IT Security Analyst 2
Aroha Technologies, Inc · Lansing, MI · 3 wk ago
HybridContract
Duration: 1 year with possible extension. Hybrid schedule requiring onsite presence from Day 1, two days per week (Tuesdays and Wednesdays). No remote-only option.
Location: Local candidates only, must be located within 100 miles of Lansing, MI.
Additional requirements: References, pre-screening questions, and a standard cover letter summarizing qualifications must be submitted. Candidates must attach official transcripts or a Cyber Security certification.
Responsibilities
- Create and maintain System Security Plans (SSPs) for new and existing systems in collaboration with Automation Managers, System Owners, System Security Administrators, and project teams following the Secure Application Development Life Cycle and Security Accreditation Process.
- Maintain SSPs for existing applications requiring Authority to Operate (ATO) and system enhancements.
- Collaborate with business representatives to establish system registration.
- Lead security testing and system scanning activities.
- Perform risk assessments and provide security control responses.
- Monitor Plans of Action & Milestones (POA&M) and Corrective Action Plans related to SSPs.
- Validate SSPs to ensure compliance with NIST security controls.
- Develop recommendations to improve security posture in accordance with security policies, standards, procedures, and NIST controls.
- Lead team members and vendors in collecting required assessment artifacts.
- Coordinate scanning and enterprise security activities with security teams, technical leads, and business areas.
- Lead system Data Classification activities within the SSP/ATO process.
- Support development projects and assist with Authority to Operate (ATO) activities during Commercial Off-the-Shelf (COTS) implementation projects to meet security requirements before production deployment.
Requirements
- 1–3 years of experience in IT Security or a related field.
- Knowledge of commonly used concepts, practices, and procedures (e.g., NIST, SSP, GRC).
- Experience with Keylight is a plus.
- Strong communication and customer service skills.
- Clear and concise written and verbal communication skills.
- Must have one of the following:
- A Bachelor’s degree or higher specific to IT (official transcripts required), or
- A Cyber Security certification (certificate required).
- Qualifying education or experience alternatives:
- Associate’s degree with qualifying coursework plus at least two years of related IT experience, or
- High School Diploma (or equivalent) plus three years of relevant IT experience, or
- IT Certification.