ORS – Security & Compliance System Analyst
6
Job Posting: Security & Compliance Analyst
The Security & Compliance Analyst supports
the integrity, security, and compliance of systems and processes used in
administering retirement benefits for public sector employees. This role
ensures that technology solutions, operational practices, and policy
implementations adhere to state regulations, security standards, and
organizational governance requirements. The analyst will collaborate with cross‑departmental
teams to strengthen security controls, improve business processes, and ensure
consistent delivery of secure and reliable services to stakeholders and
citizens.
Key Responsibilities
• Analyze, document, and validate security
processes, system requirements, and interagency interactions supporting
retirement benefits administration.
• Collaborate with program offices, technical teams, and subject matter experts
to define and refine security and compliance requirements for system
enhancements, policy updates, and new state initiatives.
• Create and maintain clear, audit‑ready documentation, including security
requirements, user stories, workflows, and use cases aligned with public sector
standards and oversight expectations.
• Support solution design and participate in testing phases (e.g., UAT) to
verify that security controls and compliance requirements are properly
implemented.
• Recommend improvements that strengthen security posture, improve process
efficiency, and support program accountability and service quality.
• Monitor project deliverables, timelines, and milestones to ensure alignment
with organizational security objectives, state compliance mandates, and
governance frameworks.
• Assist in developing training materials and delivering security and
compliance education to program staff and stakeholders.
• Conduct gap analyses and assess impacts of legislative, regulatory, or policy
changes on business operations and system security.
• Perform data analysis and generate reports to support compliance monitoring,
performance evaluation, risk tracking, and data‑driven decision‑making across
the organization.
Leadership & Collaboration
Responsibilities
• Provide guidance and informal leadership to
cross‑functional teams by promoting best practices in security, compliance, and
risk management.
• Lead discussions with program offices, technology partners, and stakeholders
to ensure alignment on security objectives, policy interpretations, and
compliance expectations.
• Serve as a mentor to analysts by offering support in interpreting security
frameworks, documenting requirements, and navigating governance processes.
• Champion a culture of security awareness and continuous improvement by
fostering collaboration, communicating risks clearly, and influencing adoption
of secure and compliant operational behaviors.
• Take ownership of key security and compliance initiatives, driving progress,
managing expectations, and ensuring deliverables meet organizational standards
and regulatory requirements.
• Provide leadership during security incidents, compliance issues, and audit
activities by coordinating responses, ensuring timely communication, and
supporting decision‑making with clear, accurate analysis.
Security & Compliance Support
• Perform tasks in support of internal and
external security and standards reviews.
• Conduct security risk assessments and recommend mitigation strategies.
• Assist with development and maintenance of security documentation, including
System Security Plans, Assessment Reports, and Authorization packages.
• Support security audits by gathering documentation and demonstrating control
effectiveness.
Disaster Recovery & Business Continuity
Planning
• Collaborate with business units to develop and maintain Business Continuity
Plans (BCPs).
• Conduct business impact assessments and ensure DRP/BCP strategies align with
operational needs.
• Participate in tabletop exercises and simulations to test and validate plans,
documenting and addressing gaps.
• Ensure DRP/BCP efforts comply with State of Michigan policies, NIST, FISMA,
and other applicable standards.
Vulnerability Management
• Coordinate and schedule system, application,
and network vulnerability scans in collaboration with infrastructure and
security teams.
• Analyze scan results, prioritize risks, and support mitigation planning.
Minimum Qualifications
• Seven years of professional experience in security, compliance, risk
management, or a closely related discipline within a government agency, public
retirement system, or regulated financial environment.
• Demonstrated experience developing, documenting, and evaluating security
controls, compliance requirements, and governance processes.
• Experience supporting security or compliance assessments, audit activities,
policy reviews, and control validations.
• Working knowledge of security and compliance frameworks relevant to public
sector environments, such as NIST CSF, NIST 800‑53, and state IT security
standards. – 5+ years of experience
• Experience participating in system or process changes with a focus on
ensuring data protection, access controls, regulatory adherence, and secure
implementation.
• Knowledge of Agile SDLC practices with an emphasis on integrating security
and compliance into requirements, testing, and release processes.
• Ability to assess common vulnerabilities such as XSS, CSRF, SQL Injection,
and authentication weaknesses.
• Proficiency in tools used to support security
documentation, compliance tracking, and workflow management (e.g., Azure
DevOps, GRC platforms). – 5+ years of experience
• Contribute to development, documentation, and
testing of Disaster Recovery Plans (DRPs) for critical systems.
• Assist in defining recovery time objectives (RTOs) and recovery point
objectives (RPOs).
Preferred Qualifications
• Bachelor’s degree in information security,
cybersecurity, information systems, public administration, or a related field;
or equivalent experience.
• Experience supporting security and compliance
needs within public pension or retirement administration programs.
• Working knowledge of security capabilities and data protection requirements
within pension administration platforms or enterprise benefits systems.
• Experience using SQL or analytics tools (Power BI, advanced Excel) to support
compliance monitoring, security metrics, reporting, and data validation.
• Professional security or compliance certifications such as CGRC, CAP,
Security+, CISA, or similar.
• Knowledge of state and federal regulations governing data security, privacy,
and compliance within public sector retirement systems (IRS, SSA, state
statutes, audit standards).
• Familiarity with Java or the .NET framework.
• High‑level understanding of how web applications function.
| Location | Lansing, Michigan |
| Industry | Staffing/Employment Agencies |
| Company Size | 20 to 49 employees |
| Year Founded | 2004 |
| Website | http://www.novalink-solutions.com/ |
Novalink, founded in 2003 , is a leading consulting and staffing company serving clients in public and private sectors in Information Technology, Telecommunications (IT/Telecom), Technical Networks, Finance, and Administration. With government agencies as our primary clientele, our team has a proven track record of success in providing temporary personnel solutions and managing government deliverables-based projects over the past 20 years.
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder