IT Security Analyst

Posted 2 Days Ago
Be an Early Applicant
Lansing, MI, USA
In-Office
Senior level
Cloud • Information Technology • Consulting • Cybersecurity
The Role
Perform Security Control Assessments and continuous monitoring for State of Michigan applications per NIST guidance. Validate security plans, execute SCA documentation (POA&M, CAP, DTMB-170), interview and test procedures, author remediation recommendations, lead small assessments, and assist vendors and team members with artifact collection to ensure controls meet NIST and state policies.
Summary Generated by Built In
Job Description

Complete Description: Monitor and advise on information security issues related to the systems & workflow @ an agency to ensure the internal IT security controls for an agency are appropriate & operating as intended.In Person Only

Years of Experience:

4-7 years of experience in the field or in a related area.

Responsibilities:

•Facilitate Security Control Assessment (SCA) and Continuous Monitoring Activities (Plans of Action and Milestones (POA&M) , Corrective Action Plans (CAP) with State of Michigan Applications.

•To be considered for this position, the candidate must be available to work in Lansing Michigan 

•Examine, interview, and test procedures in accordance with NIST SP 800-53A Revision 4.

•Ensure State of Michigan & Agency policies are adhered to and that required controls are implemented.

•Validate respective information system security plans to ensure NIST control requirements are met.

•Execute SCA  (DTMB-170) documentation, including but not limited to POA&M & CAP.

•Familiarity with NIST requirements, particularly 800-53 revision 3 and revision 4.

•Author recommendations associated with your findings on how to improve the customer’s security posture in accordance with SOM PSP & NIST controls.

•Ability to lead small, less complex system assessments independently

•Ability to assist team members & Vendors  with proper artifact collection and detail to clients examples of artifacts that will satisfy assessment requirements

Qualifications:

•Candidate must have solid knowledge of information security principles and practices, as well as an advanced understanding of security protocols and standards.

•Candidate must have at (1-3) years of experience in the IT industry, and be familiar with the applicable NIST Special Publications 800-37 Revision 1, 800-53 Revision 3 or 4, and 800-53A Revision 1.

•Experience reviewing IT systems/applications plus basic knowledge of networking components and various operating   systems in including UNIX and Microsoft.

•Candidate must have the ability to work independently and as part of a team

•Preferred that the candidate has a CISSP, CISA, PMP and/or Security+ certification, but it is not required

•Expertise in other Security Frameworks (ISO, NIST, COBIT, HIPAA/HITECH, etc.) and regulatory requirements is a plus

•Strong written and verbal communication skills including the ability to explain technical matters to a non-technical audience

•Collaborate on multiple projects at a given time and experience with Vendors is a plus

•Flexibility to adjust quickly to multiple demands, shifting priorities, ambiguity, and rapid change

Additional Information

All your information will be kept confidential according to EEO guidelines.

Skills Required

  • 4-7 years of experience in the field or a related area
  • Available to work in person in Lansing, Michigan (In Person Only)
  • Solid knowledge of information security principles, protocols, and standards
  • Experience with Security Control Assessment (SCA) and Continuous Monitoring activities, including POA&M and CAP
  • Familiarity with NIST SP 800-53 Revision 3 and Revision 4
  • Ability to examine, interview, and test procedures in accordance with NIST SP 800-53A Rev 4
  • Experience validating information system security plans to ensure NIST control requirements are met
  • Experience reviewing IT systems/applications and basic knowledge of networking components
  • Familiarity with UNIX and Microsoft Windows operating systems
  • Ability to lead small, less complex system assessments independently
  • Strong written and verbal communication skills; can explain technical matters to non-technical audiences
  • Preferred certifications: CISSP, CISA, PMP, and/or Security+
  • Expertise with other security frameworks and regulatory requirements (ISO, COBIT, HIPAA/HITECH) is a plus
  • Experience collaborating with vendors and managing multiple projects concurrently
  • Flexibility to adjust quickly to shifting priorities, ambiguity, and rapid change
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
125 Employees
Year Founded: 2008

What We Do

Ask IT Consulting Inc. is a global information technology management firm founded in 2008 and headquartered in Holtsville, NY. The company specializes in providing comprehensive technology and workforce solutions, including IT consulting, talent management, and digital services. Their expertise extends to cybersecurity, cloud computing, and IT staffing, focusing on delivering tailored, innovative, and effective solutions to meet the unique objectives of their diverse clients.

Similar Jobs

In-Office
Lansing, MI, USA
471 Employees
In-Office
Lansing, MI, USA
471 Employees
In-Office or Remote
6 Locations
2082 Employees
90K-115K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account