Southern New Hampshire University logo
Southern New Hampshire University
Posted 5 days agoVerified live 2d ago

Information Security Control Assurance Analyst

Brief overview

Remote
UndergradOr in progress
$60k–$96k/yrStated range
3+ yrsMinimum
Security Control AssessmentNIST Frameworks and StandardsRisk Management Framework (RMF)Information Security Policies, Standards, and ProceduresInternal and External AuditsInformation Security and Data Protection RegulationsPlans of Action and Milestones (POA&Ms)ITIL

About the company

Southern New Hampshire University logo
Southern New Hampshire Universitysnhu.edu

Founded in 1932, Southern New Hampshire University has grown from a small school of accounting and secretarial science into one of the nation’s largest nonprofit, accredited universities.

Job description

Summary

Southern New Hampshire University is a team of innovators focused on transforming lives through education. The Information Security Control Assurance Analyst leads security assessment, authorization, risk, and compliance activities, including evaluating controls, managing remediation plans, supporting audits, and maintaining security governance documentation.

Responsibilities

  • Lead and perform information security risk and compliance assessments to evaluate the effectiveness of technical, administrative, and physical security controls across University systems and services
  • Develop, maintain, and review System Security Plans (SSPs), risk assessments, and supporting documentation in alignment with applicable security frameworks and regulatory requirements
  • Identify control gaps and security deficiencies, assess associated risk, and document findings with clear, actionable recommendations
  • Manage and oversee Plans of Action and Milestones (POA&Ms), including tracking remediation activities, validating corrective actions, and reporting progress to stakeholders
  • Coordinate and support internal and external audits and assessments, including evidence collection, validation, and response management
  • Monitor and interpret changes in federal and state information security and data privacy laws, regulations, and contractual requirements, and assess organizational impact
  • Develop, update, and maintain information security policies, standards, procedures, and governance documentation to ensure ongoing compliance and operational effectiveness
  • Partner closely with ISMO, Privacy, Legal, and business stakeholders to translate regulatory and security requirements into practical, implementable controls and processes
  • Prepare and deliver compliance, risk, and audit reporting to management and leadership to support informed decision-making
  • Contribute to continuous improvement of the University's information security governance, risk management, and compliance programs

Skills

  • 3 years of experience in a related field
  • Completion of a Bachelor's Degree or working toward a degree in a related field
  • Equivalent of experience in lieu of degree acceptable
  • Demonstrated understanding of technical, administrative, and physical information security controls and how they are applied to manage risk across enterprise systems and services
  • Strong knowledge of information security governance, risk management, and compliance principles, including the ability to assess control effectiveness and identify compliance gaps
  • Working knowledge of NIST frameworks and standards (including NIST SP 800-53, 800-171, and the Risk Management Framework) and their application in assessment, authorization, and continuous monitoring activities
  • Familiarity with federal and state regulatory requirements and higher education compliance obligations related to information security and data protection (e.g., GLBA, FERPA, Simplified FAFSA Act)
  • Advanced understanding of information security policies, standards, procedures, and governance documentation, including development, maintenance, and implementation
  • Experience supporting internal and external audits, including evidence collection, documentation review, and response coordination
  • Ability to translate complex regulatory and technical security requirements into practical, implementable controls and processes for technical and non-technical stakeholders
  • Working understanding of IT service management concepts and best practices (e.g., ITIL) as they relate to security operations, controls, and risk management

Qualifications

Must Haves

  • 3 years of experience in a related field
  • Completion of a Bachelor's Degree or working toward a degree in a related field
  • Equivalent of experience in lieu of degree acceptable
  • Demonstrated understanding of technical, administrative, and physical information security controls and how they are applied to manage risk across enterprise systems and services
  • Strong knowledge of information security governance, risk management, and compliance principles, including the ability to assess control effectiveness and identify compliance gaps
  • Working knowledge of NIST frameworks and standards (including NIST SP 800-53, 800-171, and the Risk Management Framework) and their application in assessment, authorization, and continuous monitoring activities
  • Familiarity with federal and state regulatory requirements and higher education compliance obligations related to information security and data protection (e.g., GLBA, FERPA, Simplified FAFSA Act)
  • Advanced understanding of information security policies, standards, procedures, and governance documentation, including development, maintenance, and implementation
  • Experience supporting internal and external audits, including evidence collection, documentation review, and response coordination
  • Ability to translate complex regulatory and technical security requirements into practical, implementable controls and processes for technical and non-technical stakeholders
  • Working understanding of IT service management concepts and best practices (e.g., ITIL) as they relate to security operations, controls, and risk management

Benefits

  • 100% remotely from any of our approved states
  • High-quality, low-deductible medical insurance
  • Low to no-cost dental and vision plans
  • 5 weeks of paid time off (plus almost a dozen paid holidays)
  • Employer-funded retirement
  • Free tuition program
  • Parental leave
  • Mental health and wellbeing resources

More jobs like this