Share this job
IT Security Analyst
Lansing, Michigan, United States
Apply for this job

Come build, innovate, disrupt, and thrive!

 

KēSTA I.T is actively seeking a IT Security Analyst for an immediate contract engagement with our client.

  

Job Description:

We Are Seeking a senior IT Security Analyst to provide compliance oversight, security guidance, and strategic support for enterprise applications and information systems. This role will serve as a key liaison between business stakeholders, technical teams, security professionals, management, vendors, auditors, and project leadership to ensure security requirements, documentation, processes, and controls remain aligned with established security frameworks and organizational standards.

The IT Security Analyst will lead and support System Security Plan (SSP) development and maintenance, Authority to Operate (ATO) activities, security risk assessments, compliance documentation, security control reviews, remediation tracking, and incident response. The ideal candidate will have strong knowledge of NIST security frameworks and controls, excellent documentation and communication skills, and the ability to coordinate complex compliance activities across multiple application environments.

Responsibilities:

·         Provide senior-level oversight for the development, maintenance, review, and continuous improvement of System Security Plans (SSPs).

·         Ensure security documentation is accurate, complete, current, and aligned with applicable security standards, frameworks, and organizational requirements.

·         Lead and coordinate Authority to Operate (ATO) renewal activities, including planning, documentation, evidence collection, timeline management, stakeholder coordination, and approval support.

·         Monitor application authorization status and ensure security controls and supporting documentation remain current throughout the authorization lifecycle.

·         Review security risk assessment results, communicate findings to management, and recommend appropriate corrective actions.

·         Assess security risks associated with significant incidents and provide guidance on appropriate response and remediation activities.

·         Develop and maintain management reports using security and compliance metrics collected across multiple application environments.

·         Perform trend analysis to identify recurring security risks, compliance issues, control weaknesses, and opportunities for improvement.

·         Coordinate the identification, tracking, remediation, and closure of Plans of Action and Milestones (POA&Ms) and other compliance findings.

·         Review existing compliance documentation to identify gaps, inconsistencies, deficiencies, and potential risks.

·         Guide stakeholders in developing and implementing corrective actions necessary to address identified compliance or security gaps.

·         Coordinate with technical teams, business owners, application stakeholders, enterprise security personnel, vendors, auditors, and project managers to collect and maintain required security evidence and artifacts.

·         Oversee the review, maintenance, testing, and remediation of security controls.

·         Track security issues and corrective actions through resolution while ensuring stakeholders remain informed of progress and risks.

·         Identify procedural gaps and opportunities to improve security governance, compliance processes, documentation, and operational consistency.

·         Provide guidance on security and compliance requirements and assist stakeholders in interpreting applicable policies, standards, and controls.

·         Maintain accurate compliance records, audit documentation, security plans, and supporting artifacts.

·         Support enterprise security governance activities by promoting consistent practices across application and business areas.

·         Provide guidance and mentorship to less experienced team members regarding compliance processes, documentation, and security practices.

·         Lead moderate- to high-complexity incident response activities and coordinate efforts to resolve security incidents.

·         Support cyber event detection, analysis, correlation, response, containment, and recovery activities.

·         Prepare and deliver written and verbal reports, presentations, status updates, and recommendations to management and stakeholders.

·         Facilitate meetings and working sessions involving business, technical, security, and compliance teams.

·         Serve as a trusted liaison between business and IT teams to facilitate communication, resolve issues, and maintain alignment on security objectives.

Required Skills

·         5+ years of experience providing audit evidence and supporting compliance with security standards or regulatory frameworks such as NIST, PCI, HIPAA, and FERPA.

·         5+ years of experience working with or supporting complex IT web applications within recent enterprise environments.

·         5+ years of experience leading meetings and preparing or delivering professional written and verbal reports.

·         5+ years of experience serving as a liaison between business stakeholders, IT teams, security groups, and other cross-functional organizations.

·         5+ years of experience in cybersecurity, information assurance, IT, business analytics, compliance, or a closely related field, in lieu of the education requirement where applicable.

·         Bachelor’s degree in Cybersecurity, Information Assurance, Business Analytics, Information Technology, or a related field, or equivalent professional experience.

·         Strong knowledge of NIST frameworks, security controls, and compliance practices.

·         Strong understanding of security governance, risk management, compliance documentation, and audit processes.

·         Demonstrated ability to develop and maintain detailed technical and compliance documentation.

·         Strong written and verbal communication skills, including the ability to communicate complex security and compliance concepts clearly.

·         Strong organizational and analytical skills with the ability to manage multiple compliance activities, deadlines, and stakeholders.

·         Ability to collaborate effectively across business, technical, security, vendor, and management teams.

·         Strong problem-solving and critical-thinking skills with the ability to assess risks and recommend appropriate corrective actions.

Preferred Skills

·         2+ years of experience creating supporting documentation for IT system audits.

·         2+ years of experience developing or maintaining Disaster Recovery Plans, Business Continuity Plans, and Incident Response Plans.

·         Master’s degree in Cybersecurity, Information Assurance, Information Systems, IT Leadership, Business Administration, or a related discipline with an IT or security concentration.

·         Experience supporting formal Authority to Operate (ATO) processes and security authorization activities.

·         Experience developing and maintaining System Security Plans and security control documentation.

·         Experience managing POA&Ms, compliance findings, security remediation activities, and audit responses.

·         Experience with security incident response, cyber event analysis, and recovery activities.

·         Experience developing security metrics, management reports, and compliance trend analyses.

·         Experience working with vendors, auditors, project managers, and enterprise security teams.

·         Experience mentoring or providing guidance to other security, compliance, or technical professionals.

Available Benefits:

·         Medical Benefits (Platinum level plans available)

·         Work from home / Hybrid / Onsite options

·         PTO

·         Holiday Pay

·         VTO

·         401K

·         Charitable Match

·         Training reimbursement

 

About KēSTA I.T.:

 

Our name says it all; KēSTA I.T. (Keys-to-I.T.) AND our people are our keys to our success!

 

KēSTA I.T. is a premier Utah-based technical staffing and consulting services firm. We specialize in temporary and permanent placement of Software, Hardware, Network, Cloud, CRM/ERP, Data, End-User support, Web and Executive / leadership-based positions on a full time and consulting basis.

If you're interested in a role where top performance is rewarded, personal time is valued, and excellence is demanded at every level we want to talk to you today! 

 

Where do you want to go? We've got the keys! ~ KēSTA I.T.

 

WWW.KeSTAIT.COM






Apply for this job
Powered by