We are looking for System Analyst 6 in Lansing MI Hybrid. Please read the job description below and let me know if you are interested.
Position: System Analyst 6 – Security & Compliance
Location: Lansing, MI – Hybrid
Duration: 12+ Months Contract with Possible Extension
Interview Process: Virtual/In-Person
Job Description
The State of Michigan is seeking an experienced System Analyst 6 – Security & Compliance to support the security, compliance, risk management, and business continuity needs of systems and processes used in administering retirement benefits for public-sector employees.
Key Responsibilities
- Analyze, document, and validate security processes, system requirements, workflows, and interagency interactions.
- Collaborate with business, technical, and program stakeholders to define security and compliance requirements for system enhancements and new initiatives.
- Develop and maintain audit-ready documentation, including security requirements, user stories, workflows, use cases, and compliance documentation.
- Support solution design and participate in testing activities, including User Acceptance Testing (UAT), to validate security and compliance controls.
- Conduct security risk assessments, gap analyses, and impact assessments and recommend appropriate mitigation strategies.
- Support internal and external security assessments, audits, standards reviews, and control validation activities.
- Assist with the development and maintenance of System Security Plans, Assessment Reports, Authorization Packages, and other security documentation.
- Monitor project deliverables, timelines, and milestones to ensure alignment with security objectives and compliance requirements.
- Analyze legislative, regulatory, and policy changes and assess their impact on business operations and system security.
- Provide guidance and informal leadership to cross-functional teams regarding security, compliance, risk management, and governance best practices.
- Lead discussions with stakeholders and technology partners to establish alignment on security objectives and compliance expectations.
- Mentor analysts in interpreting security frameworks, documenting requirements, and navigating governance processes.
- Support security incident, compliance issue, and audit activities by coordinating responses and communicating risks and findings.
- Develop training materials and assist with security and compliance awareness activities.
- Perform data analysis and prepare reports for compliance monitoring, risk tracking, performance evaluation, and decision-making.
Disaster Recovery & Business Continuity
- Collaborate with business units to develop and maintain Business Continuity Plans (BCPs).
- Contribute to the development, documentation, testing, and maintenance of Disaster Recovery Plans (DRPs) for critical systems.
- Conduct business impact assessments and ensure DR/BC strategies align with operational requirements.
- Assist in defining and documenting Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
- Participate in tabletop exercises and simulations to validate recovery plans.
- Identify, document, and help remediate gaps identified during DR/BC testing.
- Ensure DR/BC activities align with State of Michigan policies, NIST, FISMA, and other applicable standards.
Vulnerability & Security Assessment
- Coordinate system, application, and network vulnerability scans with infrastructure and security teams.
- Review and analyze vulnerability scan results.
- Prioritize identified risks based on severity and business impact.
- Support mitigation planning and remediation activities.
- Demonstrate knowledge of common application vulnerabilities, including XSS, CSRF, SQL Injection, and authentication weaknesses.
Required Qualifications
- Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Public Administration, or a related field, or equivalent professional experience.
- 7+ years of professional experience in security, compliance, risk management, or a closely related discipline.
- 5+ years of experience working with security and compliance frameworks such as:
- NIST Cybersecurity Framework (NIST CSF)
- NIST SP 800-53
- State IT security standards
- 5+ years of experience using tools supporting security documentation, compliance tracking, and workflow management, such as Azure DevOps and GRC platforms.
- Experience developing, documenting, and evaluating security controls, compliance requirements, and governance processes.
- Experience supporting security assessments, audits, policy reviews, and control validation.
- Experience contributing to the development, documentation, and testing of Disaster Recovery Plans.
- Experience assisting with the definition of RTOs and RPOs.
- Knowledge of Agile SDLC practices and integrating security and compliance requirements into development, testing, and release processes.
- Experience with data protection, access controls, regulatory compliance, and secure system implementation.
Preferred Qualifications
- Previous government or military experience.
- Experience working within a public retirement system or regulated financial environment.
- Experience working with State of Michigan security policies and standards.
- Strong communication, documentation, analytical, and stakeholder-management skills.
- Ability to provide guidance and mentorship to other analysts and cross-functional teams.
Best Regards, Salman Alam
IT Recruiter||Syntricate Technologies Inc.
Direct: 781-236-6328
Email:
salman.a@syntricatetechnologies.com