> Markdown version of [/jobs/ext/2572584-it-security-analyst-2](https://www.wearedevelopers.com/jobs/ext/2572584-it-security-analyst-2). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Analyst 2 - **Company:** Syntricate Technologies Inc - **Location:** Lansing, MI, United States - **Experience:** Starter - **Contract:** Temporary contract - **Skills:** Cyber Security, Software Vulnerability Management, Enterprise Software Applications, Data Classification, Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 5, 2026 - **Apply:** https://www.dice.com/job-detail/086ada1d-bb69-434e-82a5-1d041f80a2d2 ## About the Role * 1-3 years of experience in Information Security, Cybersecurity, or a related field. * Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC), and security assessment processes. * Strong written and verbal communication skills. * Excellent customer service and stakeholder collaboration abilities. * Bachelor''s degree in Information Technology, Cybersecurity, Computer Science, or related field OR a valid Cybersecurity certification., * Experience with Keylight GRC. * Experience supporting SSP, ATO, and compliance initiatives. * Familiarity with vulnerability management and security testing. * Experience working in government or public sector environments. ## Description The State of Michigan is seeking an IT Security Analyst 2 to support the Michigan Department of Transportation (MDOT). The selected candidate will be responsible for developing, maintaining, and validating System Security Plans (SSPs), supporting Authority to Operate (ATO) activities, conducting risk assessments, and ensuring compliance with NIST security standards. This role requires close collaboration with project teams, business stakeholders, and cybersecurity teams to strengthen the security posture of enterprise applications., * Create and maintain System Security Plans (SSPs) for new and existing applications. * Support Authority to Operate (ATO) processes and security compliance activities. * Collaborate with system owners, project teams, and security stakeholders to implement security controls. * Conduct security risk assessments and recommend remediation plans. * Validate compliance with NIST security controls and state security standards. * Coordinate security testing, vulnerability scanning, and remediation efforts. * Monitor Plans of Action & Milestones (POA&M) and corrective action plans. * Lead system data classification activities as part of SSP/ATO processes. * Prepare security documentation and provide recommendations to improve security posture. * Work with vendors and technical teams to collect security artifacts required for assessments. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)