IT & Security Governance Analyst

Communication Service for the Deaf, Inc

United States

On-site

USD 90,000 - 130,000

Full time

37 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Communication Service for the Deaf, Inc is seeking an IT & Security Governance Analyst to strengthen governance processes across IT, cloud, and product environments. You will maintain risk registers, develop policies, and support audits while partnering with stakeholders to improve resilience and data protection.

The role emphasizes practical governance, security controls, and documentation to drive efficiency and accountability across the organization.

Qualifications

  • Bachelor's degree or equivalent work experience in IT governance, cybersecurity, or risk management.
  • Experience across multiple IT or security domains.
  • Familiarity with IAM concepts such as SSO, MFA, and least privilege.
  • Knowledge of logging, encryption, backup management, vulnerability management, and network security.
  • Experience supporting audits or security frameworks is a plus.
  • Certifications such as Security+, SSCP, or equivalent are preferred.

Responsibilities

  • Support governance initiatives across corporate IT, cloud, and product environments.
  • Maintain technology risk registers and remediation tracking.
  • Develop and document IT and security policies, standards, and procedures.
  • Maintain governance records, system ownership docs, and inventories.
  • Prepare governance metrics, risk reports, and audit readiness docs.
  • Support data governance, data flows, and retention standards.
  • Assist with secure SDLC practices and vulnerability management workstreams.
  • Coordinate IAM, endpoint management, and cloud security controls.
  • Assist with business continuity and disaster recovery planning and testing.
  • Support vendor/security assessments and audit inquiries.

Skills

IAM principles
SSO
MFA
least privilege
access reviews
logging
encryption
backup management
vulnerability management
network security
risk management
security frameworks

Education

Bachelor's degree in IT/Cybersecurity/CS or related field
Security+ or equivalent certification

Tools

AWS
Azure
GCP
CI/CD environments
MDM
EDR
SIEM
Vulnerability scanners

Job description

All Jobs > IT & Security Governance Analyst

The IT & Security Governance Analyst supports technology governance, security, and operational maturity initiatives across corporate IT, cloud and product environments, and operational systems. This role works across the organization to strengthen governance processes, maintain security controls and documentation, support data stewardship, and identify and track technology risks.

This position helps operationalize compliance frameworks as practical tools to improve efficiency, accountability, risk management, and resilience, rather than treating compliance as the sole objective.

  • Support the development and maintenance of the organization's IT and security roadmap aligned with mission priorities and partner obligations.
  • Maintain the technology risk register, including security, data, vendor, and operational risks, and track remediation activities.
  • Assist with developing, documenting, and maintaining IT and security policies, standards, and procedures.
  • Maintain system ownership documentation, governance records, and technology inventories.
  • Prepare technology governance metrics, risk reports, and audit readiness documentation.
Data Governance & System Oversight
  • Support implementation and maintenance of data classification, access governance, and retention standards.
  • Document and maintain key data flows across internal systems, partner integrations, and cloud environments.
  • Review encryption, logging, and access controls for alignment with data sensitivity and contractual requirements.
  • Partner with Engineering and program teams to support secure and scalable system practices.
  • Maintain architecture documentation, data flow diagrams, and security control mappings.
Identity, Access & Organizational IT Foundations
  • Support identity and access management processes, including SSO, MFA, least privilege, access reviews, and joiner-mover-leaver workflows.
  • Coordinate endpoint and device management practices, including MDM, encryption, patching, configuration baselines, and endpoint protection.
  • Review SaaS governance practices and recommend improvements to reduce shadow IT risk.
  • Support validation of backup, recovery, and resilience capabilities for critical systems.
  • Provide guidance to departments on security and data handling best practices.
Cloud, Application & Vulnerability Management
  • Partner with Engineering to support Secure SDLC practices.
  • Coordinate vulnerability management activities, including scanning, triage, remediation tracking, and verification.
  • Support cloud security practices related to IAM, key management, logging, monitoring, and network security.
  • Participate in security and architecture reviews for new systems and major technology initiatives.
  • Maintain incident response documentation, runbooks, and severity classifications.
  • Support tabletop exercises and track remediation activities.
  • Assist with business continuity and disaster recovery testing.
  • Coordinate vendor and partner security assessments and remediation tracking.
  • Support audits, customer security questionnaires, and partner assurance initiatives.
  • Partner with Legal and business stakeholders to support implementation of data protection and security requirements.
  • Other duties as assigned.
Requirements
  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or a minimum of one (1) year of relevant experience in IT governance, cybersecurity, IT operations, or risk management.
  • Experience working across multiple IT or security domains.
  • Understanding of IAM principles, including SSO, MFA, least privilege, and access reviews.
  • Working knowledge of areas such as logging, endpoint security, encryption, backup management, vulnerability management, and network security.
  • Experience supporting IT, data, or security governance initiatives.
  • Ability to analyze technical risks and develop practical recommendations.
  • Ability to coordinate cross-functional initiatives and work effectively with technical and non-technical stakeholders.
  • Experience supporting audits or security frameworks such as PCI DSS, SOC 2, ISO 27001, NIST 800-53 Rev. 5, or HIPAA-adjacent controls preferred.
  • Experience with AWS, Azure, or GCP and CI/CD environments preferred.
  • Experience with MDM, EDR, SIEM, vulnerability scanners, or related tooling preferred.
  • Familiarity with secure software development practices and threat modeling preferred.
  • Relevant certifications such as Security+, SSCP, GSEC, or equivalent preferred.
  • Experience supporting grant-funded initiatives, multi-partner collaborations, or externally funded programs preferred.
  • Ability to communicate effectively in American Sign Language preferred.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT & Security Governance Analyst
IT & Security Governance Analyst

Communication Service for the Deaf (CSD) • Austin (TX)

On-site
USD 85,000 - 120,000
Cybersecurity Governance Analyst
Cybersecurity Governance Analyst

Veriipro • Fort Lauderdale (FL)

On-site
USD 90,000 - 130,000
Information Technology Governance Consultant
Information Technology Governance Consultant

Brooksource • Kansas City (MO)

On-site
USD 140,000 - 190,000
Competitive medical, dental, vision coverage
401k with company match
Paid time off and holidays
+1
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade • Oxford (MS)

On-site
USD 110,000 - 160,000
Technical Security Risk & Governance Analyst
Technical Security Risk & Governance Analyst

Mbi Llc • Harrisburg

On-site
USD 80,000 - 100,000
Hybrid/telework eligibility
Participation in after-hours change windows or incident support
Senior Technology & Data Governance Lead (Information Security)
Senior Technology & Data Governance Lead (Information Security)

MSR Technology Group • Kansas City (MO)

On-site
USD 100,000 - 130,000
Cyber Compliance Analyst III
Cyber Compliance Analyst III

Seminole Hard Rock Support Services • Town of Florida (NY)

On-site
USD 95,000 - 145,000
Sr. Governance Analyst
Sr. Governance Analyst

Alexander Technology Group • Boston (MA)

On-site
USD 110,000 - 150,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000