Security Compliance Analyst in Lansing, Michigan at Michigan Farm Bureau
Explore Related Opportunities
Job Description
To support the maintenance and execution of the security compliance operations for the Michigan Farm Bureau Family of Companies, ensuring compliance with regulatory requirements, industry standards, and internal security policies. To work closely with the Security Compliance Specialist and partners with Information Security, Identity & Access Management, Infrastructure, Application Development, Risk Management, Internal and External Auditors, Legal, and business stakeholders to promote effective security compliance practices across the organization. To perform day-to-day compliance activities, configures and maintains compliance settings within the Microsoft Security Suite, maintains accurate documentation, researches requirements, monitors security controls, assists with the identifying and remediating compliance gaps and supports the IT Model Audit Rule (MAR) Control Owner and IT Enterprise Risk Management (ERM) Risk Owner by gathering control evidence, tracking remediation activities, and preparing audit responses.
Manage the third-party risk assessment process, including intake of new vendor requests, distribution and evaluation of security questionnaires, collection and review of SOC reports and attestations, and documentation of assessment outcomes and residual risk.
Conduct security reviews of vendor contracts, service level agreements, and technology integrations, identifying gaps against organizational security requirements and escalating exceptions for review.
Maintain the vendor inventory and risk register, tracking assessment status, reassessment schedules, contract renewal dates, and outstanding vendor remediation commitments.
Monitor ongoing vendor compliance obligations, including annual attestations, subcontractor changes, and vendor security incidents affecting Michigan Farm Bureau data or services.
Required
Bachelor's degree in computer science or related field required, or equivalent experience may be considered.
Minimum of three to five years of experience in Information Security Compliance, IT Audit or Governance, Risk and Compliance (GRC) roles required.
Ability to communicate well with all levels of the organization including end users, technical personnel, and management required.
Certification in CISSP (Certificated Information Systems Security Professional), CISA (Certified Information Systems Auditor), CISM(Certified Information Security Manager), or related security/audit certifications preferred, or ability to obtain relevant certification within 24 of hire.
Note: Farm Bureau offers a full benefit package including medical, dental, vision, and 401K.
PM19