IT Senior Security Compliance Analyst
Quick Overview
Job Description
Title: Senior Security & Compliance Analyst
Location: Tallahassee, Florida
Duration: 12+ Months contract (Extendable)
Job Summary
We are seeking an experienced Senior Security & Compliance Analyst to join our Information Security team. This role is responsible for supporting enterprise security governance, risk, compliance (GRC), and operational security initiatives. The ideal candidate will have a strong blend of policy development, security architecture, risk management, audit support, and hands-on technical security experience within Microsoft security environments.
The successful candidate will work closely with IT leadership, legal and compliance teams, business stakeholders, and third-party vendors to strengthen the organization''''s cybersecurity posture while ensuring compliance with industry standards and regulatory requirements.
Key Responsibilities
Security Governance & Compliance
Develop, maintain, and update enterprise information security policies, standards, procedures, and guidelines.
Implement and maintain security controls aligned with NIST Cybersecurity Framework (CSF) and NIST SP 800-53.
Map security controls to applicable regulatory and organizational compliance requirements.
Support governance, risk, and compliance (GRC) initiatives across the organization.
Risk Management & Security Assessments
Conduct enterprise security risk assessments and identify control gaps.
Evaluate security risks and recommend remediation strategies based on business priorities.
Document risk assessments, exceptions, and mitigation plans for leadership review.
Support internal and external security audits and regulatory assessments.
Microsoft Security Operations
Administer and support security capabilities within the Microsoft 365 ecosystem.
Implement and monitor security controls using Microsoft Defender, Microsoft Purview, Microsoft Entra ID (Azure AD), and related Microsoft security technologies.
Support endpoint protection, vulnerability management, identity and access management, and security monitoring initiatives.
Assist with incident investigation, response, and post-incident analysis.
Identity & Access Management
Develop and maintain Identity and Access Management (IAM) standards and access control processes.
Support user provisioning, privileged access management, periodic access reviews, and identity governance initiatives.
Recommend improvements to authentication, authorization, and least-privilege access controls.
Vulnerability Management
Coordinate enterprise vulnerability management activities.
Review vulnerability assessment results, prioritize remediation efforts, and collaborate with technical teams to resolve identified issues.
Track remediation progress and report security metrics to leadership.
Security Documentation
Produce high-quality security documentation, including:
Security policies
Standards and procedures
Risk assessments
Audit responses
Security reports
Management presentations
Compliance documentation
Collaboration & Advisory
Partner with IT, legal, compliance, business units, and third-party vendors on security initiatives.
Communicate security risks, technical findings, and remediation recommendations to both technical and non-technical audiences.
Provide security guidance throughout project planning, implementation, and operational support.
Required Qualifications
Bachelor''''s degree in Cybersecurity, Computer Science, Information Systems, or a related field (or equivalent professional experience).
7+ years of experience in Information Security, including both Security Governance, Risk & Compliance (GRC) and hands-on Security Operations.
Experience developing and implementing security policies, standards, and procedures.
Strong knowledge of NIST SP 800-53, NIST Cybersecurity Framework (CSF), and security governance best practices.
Experience performing security risk assessments and supporting internal and external audits.
Hands-on experience with Microsoft 365 security technologies, including:
Microsoft Defender
Microsoft Purview
Microsoft Entra ID (Azure AD)
Endpoint Security
Identity & Access Management
Experience coordinating vulnerability management and remediation activities.
Strong analytical, documentation, and technical writing skills.
Excellent communication and stakeholder management skills.
Preferred Qualifications
Experience supporting government, public sector, healthcare, or other highly regulated organizations.
Knowledge of CJIS, HIPAA, or other regulatory compliance frameworks.
Experience implementing Identity & Access Management (IAM) controls and governance.
Hands-on experience with Microsoft 365 G5 security capabilities.
Experience with vulnerability management platforms and remediation tracking.
Experience using PowerShell or other scripting languages for automation and reporting.
Preferred Certifications
One or more of the following certifications is highly preferred:
CISSP – Certified Information Systems Security Professional
CISM – Certified Information Security Manager
CISA – Certified Information Systems Auditor
CRISC – Certified in Risk and Information Systems Control
CGRC – Certified in Governance, Risk and Compliance
Skills
Similar jobs
Systems Security Engineer Anti-Tamper with Security Clearance
Anduril Industries · Costa Mesa, United States
10 minutes ago$166k - $220k/yrSystems Security Engineer, Programs with Security Clearance
Anduril Industries · Costa Mesa, United States
10 minutes ago$146k - $194k/yrSr. Network Security Engineer
ARROWCORE GROUP · San Jose, United States
11 minutes agoStaff Systems Security Engineer, Programs with Security Clearance
Anduril Industries · Costa Mesa, United States
11 minutes ago$191k - $253k/yrSecurity Engineer
Dahl Consulting · United States
13 minutes ago€74/hrCyber Software Engineer with Security Clearance
Northrop Grumman · Cincinnati, United States
16 minutes ago$91.8k - $137.6k/yr