Security IT Business Analyst - deadline 9/1
Tier4 Group
Quincy
Posted August 26, 2026
Description
<h3>Job Description</h3><div>Job Description<div><p>Our client's Chief Information Security Officer’s (CISO) Office is seeking to hire a highly motivated and detail-oriented Security IT Business Analyst to support the development, documentation, and improvement of security operational processes and governance activities.</p><p>This role requires excellent writing and analytical skills, with a focus on documenting security policies, procedures, workflows, and processes. The successful candidate will work closely with members of the CISO’s Office, IT teams, and agency stakeholders to analyze existing security practices, identify process gaps, and translate informal or undocumented procedures into clear, structured documentation.</p><p>Strong analytical, communication, and presentation skills are critical, as the role requires gathering information from technical subject matter experts and transforming it into documentation and artifacts that support operational consistency, audit readiness, and strategic decision-making</p><p>The work schedule for this position is Monday thru Friday, 8:00AM to 4:00PM EST. This position is expected to follow a hybrid reporting model that combines in-office workdays and work-from-home days as needed. The Security IT Business Analyst is expected to occasionally travel to area offices within Massachusetts as needed.</p><p>DETAILED LIST OF JOB DUTIES AND RESPONSIBILITIES:</p><ul><li>Policies, standards, procedures, standard operating procedures (SOPs), playbooks, runbooks, workflows, swim lane diagrams, and process guides.</li><li>Analyze and document current-state security processes through interviews, observation, and analysis to identify gaps, inefficiencies, risks, and opportunities for improvement.</li><li>Support security governance, compliance activities, and audit readiness by ensuring documentation is complete, accurate, and aligned with State, federal, and industry security frameworks.</li><li>Facilitate collaboration between the CISO’s Office, IT teams, agency stakeholders, and external partners to ensure security processes are clearly defined, understood, and consistently implemented</li><li>Prepare reports, presentations, process documentation artifacts, and dashboards to track security initiatives and communicate progress to stakeholders and leadership.</li><li>Assist in developing security training, documentation, and communications that promote adoption of security policies and best practices.</li><li>Develop future-state process documentation and operational roadmaps that support improvements in security operations maturity and effectiveness.</li><li>Contribute to the planning, tracking, and monitoring of security projects and initiatives to ensure timely delivery and alignment with security strategy and operational priorities.</li><li>Manage and document risks, issues, and decisions related to security policies, operational processes, and improvement initiatives within the CISO’s Office.</li><li>Participate in security reviews and assessments and document findings, process gaps, and recommended remediation steps.</li><li>Serve as a resource for gathering, analyzing, and documenting requirements for security initiatives, tools, operational processes, and documentation artifacts.</li><li>Provide clear, structured, and auditable documentation that supports decision-making, operational consistency, audit response, and process improvement initiatives.</li><li>Translate informal or undocumented security practices into repeatable, documented processes that improve operational consistency and accountability.</li><li>Perform other related duties as assigned to support the mission of the CISO’s Office and the continuous improvement of security operations processes.</li></ul><p>Preferred Qualifications:</p><p>5–8 years of experience in information technology or cybersecurity, with at least 3 years in a business analyst, process analyst, technical writer, security analyst, or related role. <br /> Strong understanding of information security concepts, frameworks, and best practices including:</p><ul><li>National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)</li><li>Center for Internet Security Controls (CIS Controls)</li><li>ISO/IEC 27001</li></ul></div></div>
Job Overview
Location
Quincy
Job Type
full time
Date Posted
August 26, 2026