NIST frameworks, security controls, and organizational security standards.

  • Lead and coordinate Authority to Operate (ATO) renewal activities.

  • Prepare required ATO materials, coordinate evidence collection, manage timelines, and support approval activities.

  • Maintain accurate security controls and supporting documentation.

  • Review security risk assessments and provide recommendations for corrective actions.

  • Identify security and compliance gaps and coordinate remediation activities.

  • Manage and track Plans of Action & Milestones (POA&Ms) through resolution and closure.

  • Collect, review, and validate audit evidence for security assessments and compliance reviews.

  • Coordinate with technical teams, business owners, security personnel, vendors, auditors, and project managers.

  • Review and update security controls and compliance documentation.

  • Analyze existing compliance documentation and identify gaps, risks, and areas for improvement.

  • Develop security and compliance reports and perform trend analysis for management.

  • Provide guidance on security governance and compliance best practices.

  • Maintain accurate security and compliance records.

  • Participate in mid- to high-level incident response activities.

  • Support cyber event detection, correlation, response, and recovery.

  • Support the development and maintenance of Disaster Recovery Plans (DRPs), Business Continuity Plans (BCPs), and Incident Response Plans (IRPs).

  • Lead meetings and communicate security, compliance, risk, and remediation status to stakeholders and management.

  • Prepare clear written and verbal reports.

  • Collaborate with cross-functional teams to ensure timely completion of security and compliance activities.

Required Qualifications

  • 5+ years of experience providing audit evidence for security standards such as NIST, PCI, HIPAA, FERPA, or similar frameworks.

  • 5+ years of experience working with complex IT/web applications.

  • 5+ years of experience leading meetings and preparing written and verbal reports.

  • 5+ years of experience working as a liaison between business and IT teams.

  • Strong knowledge of NIST Framework and security controls.

  • Strong understanding of IT security compliance and governance.

  • Excellent written and verbal communication skills.

  • Strong documentation and analytical skills.

  • Ability to work effectively with technical and non-technical stakeholders.

Preferred Qualifications

  • 2+ years of experience creating supporting documentation for IT system audits.

  • 2+ years of experience creating or maintaining:

    • Disaster Recovery Plans

    • Business Continuity Plans

    • Incident Response Plans

  • Experience with System Security Plans (SSP).

  • Experience with Authority to Operate (ATO) processes.

  • Experience managing POA&Ms and security remediation.

  • Experience conducting security risk assessments.

  • Experience with GRC and security governance.

  • Experience working with auditors, vendors, and enterprise security teams.

Education

Bachelor's degree in Cybersecurity, Information Assurance, Business Analytics, Information Technology, or a related field.

Five years of relevant professional experience may be considered in lieu of a bachelor's degree.

Advanced degrees in Cybersecurity, Information Assurance, Information Systems, IT Leadership, or an MBA with an IT/Security concentration are preferred.

Primary Skills

NIST | NIST 800-53 | IT Security Compliance | GRC | SSP | ATO | POA&M | Security Controls | Security Audit | Audit Evidence | Risk Assessment | Security Governance | DRP | BCP | Incident Response | Compliance Documentation | Complex Web Applications | Stakeholder Management

Work Requirements

  • Hybrid – 2 days onsite per week from Day 1.

  • Candidates must be located within 90 miles of Lansing, MI at the time of submission.

  • Must be available for a potential in-person interview.

  • Remote-only candidates will not be considered.

Similar jobs