Security Analyst - MiLEAP, MCSC

Zohorecruit

Lansing (MI)

Hybrid

USD 100,000 - 135,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

AtZenfreed is seeking a Senior IT Business/Compliance Analyst to provide senior-level oversight for SSPs and DRPs across MDCR, MCSC and MiLEAP, ensuring alignment with NIST and SOM standards. The role liaises between business partners, security groups, and management, guiding compliance cycles and governance.

The candidate will coordinate with vendors, auditors, project managers, and analysts to maintain evidence for SSP and ATO processes and to drive timely remediation of gaps.

Qualifications

  • Bachelor’s degree in cyber security, Information Assurance, Business Analytics, or IT Related Field or 5 years experience
  • Educational or professional knowledge of NIST Framework and Controls a must
  • Strong aptitude for written and oral communication
  • Can collaborate cross-functionally

Responsibilities

  • Maintain and update System Security Plans (SSPs) and Disaster Recovery Plans (DRPs) to align with NIST protocol and SOM compliance standards.
  • Lead and coordinate the Authority to Operate (ATO) renewal process, including planning, preparing required materials, managing timelines, and ensuring successful approval and continuous compliance for all supported applications.
  • Ensure all applications maintain a valid ATO on a three-year cycle and lead efforts to validate and maintain accurate security controls throughout each renewal period.
  • Perform as the incident response specialist for cyber event detection, correlation, response, and recovery.
  • Oversee review, updates, and remediation of security controls, ensuring issues are tracked, communicated, and resolved in collaboration with stakeholders.

Job description

Lansing, United States | Posted on 10/02/2026

  • Minimum Education Requirement Bachelor's Degree
  • City Lansing
  • Country United States
Job Description

This Senior IT Business/Compliance Analyst position serves as a senior resource within the Department of Technology, Management and Budget (DTMB) Agency Services for Michigan Department of Civil Rights (MDCR), Michigan Civil Service Commission (MCSC) and Michigan Department of Lifelong Education, Advancement and Potential (MILEAP). The role provides high-level oversight, guidance, and strategic direction for completing, updating, and maintaining System Security Plans (SSPs) and Disaster Recovery Plans (DRPs) for the MCSC and MiLEAP applications.

The primary duty of this position is performing as the compliance authority and liaison among business partners, technical teams, security groups, and management. The Senior Analyst ensures that requirements, processes, and documentation align with State of Michigan standards, NIST protocols, and enterprise security governance. This role guides stakeholders through complex compliance cycles, drives consistency across application areas. They will also work and collaborate with people outside of the DTMB Agency Services Compliance Team such as vendors, auditors, project managers, and analysts

Job Duties
  • Provide leadership and oversight for maintaining and updating System Security Plans (SSPs), ensuring documentation accuracy, completeness, and alignment with NIST protocol and SOM compliance standards.
  • Lead and coordinate the Authority to Operate (ATO) renewal process, including planning, preparing required materials, managing timelines, and ensuring successful approval and continuous compliance for all supported applications.
  • Ensure all applications maintain a valid ATO on a three-year cycle and lead efforts to validate and maintain accurate security controls throughout each renewal period.
  • Reviews and informs management on security risk assessment results and recommends corrective actions as necessary.
  • Reviews, assesses risks and scope for high level security incidents.
  • Develops new reports for management based on those collected metrics across multiple agencies: conducts trend analysis.
  • Work with stakeholders to address and track Plans of Action & Milestones (POA&Ms) and other compliance requirements, ensuring timely reporting and closure.
  • Provide senior-level support across multiple business areas, MDCR, MCSC & MiLEAP, with a focus on standardized security plan updates, documentation improvements, and long-term process consistency.
  • Analyze existing compliance documentation, identify gaps or risks, and guide corrective actions to meet regulatory and organizational requirements.
  • Coordinate cross-functional collaboration with technical teams, business owners, enterprise security personnel, and project leadership to ensure all evidence and artifacts required for SSP and ATO processes are properly completed and maintained.
  • Oversee review, updates, and remediation of security controls, ensuring issues are tracked, communicated, and resolved in collaboration with stakeholders.
  • Lead efforts to identify procedural gaps, risks, or required updates during renewal cycles, ensuring consistent application of best practices across all supported systems.
  • Contribute to enterprise security governance by providing guidance, maintaining accurate records, mentoring team members, and driving timely completion of compliance activities.
  • Leads mid to high-level Incident Responses when working to resolve incidents.
  • Serves as the Incident response specialist for cyber event detection, correlation, response, and recovery
Requirements

5 years:

  • Experience providing audit evidence to comply with security standards such as NIST, PCI, HIPPA, FERPA Required
  • Exposure to Complex IT web Applications, within the past 5 years
  • Experience leading meetings and making oral and written reports
  • Experience working as a liaison between different business and IT areas
Bachelor’s degree in cyber security, Information Assurance, Business Analytics, or IT Related Field or 5 years experience

Preferred Advanced Degrees, Master’s in Cybersecurity, Information Assurance, Information Systems / IT Leadership, or an MBA with an IT or Security Concentration

Educational or professional knowledge of NIST Framework and Controls a must

Strong aptitude for written and oral communication

Can collaborate cross-functionally

Desired Skills

2 years:

  • Knowledge or experience creating supporting documentation for IT system audits
  • Experience with the creation of Disaster Recover Plans, Business Continuity Plans, and Incident Response Plans
  • Bachelor's Degree
Location
  • Local candidates ONLY. Candidates must be located within 90 miles of Lansing, MI at time of submission.
  • Positionis a hybrid schedule withNO REMOTE ONLY OPTION. Will need to be onsite from day 1, two days a week.
  • Working hoursMonday-Friday, approximately 8:00 a.m. to5:00 p.m.
AdditionalRequirements
  • Must be authorized towork in the United States; We are unable to offersponsorships at this time
  • Must undergo a background checkand drug screening for employment.
EmploymentTerms
  • This is a W2 position
  • HYBRID schedule -NO REMOTE ONLY OPTION. Will need to be onsite from day 1, two days a week.
AtZenfreed, we are more than an IT company. We bridge thegap between people wanting to do the work they were meant to doand organizations needing the right talent.

We are dedicated to building a diverse,inclusive and authentic workplace, so if you’re excitedabout this role but your past experience doesn’t alignperfectly with every qualification in the job description, You may be just the rightcandidate for this or other roles.

We understand a comprehensive benefits package is crucial toemployment satisfaction. We offer medical, dental and vision coverageoptions for all employees.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Analyst - MiLEAP, MCSC
Security Analyst - MiLEAP, MCSC

Zohorecruit • Town of Lansing (NY)

Hybrid
USD 90,000 - 130,000
Medical, dental, and vision coverage
System Analyst
System Analyst

Zohorecruit • Lansing (MI)

Hybrid
USD 90,000 - 120,000
Medical, dental and vision coverage
Hybrid schedule — onsite two days a wk
IT Security Analyst
IT Security Analyst

Cybersecurity Jobs • Lansing (MI)

On-site
USD 70,000 - 90,000
Long-Term Stability
Comprehensive Health Coverage
401(k)
+1
IT Security Analyst, Lansing, MI, US
IT Security Analyst, Lansing, MI, US

Intellibee • Town of Lansing (NY)

On-site
USD 100,000 - 150,000
Long-Term Stability
Comprehensive Health Coverage
Future Planning
+1
IT Security Analyst #1065395
IT Security Analyst #1065395

Fasttek • Lansing (MI)

On-site
USD 90,000 - 140,000
Medical and Dental (FastTek pays)
Vision
PTO
+3
NIST PCI HIPPA Web Applications Oral And Written Communication Cyber Security Analyst
NIST PCI HIPPA Web Applications Oral And Written Communication Cyber Security Analyst

COOLSOFT • Lansing (MI)

Hybrid
USD 83,000 - 131,000
Senior IT Security Compliance Analyst - DTMB
Senior IT Security Compliance Analyst - DTMB

IO Datasphere, Inc. • Lansing (MI)

Hybrid
USD 90,000 - 130,000
Senior IT Security Compliance Analyst
Senior IT Security Compliance Analyst

IO Datasphere, Inc. • Lansing (MI)

Hybrid
USD 90,000 - 130,000
Security Analyst
Security Analyst

Brooksource • Lansing (MI)

On-site
USD 62,000 - 69,000
Health insurance
401k plan
Paid time off
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Warehouse-Specialists,-LLC-2 • Appleton (WI)

On-site
USD 120,000 - 165,000
Medical, Dental, Vision
401(k) Plan
Paid Time Off