Digital Technology Solutions logo

Security compliance Analyst - Lansing, MI

  • Contractor
  • Full-time

Highlights

Coordinate cross functional collaboration with technical teams, business owners, enterprise security personnel, and project leadership to ensure all evidence and artifacts required for SSP and ATO processes are properly completed and maintained. - Coordinate cross‑functional collaboration with technical teams, business owners, enterprise security personnel, and project leadership to ensure all evidence and artifacts required for SSP and ATO processes are properly completed and maintained.

Numbers & Facts

LocationLansing, MI
Job TypeContractor, Full-time
Company Size51 - 200
Year Founded2005
Websitehttps://dts-it.com

Description

DTS is looking for Security compliance Analyst for our direct client position in Lansing, MI

 

 

Top Skills & Years of Experience:

- Experience providing audit evidence to comply with security standards such as NIST, PCI, HIPPA, FERPA - Required - 5 Years

- Exposure to Complex IT web Applications, within the past 5 years - Required - 5 Years

- Experience leading meetings and making oral and written reports - Required - 5 Years

- Experience working as a liaison between different business and IT areas - Required - 5 Years

 

Job responsibilities:

- Provide leadership and oversight for maintaining and updating System Security Plans (SSPs), ensuring documentation accuracy, completeness, and alignment with NIST protocol and client compliance standards.

- Lead and coordinate the Authority to Operate (ATO) renewal process, including planning, preparing required materials, managing timelines, and ensuring successful approval and continuous compliance for all supported applications.

- Ensure all applications maintain a valid ATO on a three-year cycle and lead efforts to validate and maintain accurate security controls throughout each renewal period.

- Reviews and informs management on security risk assessment results and recommends corrective actions as necessary.

- Reviews, assesses risks and scope for high level security incidents. Develops new reports for management based on those collected metrics across multiple agencies: conducts trend analysis.

- Work with stakeholders to address and track Plans of Action & Milestones (POA&Ms) and other compliance requirements, ensuring timely reporting and closure.

- Analyze existing compliance documentation, identify gaps or risks, and guide corrective actions to meet regulatory and organizational requirements.

- Coordinate cross functional collaboration with technical teams, business owners, enterprise security personnel, and project leadership to ensure all evidence and artifacts required for SSP and ATO processes are properly completed and maintained.

- Oversee review, updates, and remediation of security controls, ensuring issues are tracked, communicated, and resolved in collaboration with stakeholders.

- Lead efforts to identify procedural gaps, risks, or required updates during renewal cycles, ensuring consistent application of best practices across all supported systems.

- Contribute to enterprise security governance by providing guidance, maintaining accurate records, mentoring team members, and driving timely completion of compliance activities.

- Leads mid to high-level Incident Responses when working to resolve incidents.

- Serves as the Incident response specialist for cyber event detection, correlation, response, and recovery.

 

Job Qualifications:

-          Bachelor’s degree in cyber security, Information Assurance, Business Analytics, or IT Related Field (OR: 5 years of experience)
-          Preferred Advanced Degrees, Master’s in Cybersecurity, Information Assurance, Information Systems / IT Leadership, or an MBA with an IT or Security Concentration
-          Educational or professional knowledge of NIST Framework and Controls a must
-          Strong aptitude for written and oral communication
-          Strong documentation skills
-          Can collaborate cross-functionally
 
Skill       - Required/Desired        - Required Years of experience:
-          Experience providing audit evidence to comply with security standards such as NIST, PCI, HIPPA, FERPA - Required - 5 Years
-          Exposure to Complex IT web Applications, within the past 5 years - Required - 5 Years
-          Experience leading meetings and making oral and written reports - Required - 5 Years
-          Experience working as a liaison between different business and IT areas - Required - 5 Years
-          Knowledge or experience creating supporting documentation for IT system audits - Highly Desired - 2 Years
-          Experience with the creation of Disaster Recover Plans, Business Continuity Plans, and Incident Response Plans - Highly Desired            - 2 Years
 

Role description:

The primary duty of this position is performing as the compliance authority and liaison among business partners, technical teams, security groups, and management. The Senior Analyst ensures that requirements, processes, and documentation align with client standards, NIST protocols, and enterprise security governance. This role guides stakeholders through complex compliance cycles, drives consistency across application areas. They will also work and collaborate with people outside of the client Agency Services Compliance Team such as vendors, auditors, project managers, and analysts.

Job responsibilities:

-      Provide leadership and oversight for maintaining and updating System Security Plans (SSPs), ensuring documentation accuracy, completeness, and alignment with NIST protocol and SOM compliance standards.

-      Lead and coordinate the Authority to Operate (ATO) renewal process, including planning, preparing required materials, managing timelines, and ensuring successful approval and continuous compliance for all supported applications.

-      Ensure all applications maintain a valid ATO on a three‑year cycle and lead efforts to validate and maintain accurate security controls throughout each renewal period.

-      Reviews and informs management on security risk assessment results and recommends corrective actions as necessary.

-      Reviews, assesses risks and scope for high level security incidents. Develops new reports for management based on those collected metrics across multiple agencies: conducts trend analysis.

-      Work with stakeholders to address and track Plans of Action & Milestones (POA&Ms) and other compliance requirements, ensuring timely reporting and closure.

-      Provide senior‑level support across multiple business areas, MDCR, MCSC & MiLEAP, with a focus on standardized security plan updates, documentation improvements, and long‑term process consistency.

-      Analyze existing compliance documentation, identify gaps or risks, and guide corrective actions to meet regulatory and organizational requirements.

-      Coordinate cross‑functional collaboration with technical teams, business owners, enterprise security personnel, and project leadership to ensure all evidence and artifacts required for SSP and ATO processes are properly completed and maintained.

-      Oversee review, updates, and remediation of security controls, ensuring issues are tracked, communicated, and resolved in collaboration with stakeholders.

-      Lead efforts to identify procedural gaps, risks, or required updates during renewal cycles, ensuring consistent application of best practices across all supported systems.

-      Contribute to enterprise security governance by providing guidance, maintaining accurate records, mentoring team members, and driving timely completion of compliance activities.

-      Leads mid to high-level Incident Responses when working to resolve incidents.

-      Serves as the Incident response specialist for cyber event detection, correlation, response, and recovery.

 

 

Job Responsibilities

Job Qualifications:

-          Bachelor’s degree in cyber security, Information Assurance, Business Analytics, or IT Related Field

o   OR: 5 years of experience

-          Preferred Advanced Degrees, Master’s in Cybersecurity, Information Assurance, Information Systems / IT Leadership, or an MBA with an IT or Security Concentration

-          Educational or professional knowledge of NIST Framework and Controls a must

-          Strong aptitude for written and oral communication

-          Strong documentation skills

-          Can collaborate cross-functionally

 

Skill
Required / Desired
Required Years of experience
Experience providing audit evidence to comply with security standards such as NIST, PCI, HIPPA, FERPA
Required
5 Years
Exposure to Complex IT web Applications, within the past 5 years
Required
5 Years
Experience leading meetings and making oral and written reports
Required
5 Years
Experience working as a liaison between different business and IT areas
Required
5 Years
Knowledge or experience creating supporting documentation for IT system audits
Highly Desired
2 Years
Experience with the creation of Disaster Recover Plans, Business Continuity Plans, and Incident Response Plans
Highly Desired
2 Years
 

 

 

DTS offers an excellent compensation package.

Contact:

Kuldeep Singh

Team Lead
Digital Technology Solutions

Skills

  • Cybersecurity
  • Business Analytics
  • IT Management
  • Security Controls
  • SYSTEM SECURITY
  • HIPAA

About Company

Digital Technology Solutions LLC (DTS) is a growing Information Technology services provider to Fortune 500 companies.  DTS is a Michigan Minority Business Development Council (MMBDC) certified Minority Business Enterprise (MBE). DTS is recently certified as 8(a) Program Participant and Small Disadvantaged Business (SDB) by the US Small Business Administration (SBA). DTS is headquartered in Southfield, MI with operating location in Beavercreek, OH .  
 

Similar Jobs

See more jobs