Quick Overview
Job Description
We're looking for a Senior IT Security Compliance Analyst to lead security planning and authorization work for a portfolio of public-sector applications. You'll be the compliance authority for several business areas: keeping System Security Plans current, guiding systems through Authority to Operate (ATO) renewals, and making sure security controls, documentation and processes line up with NIST standards.
This is a senior, hands-on role. You'll work across business owners, technical teams, enterprise security, vendors, auditors and project managers, and you'll mentor other analysts on the team.
What you'll do
- Lead the maintenance and updating of System Security Plans (SSPs), making sure they're accurate, complete and aligned with NIST controls.
- Plan and run the ATO renewal process on a three-year cycle, from preparing materials and managing timelines through approval and continuous compliance.
- Validate and maintain security controls throughout each authorization period, and oversee remediation of control gaps.
- Track Plans of Action & Milestones (POA&Ms) and other compliance requirements with stakeholders through to closure.
- Review risk assessment results, brief management, and recommend corrective actions.
- Assess the risk and scope of high-level security incidents, lead mid- to high-level incident response, and support detection, response and recovery.
- Develop metrics-based reports and trend analysis for management across multiple business areas.
- Create and maintain Disaster Recovery Plans, and contribute to business continuity and incident response planning.
- Find gaps in existing compliance documentation and drive consistent practices across all supported systems.
- Coordinate with technical teams, business owners and security staff so that all evidence and artifacts for SSP and ATO work are complete and current.
Required Qualifications:
- 5+ years providing audit evidence to comply with security standards such as NIST, PCI, HIPAA or FERPA.
- 5+ years of exposure to complex IT web applications.
- 5+ years leading meetings and delivering oral and written reports.
- 5+ years working as a liaison between business and IT areas.
- Strong working knowledge of the NIST framework and controls (required).
- Strong writing and documentation skills.
- A bachelor's degree in cybersecurity, information assurance, business analytics or an IT-related field, or 5 years of equivalent experience.
Preferred Qualifications:
- 2+ years creating documentation to support IT system audits.
- 2+ years creating Disaster Recovery, Business Continuity or Incident Response Plans.
- A master's in cybersecurity, information assurance or IT leadership, or an MBA with an IT or security concentration.
- Certifications such as CISSP, CGRC (formerly CAP), CISA or CISM.
Similar jobs
- M-
Record Your Daily Routine & Get Paid - AI Training (Remote)
NewMindrift - Data annotation
Albany, New York🇺🇸RemoteYesterdayTechnology - M-
Record Your Daily Routine & Get Paid - AI Training (Remote)
NewMindrift - Data annotation
Rochester, New York🇺🇸RemoteYesterdayTechnology - M-
Record Your Daily Routine & Get Paid - AI Training (Remote)
NewMindrift - Data annotation
Buffalo, New York🇺🇸RemoteYesterdayTechnology - M-
Record Your Daily Routine & Get Paid - AI Training (Remote)
NewMindrift - Data annotation
Brooklyn, New York🇺🇸RemoteYesterdayTechnology - M-
Record Your Daily Routine & Get Paid - AI Training (Remote)
NewMindrift - Data annotation
New York🇺🇸RemoteYesterdayTechnology - M-
Record Your Daily Routine & Get Paid - AI Training (Remote)
NewMindrift - Data annotation
New York🇺🇸RemoteYesterdayTechnology