Departmental Specialist 13 - Data Protection and Management

State of Michigan

$132K — $198K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in any major.
  • Four years of professional experience in relevant fields.
  • Two years at the experienced level (P11) or one year at the advanced level (12).
  • Expertise in information security control standards, specifically NIST SP 800-53 and IRS Publication 1075.
  • Experience in reviewing SOC reports.

Responsibilities

  • Develop and implement security and regulatory compliance activities.
  • Conduct reviews of System and Organization Controls (SOC) reports.
  • Coordinate audits and assess application security scan results.
  • Manage Plans of Action and Milestones (POAM) in compliance timelines.
  • Develop and maintain departmental security policies and procedures.
  • Deliver training on security and compliance matters to agency staff.
  • Provide guidance on risk mitigation and regulatory obligations to leadership.

Benefits

  • Remote or hybrid work options may be considered.
  • Employees receive necessary computers and phones for work.
  • Flexible work schedule requests may be accommodated.
  • Opportunity for professional development in security compliance.
Full Job Description
Salary : $2,559.20 - $3,820.00 Biweekly
Location : Lansing, MI
Job Type: Permanent Full Time
Job Number: 3901-26-SIA-008LV-ESTABLISH
Department: Health and Human Services - Central Office
Opening Date: 07/13/2026
Closing Date: 7/27/2026 11:59 PM Eastern
Bargaining Unit: NON-EXCLUSIVE REPRESENTED EMPLOYEE (NERE)

Job Description
This position serves as the Security Specialist responsible for the development, implementation, coordination, and evaluation of security, privacy, and regulatory compliance activities required to ensure MDHHS adherence to federal and state standards, including NIST SP 800-53, IRS Publication 1075, and other applicable frameworks. Responsibilities include conducting and overseeing System and Organization Controls (SOC) report reviews; coordinating and participating in onsite security and compliance audits; evaluating application security scanning results; and managing all associated Plan of Action and Milestones (POAM) in Keylight to ensure required remediation is completed in accordance with established timelines. The position develops and maintains departmental security policies, procedures, and standards; assesses audit findings and risk evaluations; and recommends corrective actions to enhance internal controls and strengthen agency compliance posture. The incumbent also develops and delivers security, privacy, and compliance training and provides expert guidance to MDHHS leadership, program areas, and technical staff regarding security requirements, risk mitigation, and regulatory obligations.
To be considered for this position you must:
  • apply for this position online via NEOGOV; click on "Apply" in the job posting for instructions on submitting your electronic application. Hard copy applications are not accepted.
  • relevant experience and/or education referred to in supplemental questions must be documented in resume, transcript and/or application to allow for accurate screening.
  • attach a resume identifying specific experience and dates of employment. Dates of employment should include month and year and hours per week.
  • attach a cover letter.
  • if applicable, attach a copy of an official transcript(s). We accept scanned copies of official transcripts. We do not accept web-based, internet, or copies of unofficial transcripts. Official transcripts provide the name of the institution, confirmation that a degree was awarded and on what date, and the registrar's signature.
Failure to complete any of the above items may result in your application not being considered. See instructions for attaching files here:
Required Education and Experience

Education
Possession of a bachelor's degree in any major

Experience

Departmental Specialist 13
Four years of professional experience, including two years equivalent to the experienced (P11) level or one year equivalent to the advanced (12) level.
Additional Requirements and Information
The physical location of this position is 235 S. Grand Ave, Lansing, MI. Based on operational needs and within established limits, remote work and alternate or hybrid work schedule requests for this position may be considered.

Selected candidates who have been approved to work remotely or a hybrid schedule must complete that work within Michigan. Candidates should confirm work location and schedule at the time of interview.

Employees will be provided computers to perform state work. Phones may also be provided for necessary communications. If working remotely, employees will be responsible for providing other components of a remote office at their own expense, including:
  • A secure work location that allows privacy and prevents distractions.
  • A high-speed internet connection of at least 25 Mbps download and 5 Mbps upload.
  • Suitable lighting, furniture, and utilities.
The use of artificial intelligence (AI) software of any kind is prohibited in all areas of the selection process; including, but not limited to, responses to application questions, and responses to interview questions or exercises.

YOUR APPLICATION FOR ANY POSITION DOES NOT GUARANTEE YOU WILL BE CONTACTED BY THE DEPARTMENT/AGENCY FOR FURTHER CONSIDERATION. ONLY THOSE APPLICANTS INTERVIEWED WILL BE NOTIFIED OF THE RESULTS.

The department reserves the right to close this posting prior to its original end date once a sufficient number of applications have been received.

If you previously held status in this classification and departed within the last three (3) years, please contact Human Resources regarding your interest in a potential reinstatement. Reinstatement is not guaranteed or required.

For information about this specific position, please email . Please reference the job posting number in subject line.



Updated: 2/28/24
01

DEPSPL - Do you possess one of the following?A bachelor's degree or higher in any major. If so, please attach a copy of your official college transcripts.OR At least one year of professional experience in the state classified service.
  • Yes
  • No

02

DEPSPL - Do you possess at least four years of professional experience?
  • Yes
  • No

03

Do you possess an advanced level of knowledge and experience working in or with information security control standards? If you possess this knowledge and experience, you must document this in your application to allow for accurate screening.
  • Yes
  • No

04

Do you have experience reviewing SOC 1 and/or SOC 2 reports? If you possess this knowledge and experience, you must document this in your application to allow for accurate screening.
  • Yes
  • No

05

Describe a time when you independently conducted a security or compliance review (such as SOC reports, onsite audits, or control evaluations). Explain the scope, your analysis process, key findings, and the corrective actions or recommendations you provided. How did your work strengthen compliance or reduce risk? If you do not possess this experience, write "N/A". If your response does not fit in the box below, please write "see attachment" in the box and attach your response as a separate document to your application.
06

How many years of experience do you have conducting audits, compliance reviews, or security assessments?
  • 5 years or more
  • 3-4 years
  • 1-2 years
  • Less than 1 year
  • None

07

Explain your experience evaluating or approving collaboration platforms or software applications (e.g., Microsoft Teams, SharePoint, enterprise systems). Describe how you assessed data handling, security controls, interoperability risks, and compliance requirements, and explain how you communicated your decisions to stakeholders.
08

How many years of experience do you have with NIST frameworks (e.g., SP 800 53) or IRS Pub 1075 compliance?
  • 5 years or more
  • 3-4 years
  • 1-2 years
  • Less than 1 year
  • None

09

How many years of experience do you have reviewing or evaluating software or technology solutions for security/privacy risk?
  • 5 years or more
  • 3-4 years
  • 1-2 years
  • Less than 1 year
  • None

10

Describe a time when you needed to work cooperatively with someone that did not share the same ideas as you.
11

From the options below, which accurately describes your current status? (A current state employee works for an actual state department such as the Department of Corrections, the Department of Transportation, etc.)
  • A current Michigan Department of Health and Human Services (MDHHS) employee
  • A Michigan Department of Health and Human Services (MDHHS) employee in layoff status
  • A current State of Michigan (non-MDHHS) employee
  • A State of Michigan (non-MDHHS) employee in layoff status
  • None of the above

12

Do you have any substantiated cases of abuse or neglect reported on the Michig

Similar Jobs

More Jobs at State of Michigan

More Information Technology Jobs

Find similar Departmental Specialist 13 - Data Protection and Management jobs: