CO - P4644 - Compliance and Risk Analyst at Virginia Department of Environmental Quality
Richmond, Virginia, United States -
Full Time


Start Date

Immediate

Expiry Date

22 Jun, 26

Salary

90000.0

Posted On

24 Mar, 26

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Risk Assessment, Vulnerability Management, Compliance Monitoring, Incident Response, Business Impact Analysis, Security Awareness Training, GRC Tools, Cloud Security Compliance, Vulnerability Scanning, Remediation Coordination, Security Frameworks, Analytical Skills, Documentation Skills, Threat Analysis, Control Recommendation, Stakeholder Collaboration

Industry

Government Administration

Description
The Security Compliance and Risk Analyst plays a critical role in safeguarding the organization’s information assets by ensuring compliance with regulatory requirements, internal security policies, and industry best practices. This mid-level position serves as a key contributor to the cybersecurity program, focusing on risk assessment, vulnerability management, and compliance monitoring. The analyst is responsible for identifying and mitigating security risks, conducting vulnerability scans, analyzing results, and coordinating remediation efforts across multiple teams. Additionally, the role leads the coordination of the annual Business Impact Analysis (BIA) to support continuity planning, manages the agency’s security awareness training program, and maintains the Incident Response Playbook to ensure a structured and effective response to cybersecurity incidents. Success in this position requires a proactive approach to emerging threats, strong analytical skills, and the ability to collaborate effectively with technical and non-technical stakeholders. Please note this position follows a hybrid work schedule to include both in-office and telework. Candidates must be able to work from the assigned work location in Virginia.
Responsibilities
This role focuses on ensuring compliance with regulations and internal policies by conducting risk assessments, managing vulnerabilities, and monitoring compliance within the cybersecurity program. Key duties include leading the annual Business Impact Analysis, managing the security awareness training program, and maintaining the Incident Response Playbook.
Loading...