Information Security Risk and Compliance Analyst

Virginia Department of the Treasury

• $85K — $110K *
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Understanding of cybersecurity principles including network security, access control, and incident response basics.
  • Knowledge of NIST security frameworks and compliance standards.
  • Experience in developing System Security Plans per SEC 530 Standard or similar standards.
  • Excellent written communication skills for documentation of findings and procedures.
  • Strong analytical skills and attention to detail, especially in risk assessments.

Responsibilities

  • Create and maintain System Security Plans to outline security measures.
  • Develop and manage security awareness programs for employee training on best practices.
  • Identify and manage threats, vulnerabilities, and risk assessments to mitigate risks.
  • Coordinate internal and external audits to ensure compliance with security standards.
  • Build and update security documentation, policies, and procedures.

Benefits

  • Telework policy allows for up to two days a week, subject to position requirements.
  • Opportunity to grow cybersecurity expertise in a government setting.
Full Job Description
Information Security Risk and Compliance Analyst

Job no:
Work type: Full-Time (Salaried)
Location: Richmond (City), Virginia
Categories: Information Technology

Title: Information Security Risk and Compliance Analyst

State Role Title: Info Technology Specialist II

Hiring Range: $85,000 - $110,000; Commensurate with experience

Pay Band: 5

Agency: Department of the Treasury

Location: JAMES MONROE BUILDING

Agency Website: https://trs.virginia.gov

Recruitment Type: General Public - G

Job Duties

Are you passionate about cybersecurity and keeping systems that support the Commonwealth Treasury and ultimately the State secure? Are you curious, analytical, and motivated to learn, and interested in an opportunity to grow your cybersecurity expertise while serving the Commonwealth?

We are seeking a motivated and detail-oriented Information Security Risk and Compliance Analyst to support the agency's cybersecurity and risk management operations. This position plays a critical role in protecting the Commonwealth's financial systems, sensitive data, and technology infrastructure.

This is a mid-level role designed for someone who is building their cybersecurity career and has experience in compliance and risk management within a government environment.

The key responsibilities of the Information Security Risk and Compliance Analyst are:
Application Security
• Create and maintain System Security Plans
• Define security acceptance criteria that align with business requirements and security policies
• Document requirements for test environment and test accounts
• Develop and document test cases
• Execute security related test cases
• Support multi-factor authentication (MFA) and other identity verification mechanisms to strengthen access security.

Security Awareness & Training
• Develop, implement, and manage security awareness programs to educate employees on cybersecurity best practices.
• Create training materials, presentations, and campaigns that effectively communicate security policies and procedures.
• Analyze training metrics and reporting to identify gaps and continuously improve program effectiveness.
• Maintain familiarity with emerging threats and trends to keep awareness content current and relevant.
• Manage Treasury's annual training campaign to ensure compliance with SEC 527 and other relevant Commonwealth Standards.

Risk Management
• Identify threats and vulnerabilities
• Create and maintain risk assessments
• Manage Archer and other applicable risk registers
• Track remediation activities and corrective action plans

Governance, Compliance and Audit Support
• Verify alignment with Commonwealth of Virginia Information Security, NIST, and other applicable Standards
• Coordinate internal and external compliance audits
• Build and update security policies and procedures
• Maintain security documentation
• Develop reports and dashboards for leadership as requested

Minimum Qualifications

The selected candidate will possess the following qualifications:
• Understanding of cybersecurity principles, including:
o Network security fundamentals
o Access control concepts
o Malware and phishing threats
o Incident response basics
• Knowledge of NIST security frameworks and compliance standards
• Experience developing System Security Plans in accordance with SEC 530 Standard or similar
• Excellent written communication skills.
• Strong analytical and problem-solving skills.
• Ability to document findings clearly and concisely.
• Strong attention to detail and organizational skills.
• Ability to handle sensitive and confidential information appropriately.
• Experience working with development teams to develop and execute application security test plans.
• Strong understanding of Role-Based Access Control (RBAC), Least Privilege Principles, and Segregation of Duties.
• Familiarity with Multi-Factor Authentication (MFA) and Single Sign-On (SSO) technologies.

Additional Considerations
• Familiarity with common Governance, Risk, and Compliance security tools such as Archer.
• Experience in Information Security, Identity and Access Management (IAM)
• Experience in monitoring third-party risk.
• Familiarity with cloud environments (AWS, Azure, GCP) and their access control mechanisms.
• Experience working in a government or highly regulated environment

Special Instructions

You will be provided a confirmation of receipt when your application and/or résumé is submitted successfully. Please refer to "Your Application" in your account to check the status of your application for this position.

A résumé and cover letter are required to be submitted. Applications for this position must
be submitted electronically through this website.

The Department of the Treasury telework policy allows for up to two days a week of telework, subject to the position requirements. This position will be located in Richmond, Virginia, and must report on-site until the completion of an approved telework agreement is received.

All finalists are subject to a background investigation. The investigation may include: criminal checks; employment verification; verification of education; and other checks requested by the hiring authority.

Applicants who possess an Interagency Placement Screening Form (Yellow Form) or a Preferential Hiring Form (Blue Form) as issued under the Department of Human Resources Management (DHRM) Policy 1.30 Layoff (Commonwealth of Virginia Employees Only), must attach these forms with their state application.

Mailed, emailed, faxed, or hand delivered applications and résumés will not be accepted.

This website will provide a confirmation of receipt when the application is submitted for consideration.

Please refer to your RMS account for the status of your application and this position.

Contact Information

Name: Lori Perez

Phone: 804-225-3247

Email: [email protected]

Advertised: 27 Sep 2026 Eastern Daylight Time
Applications close: 11 Oct 2026 Eastern Daylight Time

Whatsapp Facebook LinkedIn Email App

Similar Jobs

More Education, Government & Non-Profit Jobs

Find similar Information Security Risk and Compliance Analyst jobs: