
Information Security Control Assurance Analyst
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Alabama, +31 more states.
• Lead and conduct assessments for information security risk and compliance across University systems and services.
• Create, update, and evaluate System Security Plans, risk assessments, and associated documentation.
• Identify control weaknesses and security gaps, evaluate risk, and provide actionable recommendations.
• Oversee Plans of Action and Milestones, including tracking remediation efforts, validating corrective actions, and reporting on progress.
• Facilitate and support both internal and external audits and assessments.
• Monitor and analyze changes in federal and state information security and data privacy regulations.
• Develop and sustain information security policies, standards, procedures, and governance documentation.
• Collaborate with ISMO, Privacy, Legal, and business stakeholders to implement necessary controls and processes.
• Prepare and present compliance, risk, and audit reports to management and leadership.
• Contribute to the ongoing enhancement of information security governance, risk management, and compliance initiatives.
• A minimum of 3 years of experience in a related field.
• A Bachelor's Degree or progress towards a degree in a related area is required.
• Equivalent experience may be accepted in place of a degree.
• Familiarity with technical, administrative, and physical information security controls.
• Knowledge of information security governance, risk management, and compliance principles.
• Proficient understanding of NIST frameworks and standards, including NIST SP 800-53, 800-171, and the Risk Management Framework.
• Awareness of federal and state regulatory requirements and compliance obligations in higher education, such as GLBA, FERPA, and the Simplified FAFSA Act.
• Advanced knowledge of information security policies, standards, procedures, and governance documentation.
• Experience in supporting internal and external audits.
• Capability to convert complex regulatory and technical security requirements into actionable controls and processes.
• Working knowledge of IT service management concepts and best practices, including ITIL.
• High-quality, low-deductible medical insurance.
• Affordable or no-cost dental and vision plans.
• 5 weeks of paid time off.
• Nearly a dozen paid holidays.
• Employer-funded retirement plan.
• Free tuition program.
• Parental leave.
• Resources for mental health and wellbeing.
• 100% remote work from an approved state.
• Reliable internet connection and a dedicated, well-equipped workspace.
EXL
Reli Group
Second Nature
ASRC Federal
Get handpicked remote jobs straight to your inbox weekly.