Senior IT Security Compliance Analyst

MasterApp Labs LLC

Lansing (MI)

On-site

USD 83,000 - 124,000

Part time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Flexible work options

Job summary

MasterApp Labs LLC is seeking a Sr. IT Security Compliance Analyst in Lansing, MI. The role is hybrid with onsite presence two days weekly, and starts from day one. Contract position with MS Teams and in-person interview rounds.

You will lead SSP updates, ATO renewals, and risk reviews across multiple applications, ensuring continuous compliance and proper documentation. Collaboration with MDCR, MCSC, and MiLEAP is required.

Qualifications

  • Experience providing audit evidence to comply with security standards such as NIST, PCI, HIPAA, FERPA.
  • Exposure to complex IT web applications in the past 5 years.
  • Experience leading meetings and producing oral and written reports.
  • Experience acting as a liaison between business and IT areas.
  • Knowledge or experience creating supporting documentation for IT system audits.
  • Experience creating Disaster Recovery, Business Continuity, and Incident Response Plans.

Responsibilities

  • Provide leadership and oversight for maintaining and updating System Security Plans (SSPs).
  • Lead and coordinate the Authority to Operate (ATO) renewal process across applications.
  • Ensure ATO validity on a three-year cycle and maintain security controls during renewals.
  • Review risk assessment results and recommend corrective actions.
  • Develop new reports and perform trend analysis across agencies.
  • Track Plans of Action & Milestones (POA&Ms) and ensure timely closure.
  • Provide senior level support across multiple business areas (MDCR, MCSC, MiLEAP).
  • Identify gaps or risks in compliance documentation and guide corrective actions.
  • Coordinate cross-functional collaboration to ensure SSP/ATO evidence is complete.
  • Oversee remediation of security controls and ensure issues are resolved.
  • Identify procedural gaps during renewal cycles and promote best practices.
  • Contribute to enterprise security governance and mentoring.
  • Lead mid to high-level Incident Responses and cyber event handling.

Skills

NIST/PCI/HIPAA/FERPA audit evidence
Complex IT web apps
Leadership & reporting
Business-IT liaison
Audit documentation
Disaster Recovery/BCP/IRP

Education

Bachelor’s degree in cyber security
5 years experience alternative

Job description

Job Title: Sr. IT Security Compliance Analyst

Location: Lansing, MI, (Hybrid)-Onsite from day 1, two days a week

Position Type: Contract

Interview Mode: 1st round MS Teams & 2nd round In-person

Job responsibilities:
  • Provide leadership and oversight for maintaining and updating System Security Plans (SSPs), ensuring documentation accuracy, completeness, and alignment with NIST protocol and SOM compliance standards.
  • Lead and coordinate the Authority to Operate (ATO) renewal process, including planning, preparing required materials, managing timelines, and ensuring successful approval and continuous compliance for all supported applications.
  • Ensure all applications maintain a valid ATO on a three year cycle and lead efforts to validate and maintain accurate security controls throughout each renewal period.
  • Reviews and informs management on security risk assessment results and recommends corrective actions as necessary.
  • Reviews, assesses risks and scope for high level security incidents. Develops new reports for management based on those collected metrics across multiple agencies: conducts trend analysis.
  • Work with stakeholders to address and track Plans of Action & Milestones (POA&Ms) and other compliance requirements, ensuring timely reporting and closure.
  • Provide senior level support across multiple business areas, MDCR, MCSC & MiLEAP, with a focus on standardized security plan updates, documentation improvements, and long term process consistency.
  • Analyze existing compliance documentation, identify gaps or risks, and guide corrective actions to meet regulatory and organizational requirements.
  • Coordinate cross functional collaboration with technical teams, business owners, enterprise security personnel, and project leadership to ensure all evidence and artifacts required for SSP and ATO processes are properly completed and maintained.
  • Oversee review, updates, and remediation of security controls, ensuring issues are tracked, communicated, and resolved in collaboration with stakeholders.
  • Lead efforts to identify procedural gaps, risks, or required updates during renewal cycles, ensuring consistent application of best practices across all supported systems.
  • Contribute to enterprise security governance by providing guidance, maintaining accurate records, mentoring team members, and driving timely completion of compliance activities.
  • Leads mid to high-level Incident Responses when working to resolve incidents.
  • Serves as the Incident response specialist for cyber event detection, correlation, response, and recovery.
Job Qualifications:
  • Bachelor’s degree in cyber security, Information Assurance, Business Analytics, or IT Related Field

OR: 5 years of experience

  • Preferred Advanced Degrees, Master’s in Cybersecurity, Information Assurance, Information Systems / IT Leadership, or an MBA with an IT or Security Concentration
  • Educational or professional knowledge of NIST Framework and Controls a must
  • Strong aptitude for written and oral communication
  • Strong documentation skills
  • Can collaborate cross-functionally
Skill | Required / Desired | Required Years of experience
  • Experience providing audit evidence to comply with security standards such as NIST, PCI, HIPPA, FERPA | Required | 5 Years
  • Exposure to Complex IT web Applications, within the past 5 years | Required | 5 Years
  • Experience leading meetings and making oral and written reports | Required | 5 Years
  • Experience working as a liaison between different business and IT areas | Required | 5 Years
  • Knowledge or experience creating supporting documentation for IT system audits | Highly Desired | 2 Years
  • Experience with the creation of Disaster Recover Plans, Business Continuity Plans, and Incident Response Plans | Highly Desired | 2 Years

Flexible work from home options available.

Get your free, confidential resume review.

or drag and drop your file here.