Job Description
Under the guidance of the Senior IT Compliance Manager, the IT Risk and Compliance Analyst will carry out IT security assessment activities including IT risk assessments and security reviews for university departments, as well as evaluations of third-party technology solutions, to ensure alignment with university policies, standards, and external compliance regulations wherever applicable. Assessment activities may include a wide variety of tasks depending on the scope of the review and the IT capabilities within university departments (e.g. developing asset inventory, assessing endpoint and application security controls and configurations, examining procedures, etc.)
The analyst will be expected to make contributions to the creation and maintenance of documentation/procedures in support of the IT Risk and Compliance program, and should identify opportunities for leveraging automation to support data consistency and process efficiencies within the program and as it relates to other university IT services. The analyst may provide training and outreach to the university community as needed and may also be called upon to coordinate updates for the IT Continuity of Operations plan and to assist units within the Division of Information Technology as they conduct disaster recovery planning or on other security-related initiatives as requested.
Required Qualifications
• Bachelor’s degree in business, information technology, accounting, or a related field; or equivalent combination of education, training, and experience
• Demonstrated experience performing IT security reviews, risk assessments, or audits
• Strong understanding of key information security concepts and fundamentals
• Experience in creating awareness of security practices across multiple technical teams
• Knowledge of security frameworks and standards including NIST, PCI-DSS, ISO 27001, CIS Critical Security Controls, etc.
• Ability to effectively communicate across a broad range of campus audiences
• Exceptional organizational and time-management skills
Preferred Qualifications
• Advanced degree in a related field
• Professional certification such as CISA, CISM, CRISC, or CISSP
• Experience performing security assessment of SaaS services
• Knowledgeable of relevant compliance regulations (e.g. FERPA, GLBA)
• Experience with GRC and Information security tools/technologies to collect and maintain security and risk information
• Experience with automation using common scripting tools (e.g. Python, PowerShell, Bash, etc.)
• Experience with data analysis and manipulation
• Experience managing IT security risk or compliance in a higher education setting
Appointment Type
Regular
Salary Information
$80,000 - $90,000
Review Date
10/10/2022
Additional Information
The successful candidate will be required to have a criminal conviction check.
About Virginia Tech
Dedicated to its motto, Ut Prosim (That I May Serve), Virginia Tech pushes the boundaries of knowledge by taking a hands-on, transdisciplinary approach to preparing scholars to be leaders and problem-solvers. A comprehensive land-grant institution that enhances the quality of life in Virginia and throughout the world, Virginia Tech is an inclusive community dedicated to knowledge, discovery, and creativity. The university offers more than 280 majors to a diverse enrollment of more than 36,000 undergraduate, graduate, and professional students in eight undergraduate colleges, a school of medicine, a veterinary medicine college, Graduate School, and Honors College. The university has a significant presence across Virginia, including the Innovation Campus in Northern Virginia; the Health Sciences and Technology Campus in Roanoke; sites in Newport News and Richmond; and numerous Extension offices and research centers. A leading global research institution, Virginia Tech conducts more than $500 million in research annually.
Virginia Tech does not discriminate against employees, students, or applicants on the basis of age, color, disability, sex (including pregnancy), gender, gender identity, gender expression, genetic information, national origin, political affiliation, race, religion, sexual orientation, or military status, or otherwise discriminate against employees or applicants who inquire about, discuss, or disclose their compensation or the compensation of other employees or applicants, or on any other basis protected by law.
If you are an individual with a disability and desire an accommodation, please contact Brittany Kessler at bmlester@vt.edu during regular business hours at least 10 business days prior to the event.
Each agency within the Commonwealth of Virginia is dedicated to recruiting, supporting, and maintaining a competent and diverse work force. Equal Opportunity Employer
Thank you
Thank you for sharing this job
This website uses cookies.
“Cookies” are small files either stored on a server or sent back to a visiting computer. In certain applications user information is stored as cookies, which are then sent back to and stored on the user’s computer. Some sections of the website use cookies to customize the information presented to you. Cookies are also used to aggregate site usage information to help us improve our users’ experience.
Please see our Privacy Policy.
It is the policy of the Commonwealth of Virginia to prohibit discrimination on the basis of race, sex, color, national origin, religion, sexual orientation, gender identity, age, veteran status, political affiliation, genetics, or disability in the recruitment, selection, and hiring of its workforce.
Virginia uses E-Verify to check employee eligibility to work in the United States. You will be required to complete an I-9 form and provide documentation of your identity for employment purposes. To check your current eligibility visit Self Check.
If you need accommodations as an applicant, please contact the Human Resources Office of the hiring agency directly for more information.
For questions, please contact us at: applicantinquiry@dhrm.virginia.gov