
Information Assurance and Compliance Analyst
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in Illinois.
• Design and execute comprehensive cybersecurity policies, ensuring they align with frameworks such as NIST CSF, as well as government standards including IL5 and FedRAMP HIGH.
• Oversee and uphold compliance with government security standards while ensuring that policies cater to both technical and non-technical security requirements.
• Establish data classification and protection criteria for IT systems to secure sensitive information.
• Work collaboratively with cross-functional teams to ensure that cybersecurity policies are seamlessly integrated into business operations.
• Train employees on privacy protections and security protocols, enhancing awareness through effective communication and educational initiatives.
• Conduct regular reviews and updates of cybersecurity policies to ensure ongoing compliance with changing regulations and industry best practices.
• Assist in the Approval to Operate (ATO) process by confirming that all systems adhere to necessary security standards.
• Resolve security policy implementation challenges and offer solutions to strengthen protection measures.
• Stay informed on the latest trends in cybersecurity policies and regulatory compliance to consistently enhance security protocols.
• Given the role’s involvement in GovCloud and FedRAMP, qualified candidates must be U.S. Citizens.
• Minimum of 4 years of experience in developing, implementing, and managing cybersecurity policies.
• In-depth knowledge of cybersecurity frameworks, particularly NIST Cybersecurity Framework (CSF), with practical application of its principles in enterprise settings, along with the ability to convert theoretical guidelines into actionable security strategies.
• Experience in achieving and sustaining high-level security compliance, including government security standards like DoD Impact Level 5 (IL5), FedRAMP HIGH authorization requirements, SOC2, and ISO.
• Proficient in developing and implementing data classification policies and setting data protection standards for IT systems.
• Strong expertise in the AWS Cloud Platform.
• Demonstrated ability to prepare and support comprehensive security documentation for compliance audits.
• Excellent communication and training abilities to effectively inform employees about privacy protections and restrictions.
• Capacity to review existing policies and drive practical implementation to ensure adequate protection.
• Familiarity with the Approval to Operate (ATO) process and its significance in securing IT systems.
• Relevant certifications such as CISSP, CISM, or CIPP/US are highly desirable.
• Must be able to pass an enhanced security background check, including a financial vulnerability assessment.
• Medical, Dental & Vision (including domestic partnerships).
• Employer Paid Life Insurance & Employee/Spouse/Child Supplemental Life.
• Voluntary Short/Long Term Disability Insurance.
• 401K (Roth/Traditional).
• A generous PTO plan that recognizes your commitment and seniority (includes paid Bereavement/Jury Duty, etc.).
• Above market annual bonuses.
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.