Senior IT Security Compliance Analyst

Stafford Gray

• $95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience with NIST, PCI, HIPAA, or FERPA compliance standards.
  • 5+ years working with complex IT web applications.
  • 5+ years of experience leading meetings and delivering reports.
  • 5+ years acting as a liaison between business and IT.
  • Strong knowledge of the NIST framework and controls is essential.
  • Excellent writing and documentation skills.
  • Bachelor's degree in cybersecurity, information assurance, business analytics, or IT-related field, or 5 years of equivalent experience.

Responsibilities

  • Lead the maintenance and updating of System Security Plans (SSPs) to ensure accuracy and compliance with NIST controls.
  • Plan and execute the ATO renewal process every three years, managing timelines and approvals.
  • Validate and maintain security controls, overseeing remediation of any gaps.
  • Track compliance requirements and ensure closure of Plans of Action & Milestones (POA&Ms).
  • Review risk assessment results and recommend corrective actions to management.
  • Assess high-level security incidents and lead incident response efforts.
  • Develop metrics-based reports and trend analysis for management across business areas.
  • Create and maintain Disaster Recovery Plans and contribute to business continuity planning.

Benefits

  • Opportunity to mentor junior analysts and lead compliance initiatives.
  • Engagement with diverse stakeholders including technical teams and auditors.
  • Hands-on role with significant impact on public-sector applications.
  • Chance to work with cutting-edge security frameworks and standards.
Full Job Description
We're looking for a Senior IT Security Compliance Analyst to lead security planning and authorization work for a portfolio of public-sector applications. You'll be the compliance authority for several business areas: keeping System Security Plans current, guiding systems through Authority to Operate (ATO) renewals, and making sure security controls, documentation and processes line up with NIST standards.

This is a senior, hands-on role. You'll work across business owners, technical teams, enterprise security, vendors, auditors and project managers, and you'll mentor other analysts on the team.

What you'll do
  • Lead the maintenance and updating of System Security Plans (SSPs), making sure they're accurate, complete and aligned with NIST controls.
  • Plan and run the ATO renewal process on a three-year cycle, from preparing materials and managing timelines through approval and continuous compliance.
  • Validate and maintain security controls throughout each authorization period, and oversee remediation of control gaps.
  • Track Plans of Action & Milestones (POA&Ms) and other compliance requirements with stakeholders through to closure.
  • Review risk assessment results, brief management, and recommend corrective actions.
  • Assess the risk and scope of high-level security incidents, lead mid- to high-level incident response, and support detection, response and recovery.
  • Develop metrics-based reports and trend analysis for management across multiple business areas.
  • Create and maintain Disaster Recovery Plans, and contribute to business continuity and incident response planning.
  • Find gaps in existing compliance documentation and drive consistent practices across all supported systems.
  • Coordinate with technical teams, business owners and security staff so that all evidence and artifacts for SSP and ATO work are complete and current.

Requirements

Required Qualifications:
  • 5+ years providing audit evidence to comply with security standards such as NIST, PCI, HIPAA or FERPA.
  • 5+ years of exposure to complex IT web applications.
  • 5+ years leading meetings and delivering oral and written reports.
  • 5+ years working as a liaison between business and IT areas.
  • Strong working knowledge of the NIST framework and controls (required).
  • Strong writing and documentation skills.
  • A bachelor's degree in cybersecurity, information assurance, business analytics or an IT-related field, or 5 years of equivalent experience.

Preferred Qualifications:
  • 2+ years creating documentation to support IT system audits.
  • 2+ years creating Disaster Recovery, Business Continuity or Incident Response Plans.
  • A master's in cybersecurity, information assurance or IT leadership, or an MBA with an IT or security concentration.
  • Certifications such as CISSP, CGRC (formerly CAP), CISA or CISM.

Similar Jobs

More Jobs at Stafford Gray

More Information Technology Jobs

Find similar Senior IT Security Compliance Analyst jobs: