
IT Security & Compliance Analyst
Stafford Gray
Job description
We're looking for a Security & Compliance Analyst to support the security, compliance, and operational integrity of systems used in administering retirement benefits for public sector employees. This role partners with cross-departmental teams to strengthen security controls, improve business processes, and ensure secure, reliable service delivery. The ideal candidate brings hands-on experience with security/compliance frameworks in government, public retirement, or regulated financial environments, and is comfortable owning audit-ready documentation, risk assessments, and vulnerability management activities from end to end.
Key Responsibilities:
-
Analyze, document, and validate security processes and system requirements supporting retirement benefits administration
-
Define and refine security and compliance requirements for system enhancements and new initiatives alongside program offices and technical teams
-
Create and maintain audit-ready documentation โ security requirements, user stories, workflows, use cases
-
Support solution design and UAT to verify security controls are properly implemented
-
Monitor deliverables and timelines against security and compliance objectives
-
Conduct gap analyses on legislative/regulatory/policy changes and their operational impact
-
Perform data analysis and reporting to support compliance monitoring and risk tracking
-
Support security/standards reviews, risk assessments, and mitigation planning
-
Contribute to System Security Plans, Assessment Reports, and Authorization packages
-
Support Disaster Recovery and Business Continuity Planning, including business impact assessments and tabletop exercises
-
Coordinate vulnerability scans and support mitigation planning
-
Provide informal leadership and mentorship to fellow analysts on security frameworks and governance processes
Requirements
Minimum Qualifications:
-
7 years of professional experience in security, compliance, risk management, or a closely related discipline within a government agency, public retirement system, or regulated financial environment
-
Demonstrated experience developing, documenting, and evaluating security controls, compliance requirements, and governance processes
-
Experience supporting security/compliance assessments, audit activities, policy reviews, and control validations
-
Working knowledge of security/compliance frameworks relevant to public sector environments (e.g., NIST CSF, NIST 800-53)
-
Experience participating in system or process changes with a focus on data protection, access controls, and secure implementation
-
Knowledge of Agile SDLC with an emphasis on integrating security/compliance into requirements, testing, and release
-
Ability to assess common vulnerabilities (XSS, CSRF, SQL Injection, authentication weaknesses)
-
Proficiency with tools supporting security documentation, compliance tracking, and workflow management (e.g., Azure DevOps, GRC platforms)
-
Experience contributing to Disaster Recovery Plan development, documentation, and testing, including RTOs/RPOs
Preferred Qualifications:
-
Bachelor's degree in information security, cybersecurity, information systems, public administration, or related field (or equivalent experience)
-
Experience supporting security/compliance needs within public pension or retirement administration programs
-
Familiarity with security capabilities and data protection requirements within pension administration or enterprise benefits platforms
-
Experience with SQL or analytics tools (Power BI, advanced Excel) for compliance monitoring and reporting
-
Security/compliance certifications (CGRC, CAP, Security+, CISA, or similar)
-
Knowledge of federal/state regulations governing data security and privacy in public sector retirement systems (IRS, SSA, audit standards)
-
Familiarity with Java or .NET
-
High-level understanding of web application functioning