Information Security Risk and Compliance Analyst
Job no: 5112706
Position type: Full-Time (Salaried)
Location: Richmond (City), Virginia
Division/Equivalent: Department of the Treasury
School/Unit: Department of the Treasury
Department/Office: General Management
Categories: Information Technology
Title: Information Security Risk and Compliance Analyst
State Role Title: Info Technology Specialist II
Hiring Range: $85,000 - $110,000; Commensurate with experience
Pay Band: 5
Agency: Department of the Treasury
Location: JAMES MONROE BUILDING
Agency Website: https://trs.virginia.gov
Recruitment Type: General Public - G
Job Duties
Are you passionate about cybersecurity and keeping systems that support the Commonwealth Treasury and ultimately the State secure? Are you curious, analytical, and motivated to learn, and interested in an opportunity to grow your cybersecurity expertise while serving the Commonwealth?
The Virginia Department of the Treasury is dedicated to serving the Commonwealth by providing excellent management of its banking, investing, and financing services, and the administration of unclaimed property and insurance programs.
We are seeking a motivated and detail-oriented Information Security Risk and Compliance Analyst to support the agency’s cybersecurity and risk management operations. This position plays a critical role in protecting the Commonwealth’s financial systems, sensitive data, and technology infrastructure.
This is a mid-level role designed for someone who is building their cybersecurity career and has experience in compliance and risk management within a government environment.
The key responsibilities of the Information Security Risk and Compliance Analyst are:
Application Security
• Create and maintain System Security Plans
• Define security acceptance criteria that align with business requirements and security policies
• Document requirements for test environment and test accounts
• Develop and document test cases
• Execute security related test cases
• Support multi-factor authentication (MFA) and other identity verification mechanisms to strengthen access security.
Security Awareness & Training
• Develop, implement, and manage security awareness programs to educate employees on cybersecurity best practices.
• Create training materials, presentations, and campaigns that effectively communicate security policies and procedures.
• Analyze training metrics and reporting to identify gaps and continuously improve program effectiveness.
• Maintain familiarity with emerging threats and trends to keep awareness content current and relevant.
• Manage Treasury’s annual training campaign to ensure compliance with SEC 527 and other relevant Commonwealth Standards.
Risk Management
• Identify threats and vulnerabilities
• Create and maintain risk assessments
• Manage Archer and other applicable risk registers
• Track remediation activities and corrective action plans
Governance, Compliance and Audit Support
• Verify alignment with Commonwealth of Virginia Information Security, NIST, and other applicable Standards
• Coordinate internal and external compliance audits
• Build and update security policies and procedures
• Maintain security documentation
• Develop reports and dashboards for leadership as requested
Minimum Qualifications
The selected candidate will possess the following qualifications:
• Understanding of cybersecurity principles, including:
o Network security fundamentals
o Access control concepts
o Malware and phishing threats
o Incident response basics
• Knowledge of NIST security frameworks and compliance standards
• Experience developing System Security Plans in accordance with SEC 530 Standard or similar
• Excellent written communication skills.
• Strong analytical and problem-solving skills.
• Ability to document findings clearly and concisely.
• Strong attention to detail and organizational skills.
• Ability to handle sensitive and confidential information appropriately.
• Experience working with development teams to develop and execute application security test plans.
• Strong understanding of Role-Based Access Control (RBAC), Least Privilege Principles, and Segregation of Duties.
• Familiarity with Multi-Factor Authentication (MFA) and Single Sign-On (SSO) technologies.
Additional Considerations
• Familiarity with common Governance, Risk, and Compliance security tools such as Archer.
• Experience in Information Security, Identity and Access Management (IAM)
• Experience in monitoring third-party risk.
• Familiarity with cloud environments (AWS, Azure, GCP) and their access control mechanisms.
• Experience working in a government or highly regulated environment
Special Instructions
You will be provided a confirmation of receipt when your application and/or résumé is submitted successfully. Please refer to “Your Application” in your account to check the status of your application for this position.
A résumé and cover letter are required to be submitted. Applications for this position must
be submitted electronically through this website.
The Department of the Treasury telework policy allows for up to two days a week of telework, subject to the position requirements. This position will be located in Richmond, Virginia, and must report on-site until the completion of an approved telework agreement is received.
All finalists are subject to a background investigation. The investigation may include: criminal checks; employment verification; verification of education; and other checks requested by the hiring authority.
Applicants who possess an Interagency Placement Screening Form (Yellow Form) or a Preferential Hiring Form (Blue Form) as issued under the Department of Human Resources Management (DHRM) Policy 1.30 Layoff (Commonwealth of Virginia Employees Only), must attach these forms with their state application.
Mailed, emailed, faxed, or hand delivered applications and résumés will not be accepted.
This website will provide a confirmation of receipt when the application is submitted for consideration.
Please refer to your RMS account for the status of your application and this position.
The Virginia Department of the Treasury is an Equal Opportunity Employer.
Contact Information
Name: Lori Perez
Phone: 804-225-3247
Email: HR@trs.virginia.gov
In support of the Commonwealth’s commitment to inclusion, we are encouraging individuals with disabilities to apply through the Commonwealth Alternative Hiring Process. To be considered for this opportunity, applicants will need to provide their AHP Letter (formerly COD) provided by the Department for Aging & Rehabilitative Services (DARS), or the Department for the Blind & Vision Impaired (DBVI). Service-Connected Veterans are encouraged to answer Veteran status questions and submit their disability documentation, if applicable, to DARS/DBVI to get their AHP Letter. Requesting an AHP Letter can be found at AHP Letter or by calling DARS at 800-552-5019.
Note: Applicants who received a Certificate of Disability from DARS or DBVI dated between April 1, 2022- February 29, 2024, can still use that COD as applicable documentation for the Alternative Hiring Process.
Advertised: Eastern Daylight Time
Application close: Eastern Daylight Time
Apply now