Virginia Tech-posted 2 months ago
$78,000 - $95,000/Yr
Full-time • Mid Level
Blacksburg, VA
Educational Services

Under the guidance of the Associate Director of Risk and Compliance, the IT Risk and Compliance Analyst will carry out IT security assessment activities including IT risk assessments and security reviews for university departments, as well as evaluations of third-party technology solutions, to ensure alignment with university policies, standards, and external compliance regulations wherever applicable. Assessment activities may include a wide variety of tasks depending on the scope of the review and the IT capabilities within university departments (e.g. developing asset inventory, assessing endpoint and application security controls and configurations, examining procedures, etc.) The analyst will be expected to make contributions to the creation and maintenance of documentation/procedures in support of the IT Risk and Compliance program, and should identify opportunities for leveraging automation to support data consistency and process efficiencies within the program and as it relates to other university IT services. The analyst may provide training and outreach to the university community as needed and may also be called upon to coordinate updates for the IT Continuity of Operations plan and to assist units within the Division of Information Technology as they conduct disaster recovery planning or on other security-related initiatives as requested.

  • Carry out IT security assessment activities including IT risk assessments and security reviews for university departments.
  • Evaluate third-party technology solutions for compliance with university policies and external regulations.
  • Develop asset inventory and assess endpoint and application security controls.
  • Create and maintain documentation/procedures for the IT Risk and Compliance program.
  • Identify opportunities for automation to enhance data consistency and process efficiencies.
  • Provide training and outreach to the university community.
  • Coordinate updates for the IT Continuity of Operations plan.
  • Assist with disaster recovery planning and other security-related initiatives.
  • Master's degree in business, information technology, accounting, or a related field; or equivalent combination of education, training, and experience.
  • Demonstrated experience performing IT security reviews, risk assessments, or audits.
  • Strong understanding of key information security concepts and fundamentals.
  • Experience in creating awareness of security practices across multiple technical teams.
  • Knowledge of security frameworks and standards including NIST, PCI-DSS, ISO 27001, CIS Critical Security Controls, NIST Cybersecurity Framework (NIST CSF).
  • Ability to effectively communicate across a broad range of campus audiences.
  • Exceptional organizational and time-management skills.
  • Professional certification such as CISA, CISM, CRISC, or CISSP.
  • Experience performing security assessment of SaaS services.
  • Knowledgeable of relevant compliance regulations (e.g. FERPA, GLBA).
  • Experience with GRC and Information security tools/technologies.
  • Experience with automation using common scripting tools (e.g. Python, PowerShell, Bash).
  • Experience with data analysis and manipulation.
  • Experience managing IT security risk or compliance in a higher education setting.
  • Professional development opportunities.
  • Inclusive community dedicated to knowledge, discovery, and creativity.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service