Information Security Control Assurance Analyst

Southern New Hampshire University

United States

Remote

USD 60,000 - 96,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental & vision plans
Paid time off
Retirement plan
Free tuition program
Parental leave
Wellbeing resources

Job summary

Southern New Hampshire University is seeking an Information Security Control Assurance Analyst to lead risk and compliance efforts across university systems. You will develop security plans, assess controls, and drive remediation through POA&Ms while partnering with IT, Legal, Privacy, and business stakeholders.

This remote role involves staying current with regulatory requirements, translating them into practical policies, and contributing to governance and risk reporting for leadership.

Qualifications

  • 3+ years in information security, risk, or compliance.
  • Understanding of governance, risk management, and compliance principles.
  • Knowledge of NIST frameworks (SP 800-53/171) and RMF.
  • Familiarity with regulatory requirements in higher education (GLBA, FERPA).
  • Ability to translate regulatory requirements into practical controls.

Responsibilities

  • Lead information security risk and compliance assessments across systems and services.
  • Develop and maintain System Security Plans (SSPs) and risk assessments.
  • Identify control gaps and document actionable recommendations.
  • Manage Plans of Action and Milestones (POA&Ms) and report progress.
  • Coordinate internal and external audits and evidence collection.
  • Monitor changes in federal and state information security laws and impact.
  • Develop and maintain security policies, standards, and governance docs.
  • Collaborate with ISMO, Privacy, Legal, and business stakeholders.
  • Prepare compliance and risk reporting for leadership.
  • Contribute to ongoing information security governance improvements.

Skills

Information security
Risk management
Compliance governance
Regulatory knowledge
Audit support
ITIL
Security governance
Risk assessment

Education

Bachelor's Degree
Working toward degree
Equivalent experience

Job description

Southern New Hampshire University is a team of innovators. World changers. Individuals who believe in progress with purpose. Since 1932, our people-centered strategy has defined us — and helped us grow a team that now serves over 180,000 learners worldwide. Our mission to transform lives is made possible by talented people who bring diverse industry experience, backgrounds and skills to the university. And today, we're ready to expand our reach. All we need is you. Make an impact — from near or far At SNHU, you'll have the option to work remotely in the following states: Alabama, Arizona, Arkansas, Delaware, Florida, Georgia, Hawaii, Idaho, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Mississippi, Missouri, Nebraska, New Hampshire, New Mexico, North Carolina, North Dakota, Ohio, Oklahoma, South Carolina, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, West Virginia, Wisconsin and Wyoming. We ask that our remote employees have access to a reliable internet connection and a dedicated, properly equipped workspace that is free of distractions. Employees must reside in, and work from, one of the above approved states.

The opportunity

The Information Security Control Assurance Analyst plays a critical role in ensuring the University's adherence to legal, regulatory, and contractual information security and data protection requirements. This position leads and supports security assessment and authorization activities, including the development and maintenance of system security plans, evaluation of technical, administrative, and physical security controls, and management of remediation efforts through Plans of Action and Milestones (POA&Ms). The Analyst serves as a key contributor to institutional risk management by identifying compliance gaps, assessing risk associated with control deficiencies, and providing clear, actionable reporting to leadership. This role partners closely with IT, Legal, Privacy, and business stakeholders to coordinate internal and external audits, respond to regulatory changes, and translate complex security and compliance requirements into practical, well documented policies, standards, and procedures that support the University's mission and operational needs. You will work 100% remotely from any of our approved states. #LI-Remote

What You'll Do
  • Lead and perform information security risk and compliance assessments to evaluate the effectiveness of technical, administrative, and physical security controls across University systems and services.
  • Develop, maintain, and review System Security Plans (SSPs), risk assessments, and supporting documentation in alignment with applicable security frameworks and regulatory requirements.
  • Identify control gaps and security deficiencies, assess associated risk, and document findings with clear, actionable recommendations.
  • Manage and oversee Plans of Action and Milestones (POA&Ms), including tracking remediation activities, validating corrective actions, and reporting progress to stakeholders.
  • Coordinate and support internal and external audits and assessments, including evidence collection, validation, and response management.
  • Monitor and interpret changes in federal and state information security and data privacy laws, regulations, and contractual requirements, and assess organizational impact.
  • Develop, update, and maintain information security policies, standards, procedures, and governance documentation to ensure ongoing compliance and operational effectiveness.
  • Partner closely with ISMO, Privacy, Legal, and business stakeholders to translate regulatory and security requirements into practical, implementable controls and processes.
  • Prepare and deliver compliance, risk, and audit reporting to management and leadership to support informed decision-making.
  • Contribute to continuous improvement of the University's information security governance, risk management, and compliance programs.
What We're Looking For
  • 3 years of experience in a related field
  • Completion of a Bachelor's Degree or working toward a degree in a related field
  • Equivalent of experience in lieu of degree acceptable
  • Demonstrated understanding of technical, administrative, and physical information security controls and how they are applied to manage risk across enterprise systems and services.
  • Strong knowledge of information security governance, risk management, and compliance principles, including the ability to assess control effectiveness and identify compliance gaps.
  • Working knowledge of NIST frameworks and standards (including NIST SP 800-53, 800-171, and the Risk Management Framework) and their application in assessment, authorization, and continuous monitoring activities.
  • Familiarity with federal and state regulatory requirements and higher education compliance obligations related to information security and data protection (e.g., GLBA, FERPA, Simplified FAFSA Act).
  • Advanced understanding of information security policies, standards, procedures, and governance documentation, including development, maintenance, and implementation.
  • Experience supporting internal and external audits, including evidence collection, documentation review, and response coordination.
  • Ability to translate complex regulatory and technical security requirements into practical, implementable controls and processes for technical and non-technical stakeholders.
  • Working understanding of IT service management concepts and best practices (e.g., ITIL) as they relate to security operations, controls, and risk management.

We believe real innovation comes from inclusion - where different experiences, perspectives and talents are celebrated.

If you have a disability and require a reasonable accommodation to fully engage in any part of the application or hiring process, please complete the Accommodation Request form or contact us at 603-626-9447. A member from the Employee Accommodation Support Center will be in contact with you within two business days to discuss your request.

Compensation

The annual pay range for this position is $60,209.00 - $96,352.00. Actual offer will be based on skills, qualifications, experience and internal equity, in addition to relevant business considerations. We expect this position to be hired in the following target hiring range $66,531.00 - $90,013.00.

Exceptional benefits
  • High-quality, low-deductible medical insurance
  • Low to no-cost dental and vision plans
  • 5 weeks of paid time off (plus almost a dozen paid holidays)
  • Employer-funded retirement
  • Free tuition program
  • Parental leave
  • Mental health and wellbeing resources
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IAM Engineer
IAM Engineer

Southern New Hampshire University • United States

Remote
USD 97,000 - 131,000
Free tuition program
Parental leave
Mental health resources
+2
Remote Information Security Compliance & Controls Analyst
Remote Information Security Compliance & Controls Analyst

Southern New Hampshire University • United States

Remote
USD 60,000 - 96,000
Medical insurance
Dental & vision plans
Paid time off
+4
SR. Security Engineer- Governance and Compliance
SR. Security Engineer- Governance and Compliance

University of Phoenix • Phoenix (AZ)

Remote
USD 96,000 - 195,000
Lead Cybersecurity GRC, DB/BC Analyst
Lead Cybersecurity GRC, DB/BC Analyst

University of New Hampshire • United States

On-site
USD 70,000 - 125,000
Lead Cybersecurity GRC, DB/BC Analyst
Lead Cybersecurity GRC, DB/BC Analyst

CP01 University System of New Hampshire • Durham (NH)

On-site
USD 70,000 - 125,000
Lead Cybersecurity GRC, DB/BC Analyst
Lead Cybersecurity GRC, DB/BC Analyst

University of New Hampshire • Plymouth (NH)

On-site
USD 70,000 - 125,000
Lead Cybersecurity GRC, DB/BC Analyst
Lead Cybersecurity GRC, DB/BC Analyst

University of New Hampshire • Keene (NH)

On-site
USD 70,000 - 125,000
Lead Cybersecurity GRC, DB/BC Analyst
Lead Cybersecurity GRC, DB/BC Analyst

University of New Hampshire • Durham (NH)

On-site
USD 70,000 - 125,000
Sr. ServiceNow Administrator
Sr. ServiceNow Administrator

Southern New Hampshire University • United States

Remote
USD 8,100 - 128,000
Medical insurance
Dental & vision plans
Paid time off
+4
Sr Security Engineer- Incident Response, Forensics and Security Operations
Sr Security Engineer- Incident Response, Forensics and Security Operations

University of Phoenix • Phoenix (AZ)

Remote
USD 96,000 - 195,000
Medical, dental and vision plans
401(k) employer match
Tuition discount for employees