Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Stafford Gray LLC

Senior IT Security Compliance Analyst

Stafford Gray LLC

. Lead the maintenance and updating of System Security Plans (SSPs), ensuring accuracy, completeness and alignment with NIST controls .

Posted 10/2/2026contractLansing • Michigan • United StatesSenior💰 $110,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in maintaining System Security Plans (SSPs) and managing the ATO renewal process while ensuring compliance with NIST controls. Proficient in risk assessment, incident response, and developing metrics-based reports to support business continuity and security operations.

Highest-signal resume keywords
NIST Framework and ControlsSystem Security Plans (SSPs)Disaster Recovery PlanningIncident Response ManagementAudit Evidence Compliance

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk AssessmentSecurity Control ValidationCompliance DocumentationMetrics-Based ReportingPlans of Action & Milestones (POA&Ms)Incident ResponseBusiness Continuity PlanningTechnical LiaisonDocumentation CreationSecurity Standards Compliance
Soft Skills
Oral and Written CommunicationTeam MentoringCollaboration
Certifications & Qualifications
CISSPCGRCCISACISM
Industry Keywords
NISTPCIHIPAAFERPAIT Web ApplicationsCybersecurityInformation AssuranceBusiness Analytics

Tech Stack

Tools & technologies
Cyber Security

About the role

Key responsibilities & impact
  • Lead the maintenance and updating of System Security Plans (SSPs), ensuring accuracy, completeness and alignment with NIST controls
  • Plan and run the ATO renewal process on a three-year cycle, from preparing materials and managing timelines through approval and continuous compliance
  • Validate and maintain security controls throughout each authorization period and oversee remediation of control gaps
  • Track Plans of Action & Milestones (POA&Ms) and other compliance requirements through closure
  • Review risk assessment results, brief management and recommend corrective actions
  • Assess the risk and scope of high-level security incidents, lead mid- to high-level incident response, and support detection, response and recovery
  • Develop metrics-based reports and trend analysis for management across multiple business areas
  • Create and maintain Disaster Recovery Plans and contribute to business continuity and incident response planning
  • Identify gaps in compliance documentation and drive consistent practices across supported systems
  • Coordinate with technical teams, business owners and security staff to ensure SSP and ATO evidence and artifacts are complete and current
  • Work across business owners, technical teams, enterprise security, vendors, auditors and project managers
  • Mentor other analysts on the team

Requirements

What you’ll need
  • 5+ years providing audit evidence to comply with security standards such as NIST, PCI, HIPAA or FERPA
  • 5+ years of exposure to complex IT web applications
  • 5+ years leading meetings and delivering oral and written reports
  • 5+ years working as a liaison between business and IT areas
  • Strong working knowledge of the NIST framework and controls (required)
  • Strong writing and documentation skills
  • A bachelor's degree in cybersecurity, information assurance, business analytics or an IT-related field, or 5 years of equivalent experience
  • 2+ years creating documentation to support IT system audits (preferred)
  • 2+ years creating Disaster Recovery, Business Continuity or Incident Response Plans (preferred)
  • A master's in cybersecurity, information assurance or IT leadership, or an MBA with an IT or security concentration (preferred)
  • Certifications such as CISSP, CGRC (formerly CAP), CISA or CISM (preferred)