IT Security Analyst 2

Stellar Professionals
Lansing, MI, United States
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Software Applications Cyber Security Data Classification Information Technology Vulnerability Analysis

Job description

As a Compliance Analyst, you will build and maintain System Security Plans (SSPs) using Governance, Risk, and Compliance (GRC) tools. You’ll work closely with IT project teams and security leaders to identify vulnerabilities, validate NIST controls, and lead applications through the Authority to Operate (ATO) process., * System Security Plans (SSP): Draft, update, and maintain SSPs for critical IT applications.

  • Risk & Compliance: Conduct risk assessments, track remediation plans, and align systems with NIST security controls.
  • Security Testing & Scans: Lead vulnerability scanning, data classification, and mitigation tracking.
  • Collaboration: Coordinate security requirements with cross-functional technical teams and vendors.

Requirements

  • Experience: 1 3 years in IT Security, Compliance, or a related cybersecurity role.
  • Core Standards: Strong working knowledge of NIST, SSP, and GRC concepts.
  • Education / Certification (Must meet ONE):
  • Bachelor’s/Associate’s degree in IT/Computer Science, OR
  • Active Cybersecurity Certification (e.g., Security+, CISSP, CISA, etc.), OR
  • Equivalent technical work experience.
  • Communication: Clear verbal and written skills to translate complex security concepts to stakeholders.

Bonus Skills

  • Hands-on experience with Keylight (GRC tool).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

6:33 min

Integrating generative workflows for data classification and extraction

Christian Liebel Christian Liebel · WWC 2025

3:57 min

Defining the modern application software supply chain

Niels Tanis Niels Tanis · WWC 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all