Haystack
← Back to Jobs
Operations & Project Management
CO

Sr. Business Analyst – Security

Congensys Corp.Quincy, MA🇺🇸United StatesPosted 31 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Quincy, MA, United States
Posted
21 hours ago
Business AnalysisRequirements Gathering

Job Description

Job Title: Sr. Business Analyst – Security

Location: Boston, MA / Quincy, MA
Work Model: Hybrid – Onsite 2 Days/Week
Duration: 6–12+ Months, Potential Extension
Employment Type: W2 Only
Work Schedule: Monday–Friday, 8:00 AM–4:00 PM EST

Important

W2 Only – No C2C / No 1099

Candidates must be able to work onsite in the Boston/Quincy, MA area 2 days per week.

To Apply:
Please send your updated resume to

Please include your current location, work authorization, availability, and confirmation of onsite availability.

Job Description

We are seeking a Senior Business Analyst – Security with strong experience in Information Security, Cybersecurity, Security Governance, Risk & Compliance (GRC), and security process documentation.

The ideal candidate will work closely with the CISO Office, Information Security teams, IT teams, and business stakeholders to analyze current security processes, identify gaps, document procedures, and develop improved future-state workflows.

Key Responsibilities

  • Gather, analyze, and document business, functional, and security requirements.
  • Analyze current-state security processes and develop future-state workflows.
  • Create and maintain security policies, procedures, SOPs, playbooks, runbooks, process guides, and workflow documentation.
  • Develop process flows and swimlane diagrams.
  • Identify security process gaps, risks, inefficiencies, and improvement opportunities.
  • Support Security Governance, Risk & Compliance (GRC) initiatives.
  • Support security risk and control assessments, audit readiness, and remediation tracking.
  • Document risks, controls, findings, remediation activities, dependencies, and ownership.
  • Facilitate requirements workshops and stakeholder interviews with Security, Risk, Compliance, Privacy, IT, and business teams.
  • Prepare security reports, presentations, dashboards, and status updates for stakeholders and leadership.
  • Support security reviews and assessments and document findings and recommended remediation.
  • Assist with security training, communications, and process adoption.
  • Develop future-state process documentation and operational improvement roadmaps.
  • Support security projects and initiatives through planning, tracking, and monitoring.
  • Translate informal or undocumented security practices into standardized, repeatable, and auditable processes.

Required Qualifications

  • 6+ years of IT / Business Analysis experience.
  • Strong experience as a Business Analyst, Security Analyst, Cybersecurity Analyst, or related role.
  • Hands-on experience with Information Security / Cybersecurity processes.
  • Strong experience with Security Process Documentation and Analysis.
  • Experience creating security policies, procedures, SOPs, playbooks, runbooks, and workflows.
  • Experience with GRC, security risk management, compliance, and audit readiness.
  • Experience with requirements gathering, stakeholder interviews, process mapping, and gap analysis.
  • Strong written and verbal communication skills.
  • Strong documentation, analytical, and presentation skills.

Preferred Qualifications

  • Healthcare or other regulated-industry experience.
  • Experience working with a CISO Office.
  • Knowledge of:
    • NIST Cybersecurity Framework (NIST CSF)
    • CIS Controls
    • ISO/IEC 27001
  • Experience with security assessments, control validation, remediation tracking, and risk management.

Important

W2 Only – No C2C / No 1099

Candidates must be able to work onsite in the Boston/Quincy, MA area 2 days per week.

To Apply:
Please send your updated resume to

Please include your current location, work authorization, availability, and confirmation of onsite availability.

Similar jobs