Security Business Analyst

CompQsoft Inc

New York (NY)

Hybrid

USD 110,000 - 150,000

Full time

30 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

CompQsoft Inc., based in New York, seeks an experienced Security Business Analyst to translate CISO priorities into clear requirements and drive risk-informed decisions. You will work with stakeholders across Security Operations, Infrastructure, Cloud, and GRC to document controls and support remediation efforts.

The role emphasizes bridging business and technical teams, developing BRDs and workflow artifacts, and contributing to dashboards and executive risk summaries.

Qualifications

  • 5+ years of experience as a Security Business Analyst or similar.
  • Experience translating regulatory and security priorities into actionable requirements.
  • Strong knowledge of NIST RMF, FISMA, HIPAA, FERPA, and related controls.
  • Proficient with BRDs, process flows, gap analyses, and control mapping.
  • Experience with risk and POA&M management, dashboards, executive reporting.

Responsibilities

  • Serve as a Security Business Analyst supporting cybersecurity and IT risk initiatives, translating priorities into requirements.
  • Elicit, analyze, and document security and risk requirements across security operations, infrastructure, cloud, data protection, GRC, privacy.
  • Support risk and POA&M management activities, tracking remediation plans and ensuring regulatory alignment.
  • Act as a liaison between business stakeholders, technical teams, and senior leadership on risks and controls.
  • Develop and maintain BRDs, process flows, gap analyses, and control mappings.
  • Provide analytic support for executive reporting, dashboards, risk trends, and remediation progress.
  • Enable delivery of measurable security outcomes, identifying gaps and ensuring solutions meet objectives.
  • Expertise in gathering, modeling and workflow development.

Skills

JIRA
Confluence
MS Visio
Lucidchart
MS Project
SQL Query
MS Power BI
Archer/ServiceNow (GRC)
MS Office

Tools

JIRA
Confluence
MS Visio
Lucidchart
MS Project
SQL Query
MS Power BI
Archer/ServiceNow (GRC)
MS Office

Job description

Responsible for gathering and documenting requirements, analyzing business and security needs, creating workflows/SOPs, and

supporting risk assessment documentation. Working closely with the Project Manager, this role independently engages stakeholders to define, validate, and document business rules and functional requirements that meet DOE security objectives.

Requirements
Key Requirements
  • Serve as a Security Business Analyst supporting enterprise cybersecurity and IT risk initiatives, translating CISO priorities,

    regulatory requirements, and business needs into clear, actionable requirements.

  • Elicit, analyze, and document security and risk requirements, including functional, technical, and compliance needs across

    Security Operations, Infrastructure, Cloud, Data Protection, GRC, Privacy, and business units.

  • Support risk and POA&M management activities, assisting in tracking remediation plans for internal systems and third-party

    vendors, validating milestones, and ensuring alignment with regulatory and policy requirements.

  • Act as a liaison between business stakeholders, technical teams, and senior leadership, ensuring shared understanding of risks,

    controls, dependencies, and implementation impacts.

  • Develop and maintain security-related documentation and artifacts, including business requirements documents (BRDs),

    process flows, gap analyses, and control mapping aligned to frameworks such as NIST and FISMA.

  • Provide analytical support for executive reporting, contributing to dashboards, metrics, and decision-ready summaries that

    communicate security posture, risk trends, and remediation progress.

  • Risk & Compliance Knowledge: Deep understanding of frameworks like NIST SP 800-53/37 (RMF), NYC Education Law 2-d, CIPA,

    FERPA, and HIPAA.

  • Enable delivery of measurable security outcomes, supporting project and program teams by identifying gaps, clarifying

    requirements, and helping ensure solutions meet defined risk, compliance, and business objectives.

Expertise requirements for gathering, process modeling, and workflow development to bridge technical-to-business gaps.

Experience: 5+ years

Certifications: CBAP, PMI-PBA, PMP, CAPM, ITIL-F, CRISC, CompTIA Project +or CGRC

Technologies: JIRA, Confluence, MS Visio, Lucid chart, MS Project, SQL Query, MS Power BI, Archer/ServiceNow (GRC), and MS

Office Suite.

CompQsoft provides equal opportunity in all aspects of employment and in the working environment to all employees and applicants. CompQsoft does not take any non-merit factors like race, color, religion, sex (gender), mental/physical disability, and age into account for purposes of recruitment, hiring and development.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Project Manager
Project Manager

CompQsoft Inc • New York (NY)

Hybrid
USD 140,000 - 180,000
Cyber Risk Management Analyst
Cyber Risk Management Analyst

CompQsoft Inc • New York (NY)

Hybrid
USD 120,000 - 160,000
Security & Risk Analyst: Enterprise Cybersecurity
Security & Risk Analyst: Enterprise Cybersecurity

CompQsoft Inc • New York (NY)

Hybrid
USD 110,000 - 150,000
Lead Project Manager (Cybersecurity)
Lead Project Manager (Cybersecurity)

CompQsoft Inc • New York (NY)

Hybrid
USD 120,000 - 190,000
Cybersecurity Assessor
Cybersecurity Assessor

CompQsoft Inc • New York (NY)

Hybrid
USD 120,000 - 160,000
Cybersecurity Analyst
Cybersecurity Analyst

CompQsoft Inc • New York (NY)

Hybrid
USD 130,000 - 180,000
Security Compliance Analyst
Security Compliance Analyst

Managed IT & Security Provider • Alexandria (VA)

On-site
USD 75,000 - 100,000
401(k)
401(k) matching
Bonus based on performance
+3
Security Risk Analyst
Security Risk Analyst

Audax Group • Boston (MA)

On-site
USD 90,000 - 130,000
Data Privacy and Compliance Analyst
Data Privacy and Compliance Analyst

Comtech LLC • Atlanta (GA)

On-site
USD 80,000 - 100,000
Senior Information Security Analyst
Senior Information Security Analyst

Marotta Controls • Parsippany-Troy Hills (NJ)

On-site
USD 120,000 - 160,000