Information Security Risk and Compliance Analyst

Virginia Information Technologies Agency•Richmond, VA
•$85,000 - $110,000•Hybrid

About The Position

The Virginia Department of the Treasury is dedicated to serving the Commonwealth by providing excellent management of its banking, investing, and financing services, and the administration of unclaimed property and insurance programs. We are seeking a motivated and detail-oriented Information Security Risk and Compliance Analyst to support the agency’s cybersecurity and risk management operations. This position plays a critical role in protecting the Commonwealth’s financial systems, sensitive data, and technology infrastructure. This is a mid-level role designed for someone who is building their cybersecurity career and has experience in compliance and risk management within a government environment.

Requirements

  • Understanding of cybersecurity principles, including: Network security fundamentals, Access control concepts, Malware and phishing threats, Incident response basics
  • Knowledge of NIST security frameworks and compliance standards
  • Experience developing System Security Plans in accordance with SEC 530 Standard or similar
  • Excellent written communication skills.
  • Strong analytical and problem-solving skills.
  • Ability to document findings clearly and concisely.
  • Strong attention to detail and organizational skills.
  • Ability to handle sensitive and confidential information appropriately.
  • Experience working with development teams to develop and execute application security test plans.
  • Strong understanding of Role-Based Access Control (RBAC), Least Privilege Principles, and Segregation of Duties.
  • Familiarity with Multi-Factor Authentication (MFA) and Single Sign-On (SSO) technologies.

Nice To Haves

  • Familiarity with common Governance, Risk, and Compliance security tools such as Archer.
  • Experience in Information Security, Identity and Access Management (IAM)
  • Experience in monitoring third-party risk.
  • Familiarity with cloud environments (AWS, Azure, GCP) and their access control mechanisms.
  • Experience working in a government or highly regulated environment

Responsibilities

  • Create and maintain System Security Plans
  • Define security acceptance criteria that align with business requirements and security policies
  • Document requirements for test environment and test accounts
  • Develop and document test cases
  • Execute security related test cases
  • Support multi-factor authentication (MFA) and other identity verification mechanisms to strengthen access security.
  • Develop, implement, and manage security awareness programs to educate employees on cybersecurity best practices.
  • Create training materials, presentations, and campaigns that effectively communicate security policies and procedures.
  • Analyze training metrics and reporting to identify gaps and continuously improve program effectiveness.
  • Maintain familiarity with emerging threats and trends to keep awareness content current and relevant.
  • Manage Treasury’s annual training campaign to ensure compliance with SEC 527 and other relevant Commonwealth Standards.
  • Identify threats and vulnerabilities
  • Create and maintain risk assessments
  • Manage Archer and other applicable risk registers
  • Track remediation activities and corrective action plans
  • Verify alignment with Commonwealth of Virginia Information Security, NIST, and other applicable Standards
  • Coordinate internal and external compliance audits
  • Build and update security policies and procedures
  • Maintain security documentation
  • Develop reports and dashboards for leadership as requested

Benefits

  • The Department of the Treasury telework policy allows for up to two days a week of telework, subject to the position requirements.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service