← Back to Jobs
Technology
268-2 IT Security Compliance Analyst
Stafford GrayLansing, MI🇺🇸United StatesPosted 13 Aug 2026
Quick Overview
Work Type
Hybrid
Level
Mid Senior
Job Description
The Compliance Analyst is responsible for completing and maintaining System Security Plans (SSPs) for new and existing systems, documented within a Governance, Risk, and Compliance (GRC) tool. This role requires close coordination with IT project teams, tech leads, business and enterprise security representatives, and product owners to establish and maintain security controls and processes, identify vulnerabilities, and coordinate remediation efforts.
Compliance Analysts are assigned to internal development projects and are available for consultation on Commercial Off-the-Shelf (COTS) procurement-phase projects. For COTS implementation-phase projects, Compliance Analysts serve as a core resource navigating SSP/Authority to Operate (ATO) activities with the enterprise security team to support security requirements through Go Live.
Responsibilities:
Requirements
One of the following:
Compliance Analysts are assigned to internal development projects and are available for consultation on Commercial Off-the-Shelf (COTS) procurement-phase projects. For COTS implementation-phase projects, Compliance Analysts serve as a core resource navigating SSP/Authority to Operate (ATO) activities with the enterprise security team to support security requirements through Go Live.
Responsibilities:
- Create SSPs in collaboration with automation managers, system owners, system security administrators, and project teams for new applications, aligned with the organization's Secure Application Development Life Cycle and security accreditation process
- Maintain SSPs for existing applications requiring ATO, including those undergoing software or hardware enhancements
- Collaborate with business representatives to establish system registration
- Lead and identify security testing and system scanning requirements
- Perform risk assessments and provide responses for security controls
- Continuously monitor plans of action, milestones, and corrective action plans related to SSPs, in collaboration with the enterprise information management office
- Validate SSPs to ensure NIST control requirements are met
- Author recommendations on improving security posture in accordance with organizational policies, standards, and procedures, and NIST controls
- Lead team members and vendors on proper artifact collection to satisfy assessment requirements
- Coordinate scanning and enterprise activities with the security team, tech leads, and business areas
- Lead the system Data Classification component of the SSP/ATO process
Requirements
- 1 to 3 years of experience in the field or a related area
- Working knowledge of commonly used concepts, practices, and procedures within IT security/compliance
One of the following:
- A bachelor's degree or higher with 21 semester (32 term) credits in computer science, data processing, computer information systems, data communications, networking, systems analysis, computer programming, or mathematics - plus at least 2 years of experience as an application programmer, computer operator, or IT technician
- An associate's degree with 16 semester (24 term) credits in one of the above fields (or equivalent) - plus at least 2 years of experience as above
- A high school diploma or equivalent - plus 3 years of experience as an application programmer, computer operator, or IT technician (official transcripts required if applicable)
- A relevant IT certification
Similar jobs
Senior Info Security Engineer
Core & Main · St. Louis, United States
8 minutes agoCyber Security Manager, Architecture and Engineering Team
Little Caesars Enterprises · Detroit, United States
8 minutes agoSystems Security Engineer
General Dynamics · Dedham, United States
9 minutes ago$124.2k - $132k/yrSecurity Operations Center Specialist
Brinks · New York, United States
27 minutes agoIT Security Specialist 2(ITSS2) (809183)
Key Business Solutions, Inc. · United States
44 minutes agoCompliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance)
ShorePoint, Inc · Washington, United States
44 minutes ago