268-2 IT Security Compliance Analyst

Stafford GrayLansing, MI

About The Position

The Compliance Analyst is responsible for completing and maintaining System Security Plans (SSPs) for new and existing systems, documented within a Governance, Risk, and Compliance (GRC) tool. This role requires close coordination with IT project teams, tech leads, business and enterprise security representatives, and product owners to establish and maintain security controls and processes, identify vulnerabilities, and coordinate remediation efforts. Compliance Analysts are assigned to internal development projects and are available for consultation on Commercial Off-the-Shelf (COTS) procurement-phase projects. For COTS implementation-phase projects, Compliance Analysts serve as a core resource navigating SSP/Authority to Operate (ATO) activities with the enterprise security team to support security requirements through Go Live.

Requirements

  • 1 to 3 years of experience in the field or a related area
  • Working knowledge of commonly used concepts, practices, and procedures within IT security/compliance
  • A bachelor's degree or higher with 21 semester (32 term) credits in computer science, data processing, computer information systems, data communications, networking, systems analysis, computer programming, or mathematics — plus at least 2 years of experience as an application programmer, computer operator, or IT technician
  • An associate's degree with 16 semester (24 term) credits in one of the above fields (or equivalent) — plus at least 2 years of experience as above
  • A high school diploma or equivalent — plus 3 years of experience as an application programmer, computer operator, or IT technician (official transcripts required if applicable)
  • A relevant IT certification

Responsibilities

  • Create SSPs in collaboration with automation managers, system owners, system security administrators, and project teams for new applications, aligned with the organization's Secure Application Development Life Cycle and security accreditation process
  • Maintain SSPs for existing applications requiring ATO, including those undergoing software or hardware enhancements
  • Collaborate with business representatives to establish system registration
  • Lead and identify security testing and system scanning requirements
  • Perform risk assessments and provide responses for security controls
  • Continuously monitor plans of action, milestones, and corrective action plans related to SSPs, in collaboration with the enterprise information management office
  • Validate SSPs to ensure NIST control requirements are met
  • Author recommendations on improving security posture in accordance with organizational policies, standards, and procedures, and NIST controls
  • Lead team members and vendors on proper artifact collection to satisfy assessment requirements
  • Coordinate scanning and enterprise activities with the security team, tech leads, and business areas
  • Lead the system Data Classification component of the SSP/ATO process
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service