I

Security Analyst (System Security Plans & Compliance)

IO Datasphere, Inc. • France
Visa Sponsorship
Apply
AI Summary

The Security Analyst will develop, maintain, and validate System Security Plans (SSPs) for new and existing systems, ensuring compliance with NIST and Michigan Security Accreditation standards. This role involves collaborating with IT teams, business stakeholders, and vendors to establish security controls, conduct risk assessments, and lead remediation efforts. Requires 1-3 years of experience in security planning, governance, and compliance tools.

Key Highlights
Develop and maintain System Security Plans (SSPs) for new and existing systems in alignment with NIST and Michigan Security Accreditation Process
Collaborate with IT project teams, business stakeholders, and vendors to establish security controls and remediation plans
Perform risk assessments, validate SSPs, and provide recommendations to improve security posture
Key Responsibilities
Create and maintain System Security Plans (SSPs) for new applications in collaboration with project teams, aligning with Secure Application Development Life Cycle and Michigan Security Accreditation Process
Update SSPs for existing applications requiring Authorization to Operate (ATO) and those undergoing software/hardware enhancements
Conduct risk assessments, validate SSPs against NIST control requirements, and provide recommendations to improve security posture
Lead security testing, system scanning, and data classification efforts as part of the SSP/ATO process
Coordinate scanning activities and artifact collection with tech leads, business areas, and vendors to meet assessment requirements
Technical Skills Required
NIST (National Institute of Standards and Technology) Governance, Risk, and Compliance (GRC) tools System Security Planning (SSP)
Benefits & Perks
Hybrid work schedule (onsite 2 days/week: Tuesdays & Wednesdays)
Visa sponsorship for H1B, H4, TN, and other valid work visas (excluding OPT/CPT)
Nice to Have
Experience with Keylight
Associate's or Bachelor's degree in computer science, data processing, or related fields
Cyber Security certification

Job Description


Job No: 10519MI

Position Security Analyst Client Name Michigan Department of Transportation (MDOT) Requisition 164083 Location Lansing, MI Duration 1 year Due Date 08/10/2026 C2C Possible Yes. Rate depends on experience Interview Method Two rounds of interviews. First will be Webcam. 2nd interview will be Onsite

NOTE: Local candidates ONLY. Candidate must be located within 100 miles of Lansing, MI at time of submission. Relocation not allowed. Resource will be working a hybrid schedule. NO REMOTE ONLY OPTION. Will need to be onsite from day 1, two days a week. Tuesdays and Wednesdays are required onsite days. A standard cover letter that summarizes your qualifications and experience as they relate to the position requirements is required. We can accept H1b, H4, TN and other valid work visas for IT. However we cannot accept OPT or CPT visas at this time.

Description

Our client is looking for a Security Analyst to be responsible for completing and maintaining system security plans (SSP) for new and existing systems. The system security plans are documented in the Governance, Risk, Compliance tool. This requires close coordination with IT project teams, tech leads, business and enterprise security representatives, and product owners, to establish and maintain processes and security controls for systems, and to identify security vulnerabilities and coordinate remediation plans. Compliance Analysts are assigned resources for development projects.

Tasks

  • Create SSPs via collaboration with Automation Managers, System Owners, System Security Administrators, and project team for new applications in alignment with the Secure Application Development Life Cycle and Michigan Security Accreditation Process.
  • Maintain SSPs for existing applications requiring ATO and those facing software and/or hardware enhancements.
  • Collaborate with business representatives to establish system registration.
  • Lead and identify security testing and system scanning requirements.
  • Perform risk assessments and provide responses for security controls.
  • Continuously monitor plans of action and milestones and corrective action plans as they relate to the SSPs in collaboration with the Enterprise Information Management office.
  • Validate respective SSPs to ensure NIST control requirements are met.
  • Author recommendations associated with findings on how to improve the customer's security posture in accordance with the Agency's Policies, Standards, and Procedures, and NIST (National Institute of Standards and Technology) controls.
  • Lead team members and vendors with proper artifact collection to satisfy assessment requirements.
  • Coordination of scanning activities/enterprise activities with tech leads, and business areas.
  • Lead the system Data Classifications part of the SSP/ATO process.

Knowledge, Skills And Abilities Required

  • Strong communication
  • Customer service skills

Skills Required

  • 1-3 years - Experience in the field or in a related area.
  • Has knowledge of commonly used concepts, practices, and procedures within the field (NIST, SSP, GRC, etc.)
  • Experience reviewing and implementing internal controls and standards.
  • Experience using a Governance, Risk, and Compliance tool (or a comparable Audit, Risk, and Compliance tool).
  • Experience auditing processes and procedures to ensure they are being followed appropriately.
  • Experience gathering and documenting information for audits to include evidence of approvals and development/testing completion; evidence of server information; evidence of department or vendor process documents; and evidence of database audit logs.
  • Experience with process improvement, process development, or developing a new team.
  • Cyber Security certification or Associate's Degree or Bachelor's degree in a related field (computer science, data processing, computer information systems, data communications, networking, systems analysis, computer programming, or mathematics.

Skills Desired

  • Experience with Keylight

Similar Jobs

Explore other opportunities that match your interests

Senior Security Engineer - Product Security & Certifications

Cyber Security
•
5d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Arm

France

Capabilities Researcher - Claude Security

Cyber Security
•
29m ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

anthropic

United State

Software Engineer - Claude Security

Cyber Security
•
33m ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

anthropic

United State

Subscribe our newsletter

New Things Will Always Update Regularly