Work Model: Hybrid, 2 days a week on site
Allows Relocation: NO, must be within 90 miles
SUMMARY
This Senior IT Business/Compliance Analyst position serves as a senior resource within the Department of Technology, Management and Budget (DTMB) Agency Services for Michigan Department of Civil Rights (MDCR), Michigan Civil Service Commission (MCSC) and Michigan Department of Lifelong Education, Advancement and Potential (MILEAP). The role provides high‑level oversight, guidance, and strategic direction for completing, updating, and maintaining System Security Plans (SSPs) and Disaster Recovery Plans (DRPs) for the MCSC and MiLEAP applications.
The primary duty of this position is performing as the compliance authority and liaison among business partners, technical teams, security groups, and management. The Senior Analyst ensures that requirements, processes, and documentation align with State of Michigan standards, NIST protocols, and enterprise security governance. This role guides stakeholders through complex compliance cycles, drives consistency across application areas. They will also work and collaborate with people outside of the DTMB Agency Services Compliance Team such as vendors, auditors, project managers, and analysts.
RESPONSIBILITIES
- Provide leadership and oversight for maintaining and updating System Security Plans (SSPs), ensuring documentation accuracy, completeness, and alignment with NIST protocol and SOM compliance standards
- Lead and coordinate the Authority to Operate (ATO) renewal process, including planning, preparing required materials, managing timelines, and ensuring successful approval and continuous compliance for all supported applications
- Ensure all applications maintain a valid ATO on a three‑year cycle and lead efforts to validate and maintain accurate security controls throughout each renewal period
- Reviews and informs management on security risk assessment results and recommends corrective actions as necessary
- Reviews, assesses risks and scope for high level security incidents. Develops new reports for management based on those collected metrics across multiple agencies: conducts trend analysis
- Work with stakeholders to address and track Plans of Action & Milestones (POA&Ms) and other compliance requirements, ensuring timely reporting and closure
- Provide senior‑level support across multiple business areas, MDCR, MCSC & MiLEAP, with a focus on standardized security plan updates, documentation improvements, and long‑term process consistency
- Analyze existing compliance documentation, identify gaps or risks, and guide corrective actions to meet regulatory and organizational requirements
- Coordinate cross‑functional collaboration with technical teams, business owners, enterprise security personnel, and project leadership to ensure all evidence and artifacts required for SSP and ATO processes are properly completed and maintained
- Oversee review, updates, and remediation of security controls, ensuring issues are tracked, communicated, and resolved in collaboration with stakeholders
- Lead efforts to identify procedural gaps, risks, or required updates during renewal cycles, ensuring consistent application of best practices across all supported systems
- Contribute to enterprise security governance by providing guidance, maintaining accurate records, mentoring team members, and driving timely completion of compliance activities
- Leads mid to high-level Incident Responses when working to resolve incidents
- Serves as the Incident response specialist for cyber event detection, correlation, response, and recovery
QUALIFICATIONS
Required:
- Experience providing audit evidence to comply with security standards such as NIST, PCI, HIPPA, FERPA - Required - 5 Years
- Exposure to Complex IT web Applications, within the past 5 years - Required - 5 Years
- Educational or professional knowledge of NIST Framework and Controls a must
- Experience working as a liaison between different business and IT areas - Required - 5 Years
- Knowledge or experience creating supporting documentation for IT system audits
- Experience with the creation of Disaster Recovery Plans, Business Continuity Plans, and Incident Response Plans
- Experience leading meetings and making oral and written reports - Required - 5 Years
- Bachelor’s degree in cyber security, Information Assurance, Business Analytics, or IT Related Field
- Preferred Advanced Degrees, Master’s in Cybersecurity, Information Assurance, Information Systems / IT Leadership, or an MBA with an IT or Security Concentration
PRE-EMPLOYEMENT & CLIENT SUBMISSION REQUIREMENTS
Employment and/or client submission is contingent upon successful completion of required pre-employment screening and verification processes. These requirements include:
-
Background check: Candidates must successfully complete the required background screening in accordance with company policy and applicable law.
-
Drug screening: Candidates must successfully complete the required drug screening in accordance with company policy, applicable client requirements, and applicable law.
-
Identity and location verification: Candidates may be required to complete identity and/or location verification using a secure verification tool prior to client submission.
-
Employment eligibility: Candidates must provide appropriate documentation to verify employment eligibility as required by law.
-
Qualification verification: Information provided during the application and recruiting process, including employment history, education, certifications, licenses, and professional references, may be verified as applicable.
-
Additional client requirements: Additional screening, documentation, or verification may be required based on the client, position, work location, or applicable requirements.
All screening and verification activities will be conducted in accordance with applicable company policies, client requirements, and federal, state, and local laws.
BENEFITS
This is a contract opportunity with a great organization. As a contractor for Smith Johnson, you are eligible for medical, dental, life, disability. Smith Johnson pays for 70% of your medical and dental and 100% of life and disability. The contract is also eligible for PTO/holiday accrued monthly. You are also eligible for a 3% retirement matching plan. Smith Johnson believes in taking care of our contractors.