Date Posted: 09/04/2026
Hiring Organization: Rose International
Position Number: 506971
Industry: Government/Staffing
Job Title: Senior Security & Compliance Analyst GRC Risk NIST
Job Location: Lansing, MI, USA, 48933
Work Model: Hybrid
Work Model Details: On-site 2 days per week (Tue & Wed)
Shift: Mon-Fri 8:00 AM - 5:00 PM
Employment Type: Temporary
FT/PT: Full-Time
Estimated Duration (In months): 13
Min Hourly Rate($): 60.00
Max Hourly Rate($): 62.00
Must Have Skills/Attributes: Compliance, PowerBI, SQL, System Analysis
Experience Desired: Seven years of professional experience in security compliance risk management or a closely related (7+ yrs); Experience developing documenting and evaluating security controls compliance requirement (5+ yrs); Experience supporting security compliance assessments audit activities policy reviews and control (5+ yrs); Knowledge of security and compliance frameworks relevant to public sector environments such as NIST (5+ yrs); Knowledge of Agile SDLC practices with an emphasis on integrating security and compliance (5+ yrs); Ability to assess common vulnerabilities such as XSS CSRF SQL Injection & authentication weakness (5+ yrs); Support security documentation compliance tracking and workflow management (5+ yrs)
Preferred Education: Bachelor’s Degree
**C2C is not available**
 
Job Description
***Only qualified System Analyst 6 candidates located near the Lansing MI area to be considered due to the position requiring an onsite presence***
PREFERRED EDUCATION:
• Bachelor’s degree in information security cybersecurity information systems public administration or a related field; or equivalent experience
REQUIRED EXPERIENCE KNOWLEDGE ABILITIES AND SKILLS:
• Seven years of professional experience in security compliance risk management or a closely related discipline within a government agency public retirement system or regulated financial environment
• Demonstrated experience developing documenting and evaluating security controls compliance requirements and governance processes
• Experience supporting security or compliance assessments audit activities policy reviews and control validations
• Working knowledge of security and compliance frameworks relevant to public sector environments such as NIST CSF NIST 800 53 and state IT security standards (5+ years)
• Experience participating in system or process changes with a focus on ensuring data protection access controls regulatory adherence and secure implementation
• Knowledge of Agile SDLC practices with an emphasis on integrating security and compliance into requirements testing and release processes
• Ability to assess common vulnerabilities such as XSS CSRF SQL Injection and authentication weaknesses
• Proficiency in tools used to support security documentation compliance tracking and workflow management (eg Azure DevOps GRC platforms) (5+ years)
• Contribute to development documentation and testing of Disaster Recovery Plans (DRPs) for critical systems
• Assist in defining recovery time objectives (RTOs) and recovery point objectives (RPOs)
PREFERRED EXPERIENCE KNOWLEDGE ABILITIES AND SKILLS:
• Experience supporting security and compliance needs within public pension or retirement administration programs
• Working knowledge of security capabilities and data protection requirements within pension administration platforms or enterprise benefits systems
• Experience using SQL or analytics tools (Power BI advanced Excel) to support compliance monitoring security metrics reporting and data validation
• Professional security or compliance certifications such as CGRC CAP Security+ CISA or similar
• Knowledge of state and federal regulations governing data security privacy and compliance within public sector retirement systems (IRS SSA state statutes audit standards)
• Familiarity with Java or the NET framework
• High level understanding of how web applications function
The Security & Compliance Analyst supports the integrity, security, and compliance of systems and processes used in administering retirement benefits for public sector employees. This role ensures that technology solutions, operational practices, and policy implementations adhere to state regulations, security standards, and organizational governance requirements. The analyst will collaborate with cross departmental teams to strengthen security controls, improve business processes, and ensure consistent delivery of secure and reliable services to stakeholders and citizens.
JOB RESPONSIBILITIES:
• Analyze document and validate security processes system requirements and interagency interactions supporting retirement benefits administration
• Collaborate with program offices technical teams and subject matter experts to define and refine security and compliance requirements for system enhancements policy updates and new state initiatives
• Create and maintain clear audit ready documentation including security requirements user stories workflows and use cases aligned with public sector standards and oversight expectations
• Support solution design and participate in testing phases (eg UAT) to verify that security controls and compliance requirements are properly implemented
• Recommend improvements that strengthen security posture improve process efficiency and support program accountability and service quality
• Monitor project deliverables timelines and milestones to ensure alignment with organizational security objectives state compliance mandates and governance frameworks
• Assist in developing training materials and delivering security and compliance education to program staff and stakeholders
• Conduct gap analyses and assess impacts of legislative regulatory or policy changes on business operations and system security
• Perform data analysis and generate reports to support compliance monitoring performance evaluation risk tracking and data driven decision making across the organization
• Leadership & Collaboration Responsibilities
• Provide guidance and informal leadership to cross functional teams by promoting best practices in security compliance and risk management
• Lead discussions with program offices technology partners and stakeholders to ensure alignment on security objectives policy interpretations and compliance expectations
• Serve as a mentor to analysts by offering support in interpreting security frameworks documenting requirements and navigating governance processes
• Champion a culture of security awareness and continuous improvement by fostering collaboration communicating risks clearly and influencing adoption of secure and compliant operational behaviors
• Take ownership of key security and compliance initiatives driving progress managing expectations and ensuring deliverables meet organizational standards and regulatory requirements
• Provide leadership during security incidents compliance issues and audit activities by coordinating responses ensuring timely communication and supporting decision making with clear accurate analysis
• Security & Compliance Support
• Perform tasks in support of internal and external security and standards reviews
• Conduct security risk assessments and recommend mitigation strategies
• Assist with development and maintenance of security documentation including System Security Plans Assessment Reports and Authorization packages
• Support security audits by gathering documentation and demonstrating control effectiveness
• Disaster Recovery & Business Continuity Planning
• Collaborate with business units to develop and maintain Business Continuity Plans (BCPs)
• Conduct business impact assessments and ensure DRP/BCP strategies align with operational needs
• Participate in tabletop exercises and simulations to test and validate plans documenting and addressing gaps
• Ensure DRP/BCP efforts comply with State of Michigan policies NIST FISMA and other applicable standards
• Vulnerability Management
• Coordinate and schedule system application and network vulnerability scans in collaboration with infrastructure and security teams
• Analyze scan results prioritize risks and support mitigation planning - **Only those lawfully authorized to work in the designated country associated with the position will be considered.**
- **Please note that all Position start dates and duration are estimates and may be reduced or lengthened based upon a client’s business needs and requirements.**
 
Benefits:
For information and details on employment benefits offered with this position, please visit here. Should you have any questions/concerns, please contact our HR Department via our secure website.
California Pay Equity:
For information and details on pay equity laws in California, please visit the State of California Department of Industrial Relations' website here.
Rose International is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender (expression or identity), national origin, arrest and conviction records, disability, veteran status or any other characteristic protected by law. Positions located in San Francisco and Los Angeles, California will be administered in accordance with their respective Fair Chance Ordinances.
If you need assistance in completing this application, or during any phase of the application, interview, hiring, or employment process, whether due to a disability or otherwise, please contact our HR Department.
Rose International has an official agreement (ID #132522), effective June 30, 2008, with the U.S. Department of Homeland Security, U.S. Citizenship and Immigration Services, Employment Verification Program (E-Verify). (Posting required by OCGA 13/10-91.).
Rose International has been great to me. I thank everyone there for all of their hard work; it has not gone unnoticed.
Melody, Consultant
Rose International maintained good communication during assignments and are very informative through email and phone calls.
Sade, Consultant
As a contractor, I have to say that Rose International was by far the best agency I have worked for.
Q'testdalir, Consultant
I have been very pleased with my experience with Rose International. Everyone that I encountered was very helpful and courteous.
Stephanie, Consultant
Your team at Rose International is always very helpful and responsive.
Barbara, Consultant
EMPLOYEE COMMENTS