Haystack
← Back to Jobs
Technology
TA

IT Security Analyst

TalentOS AI LLCLansing, MI🇺🇸United StatesPosted Oct 7, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Lansing, MI, United States
Posted
22 hours ago
HIPAA

Job Description

Position Overview

The State of Michigan is seeking a Senior IT Security/Business Compliance Analyst to support the Department of Technology, Management and Budget (DTMB) Agency Services and applications supporting MiLEAP, MCSC, and MDCR.

The successful candidate will provide senior-level oversight and guidance for System Security Plans (SSPs), Authority to Operate (ATO) processes, security controls, compliance documentation, risk management, and Disaster Recovery Plans (DRPs).

This role will serve as a key liaison between business stakeholders, technical teams, security organizations, management, vendors, auditors, project managers, and other IT professionals.

Key Responsibilities

Lead and maintain System Security Plans (SSPs) and ensure documentation aligns with State of Michigan security standards and NIST requirements.

Lead and coordinate Authority to Operate (ATO) renewal activities, including planning, documentation, timelines, evidence collection, and approvals.

Ensure supported applications maintain valid ATOs and accurate security controls throughout the compliance lifecycle.

Review security risk assessments and provide recommendations for corrective actions.

Identify, assess, and report security risks and incidents to management.

Develop management reports, security metrics, and trend analysis across supported agencies and applications.

Manage and track Plans of Action & Milestones (POA&Ms) through resolution.

Review existing compliance documentation, identify gaps, and coordinate remediation activities.

Coordinate collection and maintenance of security evidence and artifacts required for SSP and ATO processes.

Collaborate with technical teams, business owners, enterprise security teams, project managers, vendors, and auditors.

Lead security control reviews, updates, remediation, and documentation activities.

Identify procedural gaps and recommend improvements to security and compliance processes.

Provide guidance and mentoring to team members and stakeholders.

Participate in enterprise security governance activities.

Lead mid- to high-level incident response activities.

Support cyber event detection, correlation, response, and recovery.

Required Qualifications

Bachelor's degree in Cybersecurity, Information Assurance, Business Analytics, Information Technology, or a related field; OR 5 years of relevant experience.

Strong professional knowledge of the NIST Framework and security controls.

Excellent written and verbal communication skills.

Strong documentation and analytical skills.

Ability to work effectively across business, technical, security, and management teams.

Required Experience

Candidates must have 5+ years of experience in each of the following:

Providing audit evidence to comply with security standards such as NIST, PCI, HIPAA, or FERPA.

Working with complex IT web applications within the past 5 years.

Leading meetings and preparing/presenting oral and written reports.

Acting as a liaison between different business and IT organizations.

Preferred Experience

2+ years of experience creating supporting documentation for IT system audits.

2+ years of experience creating or maintaining:

Disaster Recovery Plans (DRP)

Business Continuity Plans (BCP)

Incident Response Plans (IRP)

Experience with SSP development and maintenance.

Experience with ATO processes and renewals.

Experience with POA&M management.

Experience with security risk assessments and remediation.

Experience working with auditors, vendors, and enterprise security teams.

Candidate Requirements

Local candidates only: Candidate must be located within 90 miles of Lansing, MI at the time of submission.

Candidate must be able to work hybrid, with 2 days onsite per week from Day 1.

Remote-only candidates will not be considered.

Candidate must be available for a potential in-person interview.

Resume should be 4–5 pages maximum.

Resume must include the candidate's full legal first and last name only.

A valid Right to Represent (RTR) acknowledging the hybrid work schedule is required.

Ideal Candidate Profile

The ideal candidate is a senior cybersecurity/compliance professional with strong experience in NIST-based compliance, SSPs, ATOs, security audits, risk management, incident response, and security documentation.

The candidate should be comfortable leading meetings, communicating with senior stakeholders, coordinating across business and technical teams, and driving compliance activities to completion.

Similar jobs