
Senior IT and Security Governance Analyst
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in United States.
• Accountable for enhancing technology governance, security, and operational maturity initiatives throughout corporate IT, cloud and product environments, as well as operational systems.
• Act as a subject matter expert in governance, security controls, data stewardship, and operational risk management, collaborating across the organization to fortify processes, boost resilience, and promote sustainable growth.
• Implement compliance frameworks as structured tools to improve efficiency, accountability, and resilience—utilizing them to refine processes, reduce risk, and elevate overall technology governance rather than viewing compliance as the sole objective.
• Assist in the creation and upkeep of the organization's IT and security roadmap in alignment with mission priorities and partner commitments.
• Oversee the technology risk register, and develop, document, and maintain IT and security policies, standards, and procedures.
• Collaborate with Engineering and program teams to adopt secure, scalable system design practices.
• Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or at least five (5) years of progressively responsible experience in IT governance, cybersecurity, IT operations, or risk management.
• Experience across various IT and security domains.
• Strong grasp of IAM principles including SSO, MFA, least privilege, and access reviews.
• Proficient knowledge of logging, endpoint security, encryption, backup management, vulnerability management, and network security.
• Experience in executing IT, data, or security governance initiatives.
• Demonstrated capability to analyze intricate technical risks and formulate practical recommendations.
• Proven track record of independently leading cross-functional technical initiatives while collaborating effectively.
• Experience supporting audits or security frameworks such as PCI DSS, SOC 2, ISO 27001, NIST 800-53 Rev. 5, or HIPAA-adjacent controls (preferred).
• Familiarity with AWS, Azure, or GCP and CI/CD environments (preferred).
• Experience with MDM, EDR, SIEM, vulnerability scanners, and associated tools (preferred).
• Understanding of secure software development practices and threat modeling (preferred).
• Relevant certifications such as Security+, SSCP, GSEC, or equivalent; CISSP, CISM, or CCSP preferred.
• Experience supporting grant-funded initiatives, multi-partner collaborations, or externally funded programs.
• Ability to communicate effectively in American Sign Language (preferred).
• Flexible work arrangements
• Professional development opportunities
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.