Information Security Analyst (Hybrid)

Posted Yesterday
Be an Early Applicant
Richmond, VA, USA
Hybrid
Mid level
Information Technology
The Role
Supports information security and privacy initiatives across programs, projects, systems, applications, and vendor engagements. Maintains GRC records, security policies, standards, procedures, system security plans, controls documentation, risk assessments, and security diagrams. Participates in PMO projects, reviews contracts for security protections, supports compliance efforts, and communicates security requirements to business stakeholders. Requires at least three years of information security GRC experience and familiarity with NIST, ISO 27001, or COBIT.
Summary Generated by Built In

Title: Information Security Analyst
LocationHybrid in Richmond, VA (2~3 days onsite)
Term: 2 Years Contract
Available for W2 or 1099, No C2C
Job Description:

This important role will support information security across all Virginia Housing programs, projects, IT systems, and applications. The position is assigned to projects and initiatives with security and privacy components. The Information Security Analyst will assist in conducting cybersecurity and privacy awareness throughout Virginia Housing and help create and maintain the organization’s Information Security and privacy policies. Additionally, the Information Security Analyst will collaborate with the Information Security Office (ISO) on various security-related projects.

Key Responsibilities:
  • Participate in Information Security and Privacy efforts across all business areas and vendor engagements to ensure that appropriate security controls are in place and adhered to by all parties.
  • Work within a Governance, Risk, and Compliance (GRC) system to add and update information security records and documentation.
  • Partner with business stakeholders to develop and maintain Information System Security Plans (SSP).
  • Represent the Information Security Office in PMO-led projects to ensure significant projects have appropriate ISO representation.
  • Collaborate across teams to understand business challenges, develop tailored solutions that provide value, facilitate compliance, and ensure clear communication.
  • Assist in the development and maintenance of information security standards and processes, including conducting research as needed.
  • Assist with controls documentation, including information system diagramming, populating risk assessment templates, and drafting control narrative documentation for business approval.
  • Review contracts, agreements, and vendor documentation to ensure adequate information security protections are in place.
Required Qualifications:
  • At least 3 years of demonstrated experience in Information Security concepts related to governance, risk, and compliance.
  • Extensive knowledge of information security principles and practices.
  • Deep understanding of methods applied to information technology infrastructure planning, implementation, and management.
  • Strong organizational skills with the ability to set priorities, meet established deadlines, and follow up on assignments with minimal supervision.
  • Familiarity or experience with security frameworks such as NIST, ISO 27001, or COBIT.
  • Excellent attention to detail and organizational skills.
  • Ability to adapt to changing situations and prioritize tasks as needed.
  • Experience drafting Information Security and Privacy policies, standards, and procedures.
  • Ability to interpret security documentation, including flow diagrams and process maps.
  • Knowledge of contract terms and conditions.
  • Proficiency in creating diagrams, flowcharts, and spreadsheets using desktop software.
  • Strong written communication skills with the ability to convey complex security concepts to various audiences.
Preferred Qualifications:
  • Bachelor's degree in Computer Science, Information Systems, or equivalent.
  • Relevant security certifications such as CISA, CISSP, or an equivalent certification.
  • Previous experience in the financial services industry is preferred.
  • Knowledge of controls related to cloud security and application security.
  • Knowledge of Information Security regulatory compliance (e.g., GLBA, GDPR, PCI, etc.).
  • Familiarity with various privacy regulations (e.g., GDPR, CCPA, VCDPA).

Thanks for applying!

Skills Required

  • At least 3 years of experience with information security concepts related to governance, risk, and compliance
  • Extensive knowledge of information security principles and practices
  • Understanding of information technology infrastructure planning, implementation, and management
  • Strong organizational skills and ability to meet deadlines with minimal supervision
  • Familiarity or experience with NIST, ISO 27001, or COBIT security frameworks
  • Experience drafting information security and privacy policies, standards, and procedures
  • Ability to interpret security documentation, flow diagrams, and process maps
  • Knowledge of contract terms and conditions
  • Proficiency creating diagrams, flowcharts, and spreadsheets using desktop software
  • Strong written communication skills for explaining complex security concepts
  • Bachelor's degree in Computer Science, Information Systems, or equivalent
  • CISA, CISSP, or equivalent security certification
  • Experience in the financial services industry
  • Knowledge of cloud security and application security controls
  • Knowledge of information security regulatory compliance, including GLBA, GDPR, or PCI
  • Familiarity with privacy regulations, including GDPR, CCPA, or VCDPA
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Luanda
27 Employees
Year Founded: 2018

What We Do

The ASCENDING team commits to delivering scalable and high-available cloud solutions to clients. We use advanced technology to measure the effectiveness of your current IT infrastructure. Then we help our clients migrate to the cloud and modernize their IT infrastructure.

Similar Jobs

Mastercard Logo Mastercard

Consultant

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Arlington, VA, USA
38800 Employees
104K-177K Annually

Mastercard Logo Mastercard

Software Engineer

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Arlington, VA, USA
38800 Employees
106K-169K Annually

Mastercard Logo Mastercard

Senior Software Engineer

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Arlington, VA, USA
38800 Employees
132K-212K Annually

Dynatrace Logo Dynatrace

Artificial Intelligence Engineer

Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
Remote or Hybrid
United States
5600 Employees
160K-180K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account