Business Analyst
Stellar Professionals
We are seeking a senior Security & Compliance Analyst (System Analyst 6) to support the Office of Retirement Services (ORS) within the State of Michigan's Agency Services. This role ensures the security, integrity, and regulatory compliance of IT systems used to administer public sector retirement benefits, leading risk assessments, Disaster Recovery/Business Continuity Planning (DRP/BCP), vulnerability management, and audit readiness aligned with public sector security standards.
-
Client: State of Michigan Agency Services / Office of Retirement Services (ORS)
-
Location: Lansing, MI 48933 (530 West Allegan Street)
-
Work Arrangement: Hybrid (2 days onsite per week: Tuesdays & Wednesdays; local candidates within 75 miles preferred or willing to relocate within 2 weeks of start date at candidate's own expense)
-
Role Type: Contract (10/12/2026 10/12/2027, 1-year contract with extension potential)
-
Interview Process: In-Person Interview in Lansing, MI
-
Security & Compliance Governance: Ensure IT systems, user stories, and technical requirements comply with NIST CSF, NIST SP 800-53, FISMA, and State of Michigan IT security standards.
-
Audit & System Security Documentation: Author and maintain audit-ready documentation, including System Security Plans (SSPs), Assessment Reports, Authorization Packages, and GRC workflow tracking in Azure DevOps.
-
Disaster Recovery & Business Continuity: Lead the development, testing, and tabletop exercise execution for Business Continuity Plans (BCPs) and Disaster Recovery Plans (DRPs); assist in defining RTOs and RPOs for critical retirement systems.
-
Vulnerability & Risk Assessments: Coordinate system, network, and application vulnerability scans; analyze scan reports for common web application weaknesses (e.g., XSS, CSRF, SQL Injection) and drive risk mitigation planning.
-
Incident & Audit Leadership: Lead cross-functional responses during security incidents, external audit reviews, and legislative changes impacting pension/retirement system data security and privacy.
-
Public Sector Security Frameworks: 5+ years of hands-on experience working with NIST CSF, NIST SP 800-53, and state/federal IT security standards.
-
Security Documentation & GRC Tools: 5+ years of experience utilizing Azure DevOps or Enterprise GRC platforms for compliance tracking, user story definition, and security workflow management.
-
Disaster Recovery Planning (DRP): 5+ years contributing to the design, documentation, testing, and validation of system DRPs and BCPs.
-
RTO & RPO Definition: 5+ years of experience establishing and evaluating Recovery Time Objectives and Recovery Point Objectives for mission-critical IT applications.
-
Professional Experience: 7+ years in IT security, compliance, risk management, or governance within a government agency, public retirement system, or regulated financial institution.
-
Education & Certifications: Bachelor's degree in Cybersecurity, Information Systems, Public Administration, or a related field; professional certifications such as CGRC, CAP, Security+, or CISA.
-
Technical Skills: Experience with SQL, Power BI, or advanced Excel for compliance reporting, alongside familiarity with public pension systems or .NET/Java web architectures.
-
Background: Prior government or military experience.
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Business Analyst. Be the first to apply!
- deloitte business technology analyst Lansing, MI
- business analyst law firm Lansing, MI
- knowledge management analyst Lansing, MI
- pega business analyst Lansing, MI
- business development analyst Lansing, MI
- business analyst Lansing, MI
- software asset management analyst Lansing, MI
- public sector business analyst Lansing, MI
- business analyst part time remote Lansing, MI
- business strategy analyst Lansing, MI
