Information Security Risk and Compliance Analyst

DHRM

Richmond (VA)

Hybrid

USD 85,000 - 110,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Telework up to 2 days/week

Job summary

The Virginia Department of the Treasury is seeking an Information Security Risk and Compliance Analyst to support cybersecurity and risk management across the Commonwealth's financial systems. This mid-level role focuses on compliance, risk assessments, and governance within a government environment.

You will contribute to security testing, awareness campaigns, and policy documentation, while coordinating audits and delivering leadership-ready reports and dashboards.

Qualifications

  • Understanding of cybersecurity principles and practices.
  • Knowledge of NIST security frameworks and compliance standards.
  • Experience developing System Security Plans and security documentation.
  • Excellent written communication and analytical skills.

Responsibilities

  • Create and maintain System Security Plans with aligned acceptance criteria.
  • Develop security training materials and campaigns for awareness programs.
  • Identify threats, perform risk assessments, and track remediation actions.
  • Coordinate audits and maintain governance, policies, and security dashboards.

Skills

Cybersecurity fundamentals
NIST frameworks
RBAC & least privilege
MFA & SSO familiarity
Strong written skills

Education

Bachelor's degree in IT or related field

Tools

Archer

Job description

Title: Information Security Risk and Compliance Analyst

State Role Title: Info Technology Specialist II

Hiring Range: $85,000 - $110,000; Commensurate with experience

Pay Band: 5

Agency: Department of the Treasury

Location: JAMES MONROE BUILDING

Agency Website: https://trs.virginia.gov

Recruitment Type: General Public - G

Job Duties

Are you passionate about cybersecurity and keeping systems that support the Commonwealth Treasury and ultimately the State secure? Are you curious, analytical, and motivated to learn, and interested in an opportunity to grow your cybersecurity expertise while serving the Commonwealth? The Virginia Department of the Treasury is dedicated to serving the Commonwealth by providing excellent management of its banking, investing, and financing services, and the administration of unclaimed property and insurance programs. We are seeking a motivated and detail-oriented Information Security Risk and Compliance Analyst to support the agency’s cybersecurity and risk management operations. This position plays a critical role in protecting the Commonwealth’s financial systems, sensitive data, and technology infrastructure. This is a mid-level role designed for someone who is building their cybersecurity career and has experience in compliance and risk management within a government environment.

Application Security
  • Create and maintain System Security Plans
  • Define security acceptance criteria that align with business requirements and security policies
  • Document requirements for test environment and test accounts
  • Develop and document test cases
  • Execute security related test cases
  • Support multi-factor authentication (MFA) and other identity verification mechanisms to strengthen access security.
Security Awareness & Training
  • Develop, implement, and manage security awareness programs to educate employees on cybersecurity best practices.
  • Create training materials, presentations, and campaigns that effectively communicate security policies and procedures.
  • Analyze training metrics and reporting to identify gaps and continuously improve program effectiveness.
  • Maintain familiarity with emerging threats and trends to keep awareness content current and relevant.
  • Manage Treasury’s annual training campaign to ensure compliance with SEC 527 and other relevant Commonwealth Standards.
Risk Management
  • Identify threats and vulnerabilities
  • Create and maintain risk assessments
  • Manage Archer and other applicable risk registers
  • Track remediation activities and corrective action plans
Governance, Compliance and Audit Support
  • Verify alignment with Commonwealth of Virginia Information Security, NIST, and other applicable Standards
  • Coordinate internal and external compliance audits
  • Build and update security policies and procedures
  • Maintain security documentation
  • Develop reports and dashboards for leadership as requested
Minimum Qualifications
  • Understanding of cybersecurity principles, including:
    • Network security fundamentals
    • Access control concepts
    • Malware and phishing threats
    • Incident response basics
  • Knowledge of NIST security frameworks and compliance standards
  • Experience developing System Security Plans in accordance with SEC 530 Standard or similar
  • Excellent written communication skills.
  • Strong analytical and problem-solving skills.
  • Ability to document findings clearly and concisely.
  • Strong attention to detail and organizational skills.
  • Ability to handle sensitive and confidential information appropriately.
  • Experience working with development teams to develop and execute application security test plans.
  • Strong understanding of Role-Based Access Control (RBAC), Least Privilege Principles, and Segregation of Duties.
  • Familiarity with Multi-Factor Authentication (MFA) and Single Sign-On (SSO) technologies.
Additional Considerations
  • Familiarity with common Governance, Risk, and Compliance security tools such as Archer.
  • Experience in Information Security, Identity and Access Management (IAM)
  • Experience in monitoring third-party risk.
  • Familiarity with cloud environments (AWS, Azure, GCP) and their access control mechanisms.
  • Experience working in a government or highly regulated environment
Telework Policy

The Department of the Treasury telework policy allows for up to two days a week of telework, subject to the position requirements. This position will be located in Richmond, Virginia, and must report on-site until the completion of an approved telework agreement is received.

Additional Requirements
  • All finalists are subject to a background investigation. The investigation may include: criminal checks; employment verification; verification of education; and other checks requested by the hiring authority.
  • Applicants who possess an Interagency Placement Screening Form (Yellow Form) or a Preferential Hiring Form (Blue Form) as issued under the Department for Human Resources Management (DHRM) Policy 1.30 Layoff (Commonwealth of Virginia Employees Only), must attach these forms with their state application.
  • The Virginia Department of the Treasury is an Equal Opportunity Employer.
Contact Information

Name: Lori Perez

Phone: 804-225-3247

Email: HR@trs.virginia.gov

Alternative Hiring Process Information

In support of the Commonwealth's commitment to inclusion, we are encouraging individuals with disabilities to apply through the Commonwealth Alternative Hiring Process. To be considered for this opportunity, applicants will need to provide their AHP Letter (formerly COD) provided by the Department for Aging & Rehabilitative Services (DARS), or the Department for the Blind & Vision Impaired (DBVI). Service-Connected Veterans are encouraged to answer Veteran status questions and submit their disability documentation, if applicable, to DARS/DBVI to get their AHP Letter. Requesting an AHP Letter can be found at AHP Letter or by calling DARS at 800-552-5019.

Note: Applicants who received a Certificate of Disability from DARS or DBVI dated between April 1, 2022- February 29, 2024, can still use that COD as applicable documentation for the Alternative Hiring Process.

Advertised: 27 Sep 2026 Eastern Daylight Time

Applications close: 11 Oct 2026 Eastern Daylight Time

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Risk and Compliance Analyst
Information Security Risk and Compliance Analyst

Commonwealth of VA Careers • Richmond (VA)

On-site
USD 85,000 - 110,000
Hybrid Information Security Risk & Compliance Analyst
Hybrid Information Security Risk & Compliance Analyst

DHRM • Richmond (VA)

Hybrid
USD 85,000 - 110,000
Telework up to 2 days/week
Accountant #00011
Accountant #00011

DHRM • Richmond (VA)

On-site
USD 58,000 - 69,000
Accountant #00011
Accountant #00011

Commonwealth of VA Careers • Richmond (VA)

On-site
USD 58,000 - 69,000
Office Services Specialist for Chief of Security: Nottoway Correctional Center #00646
Office Services Specialist for Chief of Security: Nottoway Correctional Center #00646

DHRM • Virginia (MN)

On-site
USD 37,000 - 49,000
Talent Acquisition / Classification & Compensation Specialist #01370
Talent Acquisition / Classification & Compensation Specialist #01370

UNKNOWN • Richmond (VA)

On-site
USD 60,000 - 80,000
Telework options
Strategic Information Security & Compliance Analyst
Strategic Information Security & Compliance Analyst

Commonwealth of VA Careers • Richmond (VA)

On-site
USD 85,000 - 110,000
Talent Acquisition / Classification & Compensation Specialist #01370
Talent Acquisition / Classification & Compensation Specialist #01370

Virginia Department of Agriculture and Consumer Services • Richmond (VA)

On-site
USD 60,000 - 80,000
Risk Assessment Program Analyst #00011
Risk Assessment Program Analyst #00011

Virginia Department of Emergency Management • Virginia (MN)

On-site
USD 65,000 - 68,000
Fiscal Technician Senior: Central Administration #00554
Fiscal Technician Senior: Central Administration #00554

DHRM • Richmond (VA)

On-site
USD 43,000 - 62,000