Information Security Officer

Assura, Inc.

Richmond (VA)

On-site

USD 80,000 - 110,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Assura is seeking a Virtual Information Security Officer (VISO) to deliver day-to-day security program work for Assura clients in a delivery role, under supervision. The analyst-level position focuses on executing tasks, supporting assessments, and maintaining client communication while building toward greater responsibility.

The ideal candidate has 3–5 years in cybersecurity/GRC, with familiarity in NIST 800-53 and related frameworks, and experience updating GRC deliverables.

Qualifications

  • 3-5 years of relevant experience in cybersecurity, GRC, risk, compliance, audit, or information security.
  • Familiarity with at least one regulatory framework (e.g., NIST 800-53, HIPAA, PCI DSS).
  • Strong working knowledge of NIST 800-53 across AC, IA, CM, SI, SC, AU, SA, AT.
  • Experience updating or developing GRC deliverables (policies, procedures, standards, BIA, IR/DR docs, SSPs, VM plans, TPRM docs).
  • Ability to take direction and reliably carry instructions to completion.
  • Strong writing, documentation, and client communication skills.
  • Independent research and problem-solving when gaps arise.

Responsibilities

  • Perform assigned GRC service and planning tasks under direction of a Senior VISO or GRC Director.
  • Support security assessments and identify risks, issues, and basic remediation activities under supervision.
  • Maintain and develop core deliverables: policies, procedures, standards, BIA, IR/DR docs, SSPs, VM plans, TPRM docs.
  • Facilitate client meetings, track follow-ups, and communicate clearly with clients and Assura colleagues.
  • Interact directly with clients (once trained) without constant senior intervention.
  • Support audit and compliance activities—preparing compliant documentation and remediation plans.
  • Deliver client security awareness training within established parameters (e.g., KnowBe4).
  • Manage deadlines and quality expectations, including review steps.
  • Conduct independent research to close gaps or answer questions before escalation.

Skills

GRC experience
Regulatory knowledge
Audit support
Policy writing
Client communication

Job description

hatch IT is partnering with Assura to find a Virtual Information Security Officer (VISO). Details below:

About the Role

The Virtual Information Security Officer (VISO) is an analyst-level GRC consulting role delivering day-to-day security program work for Assura clients under the direction of a Senior VISO or GRC Director. This is not a strategic ownership role - it's a delivery role. You'll execute assigned service and planning tasks, support assessments and documentation, maintain professional client communication, and follow through on instructions reliably, while building toward greater responsibility over time.

About the Company

Assura is a cybersecurity firm with nearly 20 years of singular focus on information security. We work primarily with state, local, and education (SLED) organizations that need real-world, practical security leadership - not checkbox compliance or theoretical frameworks. Our team is made up of career cybersecurity practitioners, not career consultants. We take the work seriously, but not ourselves. People stay here because they're supported, trusted, and given room to grow.

Responsibilities
  • Perform assigned GRC service and planning tasks under the direction of a Senior VISO or GRC Director
  • Support security assessments and identify risks, issues, and basic remediation activities under supervision
  • Maintain, update, and support development of core deliverables: policies, procedures, standards, BIA documentation, incident response and disaster recovery documentation, system security plans, vulnerability management plans, and third-party risk documentation
  • Facilitate client meetings, track follow-up items, and communicate clearly and professionally with clients and Assura colleagues
  • Interact directly with clients (once trained) without requiring constant senior intervention
  • Support audit and compliance activities - preparing compliant documentation, participating in audit defense as directed, and helping develop remediation plans under leadership direction
  • Customize and deliver client security awareness training within established parameters (e.g., KnowBe4)
  • Manage deadlines and quality expectations, including adherence to review steps such as Second Set of Eyes
  • Conduct independent research and analysis to close gaps or answer questions before escalating
Qualifications
  • Approximately 3-5 years of relevant experience in cybersecurity, GRC, risk, compliance, audit, or information security
  • Meaningful hands-on experience with at least one regulatory framework (e.g., NIST 800-53, HIPAA, PCI DSS), with working familiarity in others
  • Strong working knowledge of NIST 800-53, with specific familiarity across the AC, IA, CM, SI, SC, AU, SA, and AT control families
  • Demonstrated experience updating or helping develop GRC deliverables (policies, procedures, standards, BIA, IR/DR docs, SSPs, VM plans, TPRM documentation)
  • Ability to take direction from senior staff and reliably carry instructions through to completion
  • Strong writing, documentation, and client communication skills
  • Intellectual curiosity and the ability to research and problem-solve independently when gaps arise
Preferred Skills
  • Familiarity with SEC530 and Virginia public-sector compliance expectations
  • Foundational understanding of how functions like IT, HR, and Finance intersect with security planning and documentation
  • Prior audit support experience beyond evidence collection (planning, remediation, documentation ownership)
  • Comfort with client-facing meetings and stakeholder communication
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Consultant
Information Security Consultant

Hatch IT • United States

Remote
USD 180,000 - 230,000
Virtual Information Security Officer (GRC Delivery)
Virtual Information Security Officer (GRC Delivery)

Assura, Inc. • Richmond (VA)

On-site
USD 80,000 - 110,000
Information Security Officer (ISO) in Richmond, VA
Information Security Officer (ISO) in Richmond, VA

Unisys Corporation • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Cleared Information System Security Officer L3 - Lorton, VA
Cleared Information System Security Officer L3 - Lorton, VA

VetJobs • Lorton (VA)

On-site
USD 140,000 - 180,000
Security Control Assessor ? Level II / Journeyman
Security Control Assessor ? Level II / Journeyman

Rividium • Washington

On-site
USD 110,000 - 180,000
Cleared Information System Security Manager (ISSM) - L4
Cleared Information System Security Manager (ISSM) - L4

Virtual Service Operations • Lorton (VA)

On-site
USD 150,000 - 210,000
Health benefits
Flexible work arrangements
Cleared Information System Security Officer (ISSO) — L3
Cleared Information System Security Officer (ISSO) — L3

Virtual Service Operations • Lorton (VA)

On-site
USD 140,000 - 180,000
Health benefits
Flexible work arrangements
Relocation assistance
Senior Cyber Security & GRC Engineer
Senior Cyber Security & GRC Engineer

Emergent Staffing • Hartford (CT)

On-site
USD 130,000 - 180,000
Information Security Officer (ISO) in Richmond, VA
Information Security Officer (ISO) in Richmond, VA

Unisys • Richmond (VA)

Hybrid
USD 140,000 - 195,000
Infosec or GRC Leader
Infosec or GRC Leader

Avantdigitalnow • San Francisco (CA)

On-site
USD 95,000 - 130,000