Summary
Southern New Hampshire University is a team of innovators focused on transforming lives through education. The Information Security Control Assurance Analyst leads security assessment, authorization, risk, and compliance activities, including evaluating controls, managing remediation plans, supporting audits, and maintaining security governance documentation.
Responsibilities
- Lead and perform information security risk and compliance assessments to evaluate the effectiveness of technical, administrative, and physical security controls across University systems and services
- Develop, maintain, and review System Security Plans (SSPs), risk assessments, and supporting documentation in alignment with applicable security frameworks and regulatory requirements
- Identify control gaps and security deficiencies, assess associated risk, and document findings with clear, actionable recommendations
- Manage and oversee Plans of Action and Milestones (POA&Ms), including tracking remediation activities, validating corrective actions, and reporting progress to stakeholders
- Coordinate and support internal and external audits and assessments, including evidence collection, validation, and response management
- Monitor and interpret changes in federal and state information security and data privacy laws, regulations, and contractual requirements, and assess organizational impact
- Develop, update, and maintain information security policies, standards, procedures, and governance documentation to ensure ongoing compliance and operational effectiveness
- Partner closely with ISMO, Privacy, Legal, and business stakeholders to translate regulatory and security requirements into practical, implementable controls and processes
- Prepare and deliver compliance, risk, and audit reporting to management and leadership to support informed decision-making
- Contribute to continuous improvement of the University's information security governance, risk management, and compliance programs
Skills
- 3 years of experience in a related field
- Completion of a Bachelor's Degree or working toward a degree in a related field
- Equivalent of experience in lieu of degree acceptable
- Demonstrated understanding of technical, administrative, and physical information security controls and how they are applied to manage risk across enterprise systems and services
- Strong knowledge of information security governance, risk management, and compliance principles, including the ability to assess control effectiveness and identify compliance gaps
- Working knowledge of NIST frameworks and standards (including NIST SP 800-53, 800-171, and the Risk Management Framework) and their application in assessment, authorization, and continuous monitoring activities
- Familiarity with federal and state regulatory requirements and higher education compliance obligations related to information security and data protection (e.g., GLBA, FERPA, Simplified FAFSA Act)
- Advanced understanding of information security policies, standards, procedures, and governance documentation, including development, maintenance, and implementation
- Experience supporting internal and external audits, including evidence collection, documentation review, and response coordination
- Ability to translate complex regulatory and technical security requirements into practical, implementable controls and processes for technical and non-technical stakeholders
- Working understanding of IT service management concepts and best practices (e.g., ITIL) as they relate to security operations, controls, and risk management
Qualifications
Must Haves
- 3 years of experience in a related field
- Completion of a Bachelor's Degree or working toward a degree in a related field
- Equivalent of experience in lieu of degree acceptable
- Demonstrated understanding of technical, administrative, and physical information security controls and how they are applied to manage risk across enterprise systems and services
- Strong knowledge of information security governance, risk management, and compliance principles, including the ability to assess control effectiveness and identify compliance gaps
- Working knowledge of NIST frameworks and standards (including NIST SP 800-53, 800-171, and the Risk Management Framework) and their application in assessment, authorization, and continuous monitoring activities
- Familiarity with federal and state regulatory requirements and higher education compliance obligations related to information security and data protection (e.g., GLBA, FERPA, Simplified FAFSA Act)
- Advanced understanding of information security policies, standards, procedures, and governance documentation, including development, maintenance, and implementation
- Experience supporting internal and external audits, including evidence collection, documentation review, and response coordination
- Ability to translate complex regulatory and technical security requirements into practical, implementable controls and processes for technical and non-technical stakeholders
- Working understanding of IT service management concepts and best practices (e.g., ITIL) as they relate to security operations, controls, and risk management
Benefits
- 100% remotely from any of our approved states
- High-quality, low-deductible medical insurance
- Low to no-cost dental and vision plans
- 5 weeks of paid time off (plus almost a dozen paid holidays)
- Employer-funded retirement
- Free tuition program
- Parental leave
- Mental health and wellbeing resources