Security Analyst

I O DATASPHERE
Lansing, MI, United States
about 1 month ago
Apply on iodatasphere.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
1 year minimum
Working hours
Regular working hours

Tech stack

Audit Trail Cyber Security Computer Programming Databases Data Transmissions Enterprise Information Management Systems Analysis Software Engineering Data Processing Software Security Information Technology

Job description

Our client is looking for a Security Analyst to be responsible for completing and maintaining system security plans (SSP) for new and existing systems. The system security plans are documented in the Governance, Risk, Compliance tool. This requires close coordination with IT project teams, tech leads, business and enterprise security representatives, and product owners, to establish and maintain processes and security controls for systems, and to identify security vulnerabilities and coordinate remediation plans. Compliance Analysts are assigned resources for development projects.

Tasks

  • Create SSPs via collaboration with Automation Managers, System Owners, System Security Administrators, and project team for new applications in alignment with the Secure Application Development Life Cycle and Michigan Security Accreditation Process.
  • Maintain SSPs for existing applications requiring ATO and those facing software and/or hardware enhancements.
  • Collaborate with business representatives to establish system registration.
  • Lead and identify security testing and system scanning requirements.
  • Perform risk assessments and provide responses for security controls.
  • Continuously monitor plans of action and milestones and corrective action plans as they relate to the SSPs in collaboration with the Enterprise Information Management office.
  • Validate respective SSPs to ensure NIST control requirements are met.
  • Author recommendations associated with findings on how to improve the customer’s security posture in accordance with the Agency’s Policies, Standards, and Procedures, and NIST (National Institute of Standards and Technology) controls.
  • Lead team members and vendors with proper artifact collection to satisfy assessment requirements.
  • Coordination of scanning activities/enterprise activities with tech leads, and business areas.
  • Lead the system Data Classifications part of the SSP/ATO process.

Requirements

  • Strong communication
  • Customer service skills, * 1-3 years - Experience in the field or in a related area.
  • Has knowledge of commonly used concepts, practices, and procedures within the field (NIST, SSP, GRC, etc.)
  • Experience reviewing and implementing internal controls and standards.
  • Experience using a Governance, Risk, and Compliance tool (or a comparable Audit, Risk, and Compliance tool).
  • Experience auditing processes and procedures to ensure they are being followed appropriately.
  • Experience gathering and documenting information for audits to include evidence of approvals and development/testing completion; evidence of server information; evidence of department or vendor process documents; and evidence of database audit logs.
  • Experience with process improvement, process development, or developing a new team.
  • Cyber Security certification or Associate’s Degree or Bachelor’s degree in a related field (computer science, data processing, computer information systems, data communications, networking, systems analysis, computer programming, or mathematics.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on iodatasphere.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

Videos

See all

Related articles

See all