IT Policy and Compliance Analyst

James Madison UniversityHarrisonburg, VA
Hybrid

About The Position

James Madison University is accepting applications for an Information Technology Policy and Compliance Analyst to provide support for Information Technology's Third-Party Vendor Management Program. The successful candidate will assist IT in ensuring compliance with applicable information technology regulations, policies, and standards. This position is eligible for a hybrid work schedule.

Requirements

  • Demonstrated knowledge or experience in computer science, information technology, technical writing, business administration, or related field.
  • Experience with information technology vendor risk assessment or vendor compliance.
  • Strong security awareness and experience interpreting technical information, especially related to information technology best practices.
  • Excellent writing skills, with the ability to create clear requirements, specifications, and documentation.
  • Ability to effectively communicate, verbally and in writing, complex, technical information to both technical and non-technical audiences.
  • Exceptional organization, time management, and prioritization skills.
  • Ability to work independently with limited supervision as well as in teams.
  • Detail-oriented and able to work with a high degree of accuracy.
  • Proficient with Microsoft Excel, Word, SharePoint, and Teams.

Nice To Haves

  • Familiarity with requirements related to information technology regulations and standards including GLBA, PCI, ISO 27001 and 27002, HIPAA, HITECH, GDPR, Title II, AI governance, etc.
  • Experience analyzing SOC 2 or other independent security audit reports that attest to a vendor’s security policies, procedures, and controls.
  • Experience with information technology policies and procedures.
  • Experience with language and terms used in contracts, licenses, and other legal documents related to information technology.
  • Experience with supporting security awareness and other compliance training programs.

Responsibilities

  • Prepare information security operations reviews of on-premises and cloud-based IT systems and services to ensure alignment with university polices and compliance regulations.
  • Perform annual reviews of existing systems to ensure continued information security compliance.
  • Analyze SOC 2 or other independent security audit reports that attest to a vendor’s security policies, procedures, and controls.
  • Provide assistance with IT’s Third-Party Vendor Management Program by serving as a member of the Technology Review Board.
  • Educate and provide guidance to key partners related to JMU’s information technology risk management requirements.
  • Assist with the administration of IT’s security awareness and compliance training program.
  • Ensure information technology compliance records are organized and complete in accordance with applicable regulations, policies, standards, and best practices.
  • Demonstrate honesty, integrity, and confidentiality in the handling of university and vendor data.

Benefits

  • Paid vacation
  • Sick leave
  • Parental leave
  • Community service leave
  • 19 paid holidays annually
  • High-quality health insurance options
  • Retirement benefits through the Virginia Retirement System
  • Balanced Dukes program (wellness and work-life integration)
  • Tuition waiver program for undergraduate and graduate courses taken at JMU
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service