IT Security Analyst
Job Description
Cilable is hiring an IT Security Analyst for a contract role based in Lansing, MI (hybrid). This position supports DTMB Agency Services for multiple Michigan organizations, with senior ownership of security plan maintenance, compliance processes, and incident response support. If you value clear standards, measurable compliance outcomes, and working across business and technical stakeholders, this role keeps security documentation and risk management moving forward.
Compensation: $50.00 to $60.00 per hour. Work model: Hybrid remote in Lansing, MI 48916.
Responsibilities
- Provide leadership and oversight for System Security Plans (SSPs), keeping documentation accurate, complete, and aligned with NIST protocol and SOM compliance standards.
- Lead and coordinate the Authority to Operate (ATO) renewal process, including planning, preparing required materials, managing timelines, and supporting successful approval and continuous compliance for supported applications.
- Ensure applications maintain a valid ATO on a three-year cycle, validating and maintaining accurate security controls throughout each renewal period.
- Review and communicate security risk assessment results to management, including recommended corrective actions as needed.
- Assess risks and define scope for high level security incidents; produce management reporting and perform trend analysis using metrics across multiple agencies.
- Partner with stakeholders to address and track Plans of Action & Milestones (POA&Ms) and other compliance requirements, ensuring timely reporting and closure.
- Support multiple business areas across MDCR, MCSC, and MiLEAP, with focus on standardized security plan updates, documentation improvements, and consistent long-term processes.
- Analyze existing compliance documentation, identify gaps or risks, and guide corrective actions to meet regulatory and organizational requirements.
- Coordinate cross-functional work with technical teams, business owners, enterprise security personnel, and project leadership to ensure SSP and ATO evidence and artifacts are properly completed and maintained.
- Oversee review, updates, and remediation of security controls, tracking issues, communicating status, and resolving items with stakeholder support.
- Lead identification of procedural gaps, risks, or renewal-cycle updates, ensuring best practices are applied consistently across supported systems.
- Contribute to enterprise security governance by maintaining accurate records, mentoring team members, and driving timely completion of compliance activities.
- Lead mid to high-level incident responses and serve as the incident response specialist for cyber event detection, correlation, response, and recovery.
Requirements
- Bachelor’s degree in cyber security, Information Assurance, Business Analytics, or an IT-related field OR 5 years of experience.
- Preferred: Advanced degree (Master’s in Cybersecurity, Information Assurance, Information Systems / IT Leadership, or an MBA with an IT or Security Concentration).
- Knowledge of the NIST Framework and Controls (required).
- Strong written and oral communication skills.
- Strong documentation skills.
- Ability to collaborate cross-functionally.
- Experience providing audit evidence to comply with standards such as NIST, PCI, HIPPA, FERPA.
- Exposure to complex IT web applications within the past 5 years.
- Experience leading meetings and delivering oral and written reports.
- Experience serving as a liaison between business and IT areas.
- Experience creating supporting documentation for IT system audits.
- Experience creating Disaster Recovery Plans, Business Continuity Plans, and Incident Response Plans.
Technologies
- NIST Framework
- NIST 800-53
- NIST CSF
- Authority to Operate (ATO)
- System Security Plans (SSPs)
- Disaster Recovery Plans (DRPs)
- Plans of Action & Milestones (POA&Ms)
- Incident Response Plans
Experience requirements (required):
- NIST CSF, NIST 800-53: 5 years
- Disaster Recovery Plans (DRPs): 5 years
- Complex IT web Applications: 5 years
Job type: Contract