Our client is looking for a Security Compliance Analyst to support the integrity, security, and compliance of systems and processes used in administering retirement benefits for public sector employees. This role ensures that technology solutions, operational practices, and policy implementations adhere to state regulations, security standards, and organizational governance requirements. The analyst will collaborate with cross‑departmental teams to strengthen security controls, improve business processes, and ensure consistent delivery of secure and reliable services to stakeholders and citizens.
Tasks:
· Analyze, document, and validate security processes, system requirements, and interagency interactions supporting retirement benefits administration.
· Collaborate with program offices, technical teams, and subject matter experts to define and refine security and compliance requirements for system enhancements, policy updates, and new state initiatives.
· Create and maintain clear, audit‑ready documentation, including security requirements, user stories, workflows, and use cases aligned with public sector standards and oversight expectations.
· Support solution design and participate in testing phases (e.g., UAT) to verify that security controls and compliance requirements are properly implemented.
· Recommend improvements that strengthen security posture, improve process efficiency, and support program accountability and service quality.
· Monitor project deliverables, timelines, and milestones to ensure alignment with organizational security objectives, state compliance mandates, and governance frameworks.
· Assist in developing training materials and delivering security and compliance education to program staff and stakeholders.
· Conduct gap analyses and assess impacts of legislative, regulatory, or policy changes on business operations and system security.
· Perform data analysis and generate reports to support compliance monitoring, performance evaluation, risk tracking, and data‑driven decision‑making across the organization.
· Provide guidance and informal leadership to cross‑functional teams by promoting best practices in security, compliance, and risk management.
· Lead discussions with program offices, technology partners, and stakeholders to ensure alignment on security objectives, policy interpretations, and compliance expectations.
· Serve as a mentor to analysts by offering support in interpreting security frameworks, documenting requirements, and navigating governance processes.
· Champion a culture of security awareness and continuous improvement by fostering collaboration, communicating risks clearly, and influencing adoption of secure and compliant operational behaviors.
· Take ownership of key security and compliance initiatives, driving progress, managing expectations, and ensuring deliverables meet organizational standards and regulatory requirements.
· Provide leadership during security incidents, compliance issues, and audit activities by coordinating responses, ensuring timely communication, and supporting decision‑making with clear, accurate analysis.
· Perform tasks in support of internal and external security and standards reviews.
· Conduct security risk assessments and recommend mitigation strategies.
· Assist with development and maintenance of security documentation, including System Security Plans,
· Assessment Reports, and Authorization packages.
· Support security audits by gathering documentation and demonstrating control effectiveness.
· Disaster Recovery & Business Continuity Planning
NOTE: Local candidates strongly preferred (within 75-miles of Lansing, MI). Candidates outside of this range may be considered, however, if selected MUST relocate prior to start. There are no exceptions for this, if a candidate is selected and cannot relocate, their assignment will be ended. Resource will be working a hybrid schedule. NO REMOTE ONLY OPTION. Will need to be onsite from day 1, two days a week. (Tuesday/Wednesday).
Location: Lansing, MI
Contract: 1 year
Skills Required:
· 7 years - Professional experience in security, compliance, risk management, or a closely related discipline within a government agency, public retirement system, or regulated financial environment.
· 5+ years - Experience of security and compliance frameworks relevant to public sector environments, such as NIST CSF, NIST 800 53, and state IT security standards.
· 5+ years - Experience in tools used to support security documentation, compliance tracking, and workflow management (e.g., Azure DevOps, GRC platforms).
· 5+ years - Experience contributing to development, documentation, and testing of Disaster Recovery Plans (DRPs) for critical systems.
· 5+ years - Experience in assisting in defining recovery time objectives (RTOs) and recovery point objectives (RPOs).
· Demonstrated experience developing, documenting, and evaluating security controls, compliance requirements, and governance processes.
· Experience supporting security or compliance assessments, audit activities, policy reviews, and control validations.
· Experience participating in system or process changes with a focus on ensuring data protection, access controls, regulatory adherence, and secure implementation.
· Ability to assess common vulnerabilities such as XSS, CSRF, SQL Injection, and authentication weaknesses.
· Contribute to development, documentation, and testing of Disaster Recovery Plans (DRPs) for critical systems.
· Assist in defining recovery time objectives (RTOs) and recovery point objectives (RPOs).
Skills Desired – A plus to have:
· Knowledge of Agile SDLC practices with an emphasis on integrating security and compliance into requirements, testing, and release processes.
· Previous government/military experience.
· Bachelor’s degree in information security, cybersecurity, information systems, public administration, or a related field.
*** Rate depends on experience
*** Candidates authorized to work in the US are encouraged to apply. We can accept H1b, , TN, and other valid work visas for IT. However, we cannot accept OPT or CPT visas at this time.
*** Companies submitting candidates should only submit direct W2 employees for this position.