IT Security Analyst 2
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The State of Michigan is seeking an IT Security Analyst 2 to support the Michigan Department of Transportation (MDOT). The selected candidate will be responsible for developing, maintaining, and validating System Security Plans (SSPs), supporting Authority to Operate (ATO) activities, conducting risk assessments, and ensuring compliance with NIST security standards. This role requires close collaboration with project teams, business stakeholders, and cybersecurity teams to strengthen the security posture of enterprise applications., * Create and maintain System Security Plans (SSPs) for new and existing applications.
- Support Authority to Operate (ATO) processes and security compliance activities.
- Collaborate with system owners, project teams, and security stakeholders to implement security controls.
- Conduct security risk assessments and recommend remediation plans.
- Validate compliance with NIST security controls and state security standards.
- Coordinate security testing, vulnerability scanning, and remediation efforts.
- Monitor Plans of Action & Milestones (POA&M) and corrective action plans.
- Lead system data classification activities as part of SSP/ATO processes.
- Prepare security documentation and provide recommendations to improve security posture.
- Work with vendors and technical teams to collect security artifacts required for assessments.
Requirements
- 1-3 years of experience in Information Security, Cybersecurity, or a related field.
- Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC), and security assessment processes.
- Strong written and verbal communication skills.
- Excellent customer service and stakeholder collaboration abilities.
- Bachelor’’s degree in Information Technology, Cybersecurity, Computer Science, or related field OR a valid Cybersecurity certification., * Experience with Keylight GRC.
- Experience supporting SSP, ATO, and compliance initiatives.
- Familiarity with vulnerability management and security testing.
- Experience working in government or public sector environments.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Walking Into The Era of Supply Chain Risks
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.