Quick Overview
Job Description
Position Overview
The State of Michigan is seeking a Senior IT Security/Business Compliance Analyst to support the Department of Technology, Management and Budget (DTMB) Agency Services and applications supporting MiLEAP, MCSC, and MDCR.
The successful candidate will provide senior-level oversight and guidance for System Security Plans (SSPs), Authority to Operate (ATO) processes, security controls, compliance documentation, risk management, and Disaster Recovery Plans (DRPs).
This role will serve as a key liaison between business stakeholders, technical teams, security organizations, management, vendors, auditors, project managers, and other IT professionals.
Key Responsibilities
Lead and maintain System Security Plans (SSPs) and ensure documentation aligns with State of Michigan security standards and NIST requirements.
Lead and coordinate Authority to Operate (ATO) renewal activities, including planning, documentation, timelines, evidence collection, and approvals.
Ensure supported applications maintain valid ATOs and accurate security controls throughout the compliance lifecycle.
Review security risk assessments and provide recommendations for corrective actions.
Identify, assess, and report security risks and incidents to management.
Develop management reports, security metrics, and trend analysis across supported agencies and applications.
Manage and track Plans of Action & Milestones (POA&Ms) through resolution.
Review existing compliance documentation, identify gaps, and coordinate remediation activities.
Coordinate collection and maintenance of security evidence and artifacts required for SSP and ATO processes.
Collaborate with technical teams, business owners, enterprise security teams, project managers, vendors, and auditors.
Lead security control reviews, updates, remediation, and documentation activities.
Identify procedural gaps and recommend improvements to security and compliance processes.
Provide guidance and mentoring to team members and stakeholders.
Participate in enterprise security governance activities.
Lead mid- to high-level incident response activities.
Support cyber event detection, correlation, response, and recovery.
Required Qualifications
Bachelor's degree in Cybersecurity, Information Assurance, Business Analytics, Information Technology, or a related field; OR 5 years of relevant experience.
Strong professional knowledge of the NIST Framework and security controls.
Excellent written and verbal communication skills.
Strong documentation and analytical skills.
Ability to work effectively across business, technical, security, and management teams.
Required Experience
Candidates must have 5+ years of experience in each of the following:
Providing audit evidence to comply with security standards such as NIST, PCI, HIPAA, or FERPA.
Working with complex IT web applications within the past 5 years.
Leading meetings and preparing/presenting oral and written reports.
Acting as a liaison between different business and IT organizations.
Preferred Experience
2+ years of experience creating supporting documentation for IT system audits.
2+ years of experience creating or maintaining:
Disaster Recovery Plans (DRP)
Business Continuity Plans (BCP)
Incident Response Plans (IRP)
Experience with SSP development and maintenance.
Experience with ATO processes and renewals.
Experience with POA&M management.
Experience with security risk assessments and remediation.
Experience working with auditors, vendors, and enterprise security teams.
Candidate Requirements
Local candidates only: Candidate must be located within 90 miles of Lansing, MI at the time of submission.
Candidate must be able to work hybrid, with 2 days onsite per week from Day 1.
Remote-only candidates will not be considered.
Candidate must be available for a potential in-person interview.
Resume should be 4–5 pages maximum.
Resume must include the candidate's full legal first and last name only.
A valid Right to Represent (RTR) acknowledging the hybrid work schedule is required.
Ideal Candidate Profile
The ideal candidate is a senior cybersecurity/compliance professional with strong experience in NIST-based compliance, SSPs, ATOs, security audits, risk management, incident response, and security documentation.
The candidate should be comfortable leading meetings, communicating with senior stakeholders, coordinating across business and technical teams, and driving compliance activities to completion.
Similar jobs
- KT
Senior Security Engineer
NewKforce Technology Staffing
San Jose, CA🇺🇸Hybrid22 hours agoDockerAWSSOC 2+11Technology - CP
Workspace Security Sales Specialist
NewCheck Point Software Technologies
United States🇺🇸$120k - $160k/yrOn-site18 hours agoSalesforceCRMEnterprise Sales+5Sales - SC
Immediately require - Security Analyst - Entry Level
NewSita Consulting Services, LLC
SC🇺🇸On-site22 hours agoPowerShellTechnology - QS
Cyber Network Defense Analyst with Security Clearance
NewQuantum Science Solutions
Arlington, VA🇺🇸On-site22 hours agoPythonTechnology - AG
Aviation Cybersecurity Engineering Professional
AIT Global, Inc.
Dorval, QC🇺🇸Hybrid2 weeks agoLESSPenetration TestingTechnology - TE
Information Systems Security Engineer (ISSE)
NewTekSynap
Fort Belvoir, Virginia🇺🇸$145k - $170k/yrHybrid54 minutes agoLogstashSAMLPKI+1Technology