Information Security Risk and Compliance Analyst

Commonwealth of VA Careers

Richmond (VA)

On-site

USD 85,000 - 110,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Commonwealth of VA Careers is seeking an Information Security Risk and Compliance Analyst to join the Virginia Treasury agency in Richmond. This mid‑level role focuses on risk management, governance, and security program execution to protect critical financial systems.

The role requires expertise in NIST standards, System Security Plans, and collaboration with development teams to implement robust application security controls.

Qualifications

  • Understanding of cybersecurity principles including network security, access control, and threat awareness.
  • Knowledge of NIST security frameworks and compliance standards.
  • Experience developing System Security Plans in line with SEC 530 or equivalent.
  • Excellent written communication and strong analytical skills.
  • Ability to document findings clearly and concisely with attention to detail.
  • Experience working with development teams on application security test plans.

Responsibilities

  • Application Security: create and maintain System Security Plans and acceptance criteria; define testing requirements and execute security test cases; support MFA/SSO to strengthen access control.
  • Security Awareness & Training: develop and manage security awareness programs; create training materials and campaigns; analyze metrics to improve program effectiveness.
  • Risk Management: identify threats and vulnerabilities; create risk assessments; manage risk registers and remediation tracking.
  • Governance, Compliance and Audit Support: verify alignment with NIST/SEC standards; coordinate audits; maintain security policies and dashboards.

Skills

Cybersecurity principles
NIST frameworks
RBAC & least privilege
MFA & SSO familiarity
Analytical thinking
Documentation quality
Security testing coordination

Tools

Archer

Job description

Title: Information Security Risk and Compliance Analyst

State Role Title: Info Technology Specialist II

Hiring Range: $85,000 - $110,000; Commensurate with experience

Pay Band: 5

Agency: Department of the Treasury

Location: JAMES MONROE BUILDING

Agency Website: https://trs.virginia.gov

Recruitment Type: General Public - G

Job Duties

Are you passionate about cybersecurity and keeping systems that support the Commonwealth Treasury and ultimately the State secure? Are you curious, analytical, and motivated to learn, and interested in an opportunity to grow your cybersecurity expertise while serving the Commonwealth?

The Virginia Department of the Treasury is dedicated to serving the Commonwealth by providing excellent management of its banking, investing, and financing services, and the administration of unclaimed property and insurance programs.

We are seeking a motivated and detail-oriented Information Security Risk and Compliance Analyst to support the agency’s cybersecurity and risk management operations. This position plays a critical role in protecting the Commonwealth’s financial systems, sensitive data, and technology infrastructure.

This is a mid-level role designed for someone who is building their cybersecurity career and has experience in compliance and risk management within a government environment.

The key responsibilities of the Information Security Risk and Compliance Analyst are:

Application Security
  • Create and maintain System Security Plans
  • Define security acceptance criteria that align with business requirements and security policies
  • Document requirements for test environment and test accounts
  • Develop and document test cases
  • Execute security related test cases
  • Support multi-factor authentication (MFA) and other identity verification mechanisms to strengthen access security.
Security Awareness & Training
  • Develop, implement, and manage security awareness programs to educate employees on cybersecurity best practices.
  • Create training materials, presentations, and campaigns that effectively communicate security policies and procedures.
  • Analyze training metrics and reporting to identify gaps and continuously improve program effectiveness.
  • Maintain familiarity with emerging threats and trends to keep awareness content current and relevant.
  • Manage Treasury’s annual training campaign to ensure compliance with SEC 527 and other relevant Commonwealth Standards.
Risk Management
  • Identify threats and vulnerabilities
  • Create and maintain risk assessments
  • Manage Archer and other applicable risk registers
  • Track remediation activities and corrective action plans
Governance, Compliance and Audit Support
  • Verify alignment with Commonwealth of Virginia Information Security, NIST, and other applicable Standards
  • Coordinate internal and external compliance audits
  • Build and update security policies and procedures
  • Maintain security documentation
  • Develop reports and dashboards for leadership as requested
Minimum Qualifications

The selected candidate will possess the following qualifications:

  • Understanding of cybersecurity principles, including:
    • Network security fundamentals
    • Access control concepts
    • Malware and phishing threats
    • Incident response basics
  • Knowledge of NIST security frameworks and compliance standards
  • Experience developing System Security Plans in accordance with SEC 530 Standard or similar
  • Excellent written communication skills
  • Strong analytical and problem-solving skills
  • Ability to document findings clearly and concisely
  • Strong attention to detail and organizational skills
  • Ability to handle sensitive and confidential information appropriately
  • Experience working with development teams to develop and execute application security test plans
  • Strong understanding of Role-Based Access Control (RBAC), Least Privilege Principles, and Segregation of Duties
  • Familiarity with Multi-Factor Authentication (MFA) and Single Sign-On (SSO) technologies
Additional Considerations
  • Familiarity with common Governance, Risk, and Compliance security tools such as Archer.
  • Experience in Information Security, Identity and Access Management (IAM)
  • Experience in monitoring third-party risk.
  • Familiarity with cloud environments (AWS, Azure, GCP) and their access control mechanisms.
  • Experience working in a government or highly regulated environment
Contact Information

Name: Lori Perez

Phone: 804-225-3247

Email: HR@trs.virginia.gov

In support of the Commonwealth’s commitment to inclusion, we are encouraging individuals with disabilities to apply through the Commonwealth Alternative Hiring Process. To be considered for this opportunity, applicants will need to provide their AHP Letter (formerly COD) provided by the Department for Aging & Rehabilitative Services (DARS), or the Department for the Blind & Vision Impaired (DBVI). Service-Connected Veterans are encouraged to answer Veteran status questions and submit their disability documentation, if applicable, to DARS/DBVI to get their AHP Letter. Requesting an AHP Letter can be found at AHP Letter or by calling DARS at 800-552-5019.

Note: Applicants who received a Certificate of Disability from DARS or DBVI dated between April 1, 2022- February 29, 2024, can still use that COD as applicable documentation for the Alternative Hiring Process.

The Virginia Department of the Treasury is an Equal Opportunity Employer.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Risk and Compliance Analyst
Information Security Risk and Compliance Analyst

DHRM • Richmond (VA)

Hybrid
USD 85,000 - 110,000
Telework up to 2 days/week
Hybrid Information Security Risk & Compliance Analyst
Hybrid Information Security Risk & Compliance Analyst

DHRM • Richmond (VA)

Hybrid
USD 85,000 - 110,000
Telework up to 2 days/week
Strategic Information Security & Compliance Analyst
Strategic Information Security & Compliance Analyst

Commonwealth of VA Careers • Richmond (VA)

On-site
USD 85,000 - 110,000
Accountant #00011
Accountant #00011

Commonwealth of VA Careers • Richmond (VA)

On-site
USD 58,000 - 69,000
Accountant #00011
Accountant #00011

DHRM • Richmond (VA)

On-site
USD 58,000 - 69,000
Risk Assessment Program Analyst #00011
Risk Assessment Program Analyst #00011

Virginia Department of Emergency Management • Virginia (MN)

On-site
USD 65,000 - 68,000
Talent Acquisition / Classification & Compensation Specialist #01370
Talent Acquisition / Classification & Compensation Specialist #01370

UNKNOWN • Richmond (VA)

On-site
USD 60,000 - 80,000
Telework options
Information Security Specialist 2
Information Security Specialist 2

Commonwealth of Pennsylvania • Harrisburg

On-site
USD 78,925 - 119,844
Risk and Compliance Analyst
Risk and Compliance Analyst

Triumph Enterprises, Inc • Washington, Northern (KY)

Hybrid
USD 110,000 - 150,000
1.20. IT Security Analyst
1.20. IT Security Analyst

Focused HR Solutions • Richmond (VA)

On-site
USD 80,000 - 120,000