Über diese IT Security & Compliance Analyst Stelle bei Stafford Gray
We're looking for a Security & Compliance Analyst to support the security, compliance, and operational integrity of systems used in administering retirement benefits for public sector employees. This role partners with cross-departmental teams to strengthen security controls, improve business processes, and ensure secure, reliable service delivery. The ideal candidate brings hands-on experience with security/compliance frameworks in government, public retirement, or regulated financial environments, and is comfortable owning audit-ready documentation, risk assessments, and vulnerability management activities from end to end.
Key Responsibilities:
- Analyze, document, and validate security processes and system requirements supporting retirement benefits administration
- Define and refine security and compliance requirements for system enhancements and new initiatives alongside program offices and technical teams
- Create and maintain audit-ready documentation — security requirements, user stories, workflows, use cases
- Support solution design and UAT to verify security controls are properly implemented
- Monitor deliverables and timelines against security and compliance objectives
- Conduct gap analyses on legislative/regulatory/policy changes and their operational impact
- Perform data analysis and reporting to support compliance monitoring and risk tracking
- Support security/standards reviews, risk assessments, and mitigation planning
- Contribute to System Security Plans, Assessment Reports, and Authorization packages
- Support Disaster Recovery and Business Continuity Planning, including business impact assessments and tabletop exercises
- Coordinate vulnerability scans and support mitigation planning
- Provide informal leadership and mentorship to fellow analysts on security frameworks and governance processes
Requirements
Minimum Qualifications:
- 7 years of professional experience in security, compliance, risk management, or a closely related discipline within a government agency, public retirement system, or regulated financial environment
- Demonstrated experience developing, documenting, and evaluating security controls, compliance requirements, and governance processes
- Experience supporting security/compliance assessments, audit activities, policy reviews, and control validations
- Working knowledge of security/compliance frameworks relevant to public sector environments (e.g., NIST CSF, NIST 800-53)
- Experience participating in system or process changes with a focus on data protection, access controls, and secure implementation
- Knowledge of Agile SDLC with an emphasis on integrating security/compliance into requirements, testing, and release
- Ability to assess common vulnerabilities (XSS, CSRF, SQL Injection, authentication weaknesses)
- Proficiency with tools supporting security documentation, compliance tracking, and workflow management (e.g., Azure DevOps, GRC platforms)
- Experience contributing to Disaster Recovery Plan development, documentation, and testing, including RTOs/RPOs
Preferred Qualifications:
- Bachelor's degree in information security, cybersecurity, information systems, public administration, or related field (or equivalent experience)
- Experience supporting security/compliance needs within public pension or retirement administration programs
- Familiarity with security capabilities and data protection requirements within pension administration or enterprise benefits platforms
- Experience with SQL or analytics tools (Power BI, advanced Excel) for compliance monitoring and reporting
- Security/compliance certifications (CGRC, CAP, Security+, CISA, or similar)
- Knowledge of federal/state regulations governing data security and privacy in public sector retirement systems (IRS, SSA, audit standards)
- Familiarity with Java or .NET
- High-level understanding of web application functioning