# Senior IT Security Compliance Analyst

> Stafford Gray · Lansing, United States (Hybrid) · Contract · Posted 2026-10-01

**Salary:** Up to USD 110,000

**Workplace:** hybrid

## Description

We're looking for a Senior IT Security Compliance Analyst to lead security planning and authorization work for a portfolio of public-sector applications. You'll be the compliance authority for several business areas: keeping System Security Plans current, guiding systems through Authority to Operate (ATO) renewals, and making sure security controls, documentation and processes line up with NIST standards.

This is a senior, hands-on role. You'll work across business owners, technical teams, enterprise security, vendors, auditors and project managers, and you'll mentor other analysts on the team.

**What you'll do**

-   Lead the maintenance and updating of System Security Plans (SSPs), making sure they're accurate, complete and aligned with NIST controls.
-   Plan and run the ATO renewal process on a three-year cycle, from preparing materials and managing timelines through approval and continuous compliance.
-   Validate and maintain security controls throughout each authorization period, and oversee remediation of control gaps.
-   Track Plans of Action & Milestones (POA&Ms) and other compliance requirements with stakeholders through to closure.
-   Review risk assessment results, brief management, and recommend corrective actions.
-   Assess the risk and scope of high-level security incidents, lead mid- to high-level incident response, and support detection, response and recovery.
-   Develop metrics-based reports and trend analysis for management across multiple business areas.
-   Create and maintain Disaster Recovery Plans, and contribute to business continuity and incident response planning.
-   Find gaps in existing compliance documentation and drive consistent practices across all supported systems.
-   Coordinate with technical teams, business owners and security staff so that all evidence and artifacts for SSP and ATO work are complete and current.

## Requirements

Required Qualifications:

-   5+ years providing audit evidence to comply with security standards such as NIST, PCI, HIPAA or FERPA.
-   5+ years of exposure to complex IT web applications.
-   5+ years leading meetings and delivering oral and written reports.
-   5+ years working as a liaison between business and IT areas.
-   Strong working knowledge of the NIST framework and controls (required).
-   Strong writing and documentation skills.
-   A bachelor's degree in cybersecurity, information assurance, business analytics or an IT-related field, or 5 years of equivalent experience.

Preferred Qualifications:

-   2+ years creating documentation to support IT system audits.

-   2+ years creating Disaster Recovery, Business Continuity or Incident Response Plans.
-   A master's in cybersecurity, information assurance or IT leadership, or an MBA with an IT or security concentration.
-   Certifications such as CISSP, CGRC (formerly CAP), CISA or CISM.

## Apply

[Apply at Stafford Gray](https://apply.workable.com/staffordgray/j/A3830FDB94/apply)

---
Powered by [Workable](https://www.workable.com)
