Haystack
← Back to Jobs
Administrative

IT Senior Security Compliance Analyst

Cogent Infotech CorpTallahassee, FL🇺🇸United StatesPosted 30 Jul 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Title: Senior Security & Compliance Analyst

Location: Tallahassee, Florida

Duration: 12+ Months contract (Extendable)

Job Summary

We are seeking an experienced Senior Security & Compliance Analyst to join our Information Security team. This role is responsible for supporting enterprise security governance, risk, compliance (GRC), and operational security initiatives. The ideal candidate will have a strong blend of policy development, security architecture, risk management, audit support, and hands-on technical security experience within Microsoft security environments.

The successful candidate will work closely with IT leadership, legal and compliance teams, business stakeholders, and third-party vendors to strengthen the organization''''s cybersecurity posture while ensuring compliance with industry standards and regulatory requirements.

Key Responsibilities

Security Governance & Compliance

Develop, maintain, and update enterprise information security policies, standards, procedures, and guidelines.

Implement and maintain security controls aligned with NIST Cybersecurity Framework (CSF) and NIST SP 800-53.

Map security controls to applicable regulatory and organizational compliance requirements.

Support governance, risk, and compliance (GRC) initiatives across the organization.

Risk Management & Security Assessments

Conduct enterprise security risk assessments and identify control gaps.

Evaluate security risks and recommend remediation strategies based on business priorities.

Document risk assessments, exceptions, and mitigation plans for leadership review.

Support internal and external security audits and regulatory assessments.

Microsoft Security Operations

Administer and support security capabilities within the Microsoft 365 ecosystem.

Implement and monitor security controls using Microsoft Defender, Microsoft Purview, Microsoft Entra ID (Azure AD), and related Microsoft security technologies.

Support endpoint protection, vulnerability management, identity and access management, and security monitoring initiatives.

Assist with incident investigation, response, and post-incident analysis.

Identity & Access Management

Develop and maintain Identity and Access Management (IAM) standards and access control processes.

Support user provisioning, privileged access management, periodic access reviews, and identity governance initiatives.

Recommend improvements to authentication, authorization, and least-privilege access controls.

Vulnerability Management

Coordinate enterprise vulnerability management activities.

Review vulnerability assessment results, prioritize remediation efforts, and collaborate with technical teams to resolve identified issues.

Track remediation progress and report security metrics to leadership.

Security Documentation

Produce high-quality security documentation, including:

Security policies

Standards and procedures

Risk assessments

Audit responses

Security reports

Management presentations

Compliance documentation

Collaboration & Advisory

Partner with IT, legal, compliance, business units, and third-party vendors on security initiatives.

Communicate security risks, technical findings, and remediation recommendations to both technical and non-technical audiences.

Provide security guidance throughout project planning, implementation, and operational support.

Required Qualifications

Bachelor''''s degree in Cybersecurity, Computer Science, Information Systems, or a related field (or equivalent professional experience).

7+ years of experience in Information Security, including both Security Governance, Risk & Compliance (GRC) and hands-on Security Operations.

Experience developing and implementing security policies, standards, and procedures.

Strong knowledge of NIST SP 800-53, NIST Cybersecurity Framework (CSF), and security governance best practices.

Experience performing security risk assessments and supporting internal and external audits.

Hands-on experience with Microsoft 365 security technologies, including:

Microsoft Defender

Microsoft Purview

Microsoft Entra ID (Azure AD)

Endpoint Security

Identity & Access Management

Experience coordinating vulnerability management and remediation activities.

Strong analytical, documentation, and technical writing skills.

Excellent communication and stakeholder management skills.

Preferred Qualifications

Experience supporting government, public sector, healthcare, or other highly regulated organizations.

Knowledge of CJIS, HIPAA, or other regulatory compliance frameworks.

Experience implementing Identity & Access Management (IAM) controls and governance.

Hands-on experience with Microsoft 365 G5 security capabilities.

Experience with vulnerability management platforms and remediation tracking.

Experience using PowerShell or other scripting languages for automation and reporting.

Preferred Certifications

One or more of the following certifications is highly preferred:

CISSP – Certified Information Systems Security Professional

CISM – Certified Information Security Manager

CISA – Certified Information Systems Auditor

CRISC – Certified in Risk and Information Systems Control

CGRC – Certified in Governance, Risk and Compliance

Skills

Stakeholder Management

Similar jobs