Cybersecurity Controls Analyst responsible for evaluating and implementing cybersecurity controls. Ensures university compliance with internal policies and external regulations while working on various systems and infrastructure.
Responsibilities
Develops, assesses and monitors cybersecurity controls across systems, applications, vendors and infrastructure
Conducts risk assessments, controls walkthroughs, and control gap analyses to identify vulnerabilities and recommend mitigation controls-based strategies
Collaborates with IT and business units to implement and validate security controls
Maintains documentation of control effectiveness and remediation efforts
Supports internal and external audits, including evidence collection and control walkthroughs
Ensures compliance with industry standards and regulations (e.g., NIST, CIS Controls, PCI-DSS, HIPAA, FERPA, GLBA)
Develops and maintains cybersecurity policies, procedures, and standards
Monitors regulatory changes and emerging threats to adjust control strategies accordingly
Assists in the development of security awareness and training programs
Performs other duties as assigned
Requirements
Bachelor’s degree in cybersecurity, information technology management, computer science, or a related discipline
Three years of experience in information technology, cybersecurity, IT audit, or risk management, preferably in an academic or research setting
Experience with controls development and control testing methodologies
Strong customer service orientation with the ability to communicate technical concepts to non-technical users
Proficiency with cybersecurity frameworks (e.g., NIST CSF, ISO 27001, COBIT) and compliance standards (e.g., HIPAA, PCI-DSS, GDPR)
Understanding of cybersecurity principles, particularly in regulated environments
Excellent documentation skills
Attention to detail
Strong analytical skills
Strong problem-solving skills
Strong organizational and time management skills
Ability to prioritize multiple tasks
Ability to work independently and collaboratively in a team-oriented environment
CIS Security Manager responsible for EID’s information security strategy and compliance. Ensuring protection of information assets and promoting security culture across the organization.
Cyber Security Subject Matter Expert at CACI supporting a new DoD contract. Working on cloud security with an emphasis on system security engineering and risk management.
Cybersecurity Engineer developing solutions for complex security challenges protecting data and networks. Implementing next generation security solutions for government and commercial clients in hands - on roles.
Information Security Manager responsible for security governance and risk management. Engaging with technical teams for compliance with security standards and best practices.
Security Access Control Specialist at AMERICAN SYSTEMS managing database queries, document processes, and security measures. Supporting federal government programs through effective security operations in McLean, VA.
Customer Support Coordinator delivering technical support for complex security solutions. Collaborating with internal teams and external stakeholders to resolve service incidents while ensuring high performance standards.
Site Security Specialist tasked with implementing security measures for client at Richmond site. Acting as point of contact for security team and client management.
Information Security Specialist responsible for developing ISMS under ISO 27001 and guiding audits. Collaborating closely with IT and management while ensuring compliance and documentation.
Senior Threat Detection & Response Engineer at ICF developing cyber analytic capabilities for federal cybersecurity. Engage in project design and countermeasure capabilities while collaborating with key stakeholders.