Stafford Gray LLC
Stafford Gray LLC
„Stafford Gray LLC“ yra Mičigane įsikūrusi IT konsultacijų įmonė, padedanti viešojo ir privataus sektoriaus organizacijoms modernizuoti technologijas ir gerinti veiklos rezultatus. 2020 m. įkurta įmonė dirba skaitmeninės transformacijos, IT valdymo, kibernetinio saugumo ir projektų įgyvendinimo srityse. Jos paslaugos apima duomenų analizę, dirbtinį intelektą, automatizavimą, debesijos paslaugas ir valdomąją IT pagalbą. Įmonė orientuojasi į praktiškus, konkretiems klientų poreikiams pritaikytus sprendimus, skirtus didinti efektyvumą, skatinti inovacijas ir siekti išmatuojamų verslo rezultatų.

Senior IT Security Compliance Analyst (Hybrid, Michigan)

Lead IT security compliance for public-sector applications through NIST controls, System Security Plans and three-year ATO renewals. Oversee risk management, incident response, remediation and compliance reporting.

Aprašymas

  • Maintain and update System Security Plans (SSPs) for accuracy, completeness and alignment with NIST controls
  • Manage three-year ATO renewal cycles, including preparation, scheduling, approval and continuous compliance
  • Validate security controls throughout authorization periods and oversee remediation of identified gaps
  • Track Plans of Action & Milestones (POA&Ms) and related compliance obligations through resolution
  • Evaluate risk assessment findings, brief management and recommend corrective actions
  • Assess major security incidents, lead medium- to high-severity response efforts and support detection, recovery and containment
  • Produce metrics-driven management reports and trend analyses across multiple business areas
  • Develop and maintain Disaster Recovery Plans and support business continuity and incident response planning
  • Identify weaknesses in compliance documentation and promote consistent practices across supported systems
  • Partner with technical teams, business owners and security personnel to keep SSP and ATO evidence complete and current
  • Collaborate with business owners, technical teams, enterprise security, vendors, auditors and project managers
  • Coach and mentor fellow analysts

Reikalavimai

  • At least five years providing audit evidence for standards such as NIST, PCI, HIPAA or FERPA
  • At least five years working with complex IT web applications
  • At least five years leading meetings and delivering written and verbal reports
  • At least five years serving as a liaison between business and IT teams
  • Strong working knowledge of the NIST framework and its controls
  • Excellent writing and documentation abilities
  • Bachelor’s degree in cybersecurity, information assurance, business analytics or an IT-related field, or five years of equivalent experience
  • Two or more years creating documentation for IT system audits preferred
  • Two or more years developing Disaster Recovery, Business Continuity or Incident Response Plans preferred
  • Master’s degree in cybersecurity, information assurance or IT leadership, or an MBA with an IT or security concentration preferred
  • CISSP, CGRC (formerly CAP), CISA or CISM certification preferred

Susiję darbai

EY

AI Software Engineer, Financial Advisory

EY

Build and deploy GenAI, LLM, and MLOps solutions for EY financial advisory clients across the Middle East and North Africa. Contribute to AI strategy, production delivery, and business development.

Atidaryti
Maxibook OÜ

Scientific Language and AI Adaptation Contributor

Maxibook OÜ

Help Maxibook, an AI education startup, adapt English scientific content for Korean, Japanese, or Arabic audiences. Assess AI-generated material for accurate concepts, natural language, and academic credibility.

Atidaryti