> Markdown version of [/jobs/ext/2751014-it-security-compliance-analyst](https://www.wearedevelopers.com/jobs/ext/2751014-it-security-compliance-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security & Compliance Analyst - **Company:** The Stafford - **Location:** Lansing, MI, United States - **Experience:** Expert - **Salary:** $50,586.0 - $92,830.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Microsoft Excel, Agile Methodology, User Authentication, Microsoft Azure, Cyber Security, Information Systems, Cross-Site Request Forgery, Disaster Recovery, Information Security Management, Real-Time Operating Systems, Power BI, Software Requirements Analysis, SQL Injection, SQL Databases, Systems Integration, Software Vulnerability Management, Web Applications, Cross-Site Scripting (XSS), RSA Archer Platform, Tools for Reporting - **Published:** September 6, 2026 - **Apply:** https://www.careerjet.com/jobad/us8bfcb8710c9595ae09dc13ab3390cdcb ## About the Role * 7 years of professional experience in security, compliance, risk management, or a closely related discipline within a government agency, public retirement system, or regulated financial environment * Demonstrated experience developing, documenting, and evaluating security controls, compliance requirements, and governance processes * Experience supporting security/compliance assessments, audit activities, policy reviews, and control validations * Working knowledge of security/compliance frameworks relevant to public sector environments (e.g., NIST CSF, NIST 800-53) * Experience participating in system or process changes with a focus on data protection, access controls, and secure implementation * Knowledge of Agile SDLC with an emphasis on integrating security/compliance into requirements, testing, and release * Ability to assess common vulnerabilities (XSS, CSRF, SQL Injection, authentication weaknesses) * Proficiency with tools supporting security documentation, compliance tracking, and workflow management (e.g., Azure DevOps, GRC platforms) * Experience contributing to Disaster Recovery Plan development, documentation, and testing, including RTOs/RPOs Preferred Qualifications: * Bachelor's degree in information security, cybersecurity, information systems, public administration, or related field (or equivalent experience) * Experience supporting security/compliance needs within public pension or retirement administration programs * Familiarity with security capabilities and data protection requirements within pension administration or enterprise benefits platforms * Experience with SQL or analytics tools (Power BI, advanced Excel) for compliance monitoring and reporting * Security/compliance certifications (CGRC, CAP, Security+, CISA, or similar) * Knowledge of federal/state regulations governing data security and privacy in public sector retirement systems (IRS, SSA, audit standards) * Familiarity with Java or .NET * High-level understanding of web application functioning Stafford Gray ## Description We're looking for a Security & Compliance Analyst to support the security, compliance, and operational integrity of systems used in administering retirement benefits for public sector employees. This role partners with cross-departmental teams to strengthen security controls, improve business processes, and ensure secure, reliable service delivery. The ideal candidate brings hands-on experience with security/compliance frameworks in government, public retirement, or regulated financial environments, and is comfortable owning audit-ready documentation, risk assessments, and vulnerability management activities from end to end., * Analyze, document, and validate security processes and system requirements supporting retirement benefits administration * Define and refine security and compliance requirements for system enhancements and new initiatives alongside program offices and technical teams * Create and maintain audit-ready documentation - security requirements, user stories, workflows, use cases * Support solution design and UAT to verify security controls are properly implemented * Monitor deliverables and timelines against security and compliance objectives * Conduct gap analyses on legislative/regulatory/policy changes and their operational impact * Perform data analysis and reporting to support compliance monitoring and risk tracking * Support security/standards reviews, risk assessments, and mitigation planning * Contribute to System Security Plans, Assessment Reports, and Authorization packages * Support Disaster Recovery and Business Continuity Planning, including business impact assessments and tabletop exercises * Coordinate vulnerability scans and support mitigation planning * Provide informal leadership and mentorship to fellow analysts on security frameworks and governance processes, Security & Compliance System Analyst Location: Lansing, MI Duration: 12 months (Hybrid) Seeking for a Security & Compliance Analyst supports the integrity, security, and comp… + 18 hours ago, Job Summary: The System Analyst 6 role involves supporting security, compliance, risk management, and business continuity initiatives within public sector systems. The analyst wi… + 18 hours ago + Apply easily + ## Related Videos - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Dangerous Reactivity: Why AI Output Is the New XSS](https://www.wearedevelopers.com/videos/100115-dangerous-reactivity-why-ai-output-is-the-new-xss) - [ChatGPT, ignore the above instructions! Prompt injection attacks and how to avoid them.](https://www.wearedevelopers.com/videos/723-chatgpt-ignore-the-above-instructions-prompt-injection-attacks-and-how-to-avoid-them) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)