Information Security Control Assurance Analyst

Posted 13hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Information security analyst assuring controls, audits, and compliance for Southern New Hampshire University. Managing risk assessments, SSPs, POA&Ms, audits, and governance reporting remotely.

Responsibilities:

  • Lead and perform information security risk and compliance assessments across University systems and services
  • Develop, maintain, and review System Security Plans, risk assessments, and supporting documentation
  • Identify control gaps and security deficiencies, assess risk, and document actionable recommendations
  • Manage Plans of Action and Milestones, including tracking remediation, validating corrective actions, and reporting progress
  • Coordinate and support internal and external audits and assessments
  • Monitor and interpret changes in federal and state information security and data privacy requirements
  • Develop and maintain information security policies, standards, procedures, and governance documentation
  • Partner with ISMO, Privacy, Legal, and business stakeholders to implement controls and processes
  • Prepare and deliver compliance, risk, and audit reporting to management and leadership
  • Contribute to continuous improvement of information security governance, risk management, and compliance programs

Requirements:

  • 3 years of experience in a related field
  • Completion of a Bachelor's Degree or working toward a degree in a related field
  • Equivalent of experience in lieu of degree acceptable
  • Understanding of technical, administrative, and physical information security controls
  • Knowledge of information security governance, risk management, and compliance principles
  • Working knowledge of NIST frameworks and standards, including NIST SP 800-53, 800-171, and the Risk Management Framework
  • Familiarity with federal and state regulatory requirements and higher education compliance obligations, including GLBA, FERPA, and Simplified FAFSA Act
  • Advanced understanding of information security policies, standards, procedures, and governance documentation
  • Experience supporting internal and external audits
  • Ability to translate complex regulatory and technical security requirements into practical controls and processes
  • Working understanding of IT service management concepts and best practices, such as ITIL

Benefits:

  • High-quality, low-deductible medical insurance
  • Low to no-cost dental and vision plans
  • 5 weeks of paid time off
  • Almost a dozen paid holidays
  • Employer-funded retirement
  • Free tuition program
  • Parental leave
  • Mental health and wellbeing resources
  • 100% remote work from an approved state
  • Reliable internet connection and dedicated, properly equipped workspace