Information Security Analyst (Hybrid)

ASCENDING

Richmond (VA)

Hybrid

USD 85,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

ASCENDING in Richmond, VA is seeking an Information Security Analyst for a 2-year contract. The role is hybrid in Richmond with 2–3 days onsite and supports information security across Virginia Housing programs and IT systems.

The analyst will assist in cybersecurity awareness, help govern information security policies, and collaborate with the ISO on security projects, risk assessments, and privacy compliance.

Qualifications

  • 3 years of experience in Information Security governance, risk, and compliance.
  • Knowledge of information security principles and IT infrastructure management.
  • Familiarity with NIST, ISO 27001, and COBIT.
  • Ability to draft Information Security and Privacy policies and procedures.
  • Strong written communication and attention to detail.

Responsibilities

  • Participate in Information Security and Privacy efforts across all business areas and vendor engagements to ensure security controls.
  • Work within a Governance, Risk, and Compliance system to update information security records.
  • Partner with stakeholders to develop and maintain Information System Security Plans (SSP).
  • Represent the Information Security Office in PMO-led projects to ensure ISO involvement.
  • Collaborate to understand business challenges and develop compliant, value-adding solutions.
  • Assist in developing and maintaining information security standards and processes.
  • Assist with controls documentation, including diagramming risk templates and control narratives.
  • Review contracts, agreements, and vendor documentation for information security protections.

Skills

InfoSec governance
InfoSec concepts
IT infrastructure
NIST framework
ISO 27001
COBIT
Attention to detail
Adaptability
Policy drafting
Security documentation
Contract terms
Diagrams & flowcharts
Written communication

Education

Bachelor's degree in Computer Science or Information Systems
CISA
CISSP

Job description

Title: Information Security Analyst
Location:Hybrid in Richmond, VA (2~3 days onsite)
Term: 2 Years Contract
Available for W2 or 1099, No C2C
Job Description:

This important role will support information security across all Virginia Housing programs, projects, IT systems, and applications. The position is assigned to projects and initiatives with security and privacy components. The Information Security Analyst will assist in conducting cybersecurity and privacy awareness throughout Virginia Housing and help create and maintain the organization’s Information Security and privacy policies. Additionally, the Information Security Analyst will collaborate with the Information Security Office (ISO) on various security-related projects.

Key Responsibilities:
  • Participate in Information Security and Privacy efforts across all business areas and vendor engagements to ensure that appropriate security controls are in place and adhered to by all parties.
  • Work within a Governance, Risk, and Compliance (GRC) system to add and update information security records and documentation.
  • Partner with business stakeholders to develop and maintain Information System Security Plans (SSP).
  • Represent the Information Security Office in PMO-led projects to ensure significant projects have appropriate ISO representation.
  • Collaborate across teams to understand business challenges, develop tailored solutions that provide value, facilitate compliance, and ensure clear communication.
  • Assist in the development and maintenance of information security standards and processes, including conducting research as needed.
  • Assist with controls documentation, including information system diagramming, populating risk assessment templates, and drafting control narrative documentation for business approval.
  • Review contracts, agreements, and vendor documentation to ensure adequate information security protections are in place.
Required Qualifications:
  • At least 3 years of demonstrated experience in Information Security concepts related to governance, risk, and compliance.
  • Extensive knowledge of information security principles and practices.
  • Deep understanding of methods applied to information technology infrastructure planning, implementation, and management.
  • Strong organizational skills with the ability to set priorities, meet established deadlines, and follow up on assignments with minimal supervision.
  • Familiarity or experience with security frameworks such as NIST, ISO 27001, or COBIT.
  • Excellent attention to detail and organizational skills.
  • Ability to adapt to changing situations and prioritize tasks as needed.
  • Experience drafting Information Security and Privacy policies, standards, and procedures.
  • Ability to interpret security documentation, including flow diagrams and process maps.
  • Knowledge of contract terms and conditions.
  • Proficiency in creating diagrams, flowcharts, and spreadsheets using desktop software.
  • Strong written communication skills with the ability to convey complex security concepts to various audiences.
Preferred Qualifications:
  • Bachelor's degree in Computer Science, Information Systems, or equivalent.
  • Relevant security certifications such as CISA, CISSP, or an equivalent certification.
  • Previous experience in the financial services industry is preferred.
  • Knowledge of controls related to cloud security and application security.
  • Knowledge of Information Security regulatory compliance (e.g., GLBA, GDPR, PCI, etc.).
  • Familiarity with various privacy regulations (e.g., GDPR, CCPA, VCDPA).

Thanks for applying!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid Information Security Analyst: GRC & Policy
Hybrid Information Security Analyst: GRC & Policy

ASCENDING • Richmond (VA)

Hybrid
USD 85,000 - 120,000
1.20. IT Security Analyst
1.20. IT Security Analyst

Focused HR Solutions • Richmond (VA)

On-site
USD 80,000 - 120,000
Security Analyst
Security Analyst

MACHINE LEARNING TECHNOLOGIES LLC • Richmond (VA)

On-site
USD 55,104 - 103,320
IT Security Analyst 4 - Richmond, VA (Hybrid)
IT Security Analyst 4 - Richmond, VA (Hybrid)

Yakshna Solutions, Inc. • Herndon (VA)

Hybrid
USD 100,000 - 110,000
401(k) plan
Health insurance
Paid time off
+1
IT Security Architect
IT Security Architect

DataStaff, Inc. • Richmond (VA)

Hybrid
USD 114,000 - 197,000
Medical insurance
Vision insurance
401(k) plan
+3
IT Security Analyst 2 - Richmond, VA 23219 (Onsite)
IT Security Analyst 2 - Richmond, VA 23219 (Onsite)

Yakshna Solutions, Inc. • Richmond (VA)

On-site
USD 60,000 - 65,000
401(k)
Health insurance
Dental insurance
+6
Information Security Specialist (Remote)
Information Security Specialist (Remote)

Harris Computer • North Dakota

On-site
USD 80,000 - 110,000
Competitive compensation package
Health Insurance (medical, dental, vision)
Paid Vacation
+1
Security Analyst: Incident Response & Policy Leader
Security Analyst: Incident Response & Policy Leader

MACHINE LEARNING TECHNOLOGIES LLC • Richmond (VA)

On-site
USD 55,104 - 103,320
Information Assurance Analyst
Information Assurance Analyst

Cymertek Corporation • Reston (VA)

On-site
USD 85,000 - 120,000
Excellent Salaries
Flexible Work Schedule
401k Matching
+5
Information Security Analyst - W2 Only (NO 3rd Party)
Information Security Analyst - W2 Only (NO 3rd Party)

CBTS • Indianapolis (IN)

Hybrid
USD 60,000 - 90,000