Custom Software Systems, Inc. (CSS) is seeking a mid-level Business Analyst to anchor compliance work and to bring the same analytical discipline to application development support. On the governance side, this means owning the documentation and coordination work that keeps clients’ system portfolio compliant: system security plans, ATO cycles, PIA reviews, data classification, and records obligations. On the application side, it means working alongside the development team to determine what applications should do — translating what program staff describes into structured requirements that developers can build against.
This IT section is small. Governance, business analysis, and project coordination are not
separate departments here — they are responsibilities the same small group shares fluidly. This
role will work directly with the economists, bank examiners, policy analysts, and attorneys
whose work both generates the compliance obligations and drives the application backlog. The
governance work and the application work are not as separate as they might appear: a PIA for a
new system and a requirements document for that same system draw on the same conversations.
Responsibilities
IT Governance and Compliance
system security plans (SSPs), security categorizations, and related artifacts.
working with the clients’ security and privacy offices through assessment and
authorization cycles.
collect, process, or maintain personally identifiable information.
agency reporting requirements.
management, and retention schedule compliance.
compliance functions on matters related to DCCA’s IT systems and application portfolio.
updated documentation or reassessment.
audits.
Business Analysis and Requirements
and attorneys — to elicit, refine, and document business requirements for new and
modified applications.
requirements, process diagrams, and functional specifications that the development
team can act on.
to support application design and, where applicable, governance activities.
manager, surfacing dependencies and tradeoffs early.
business users, and documenting outcomes.
reducing friction during discovery, design, and delivery.
This role will participate in QA activities — contributing test cases, supporting UAT coordination,
and helping verify that delivered applications meet business requirements — but does not serve
as a dedicated QA resource. Testing support is a component of the BA function here, not a
primary accountability.
Citizenship
· US Citizenship
Required Qualifications
security plans, security categorizations, and related assessment and authorization
artifacts.
process personally identifiable information.
800-53 and NIST SP 800-37.
documentation for security assessments.
management obligations.
including process flow diagrams, use cases, or functional specifications.
attorneys, and program staff — to develop requirements and designs; skill at uncovering
underlying business needs, which may require significant effort to surface.
Preferred Qualifications
supervisory, or policy-adjacent context.
frameworks.
business context (not development).
(e.g., CIPP, CISSP, CRM, or equivalent) is a plus but not required.
Work Environment & Schedule
(approximately 6–8 weeks).
This job description reflects current program needs and may evolve as modernization efforts
progress.
[1] Compensation range must be coordinated with and approved by the CSS Chief Operating Officer (COO).
[2] Compensation & Benefits information is required for all Maryland Employers effective October 1, 2024.