IT Compliance Analyst

Virginia Community Colleges

• $95K — $105K *
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in cybersecurity operations, risk management, or compliance enforcement.
  • Knowledge of IT cybersecurity and privacy principles with control requirements for FERPA, HIPAA, PCI DSS, GLBA, and CIS Controls.
  • Strong analytical skills with attention to detail for reviewing policies and conducting risk assessments.
  • Experience in third-party risk management and validating controls through collaboration with vendors and technical teams.
  • Ability to create and administer cybersecurity awareness and compliance training programs.

Responsibilities

  • Implement, monitor, and maintain cybersecurity controls and compliance processes.
  • Regularly review and update cybersecurity policies, procedures, and guidelines.
  • Manage the Third-Party Risk Management (TPRM) policies and processes.
  • Conduct internal cybersecurity assessments and report on control readiness.
  • Develop and implement IT compliance and data privacy training programs.

Benefits

  • Full-time position with standard work week (Monday to Friday) totaling 40 hours.
  • Opportunities for professional development and continuing education.
  • Work environment dedicated to ensuring compliance with federal and state regulations.
Full Job Description
Posting Details

Posting Summary

Working Title
IT Compliance Analyst

Role Title
Policy Planning Spcialst II

Role Code
19132-FP

FLSA
Exempt

Pay Band
05

Position Number
28000957

Agency
Northern VA Community College

Division
NV280-VP of College Computing

Work Location
Fairfax County - 059

Hiring Range
$95,000 - $105,000

Emergency/Essential Personnel
No

EEO Category
5-Paraprofessionals

Full Time or Part Time
Full Time

Does this position have telework options? -Telework options are subject to change based on business needs-
No

Does this position have a bilingual or multilingual skill requirement or preference?

Work Schedule

Monday thru Friday (Standard work week). 8 hours per day.

Sensitive Position
No

Job Description

General Description:
The IT Compliance Analyst is responsible for protecting the organization's digital assets by implementing, monitoring, and maintaining robust cybersecurity controls, systems, and compliance processes. This role ensures that the institution's information technology systems, processes, and data practices comply with applicable federal and state regulations, industry standards, and institutional policies.

Duties and Responsibilities:
  • Regulatory Compliance & Policy Management: Performs regular reviews, updates, and version control of cybersecurity policies, procedures, standards, guidelines, and supporting documentation.
  • Vendor & Third-Party Risk Management (TPRM): Review, update, and maintain Third-Party Risk Management (TPRM) policies and processes.
  • Cybersecurity Assessments & Internal Controls Preparedness: Track gaps in Internal Controls, ensuring timely follow-up by responsible parties, and prepare readiness reports for senior IT leadership.
  • Security Awareness & Compliance Training: Develop and deliver IT compliance and data privacy training programs (e.g., FERPA, cybersecurity awareness); and track completion rates institution wide.
  • Risk Management & Data Privacy: Conduct periodic IT risk assessments and Privacy Impact Assessments


Special Assignments

May be required to perform other duties as assigned. May be required to assist the agency or state government generally in the event of an emergency declaration by the Governor.

KSA's/Required Qualifications

KSA Requirements:
  • Knowledge, and a capability for clear, concise technical reporting and cross-functional collaboration.
  • Knowledge of IT cybersecurity and privacy principles, including the control requirements of FERPA, HIPAA, PCI DSS, GLBA, and CIS Controls.
  • Demonstrated analytical skills and attention to detail in reviewing cybersecurity policies, procedures, and standards; conducting maturity and risk assessments; and managing supporting compliance evidence.
  • Ability to collaborate with technical teams, vendors, and third-party providers to validate controls and collect compliance evidence (e.g., HECVAT questionnaires, SOC 2 / reports) in support of the Third-Party Risk Management program.
  • Ability to administer security awareness and compliance training programs, including phishing simulations and institution-wide campaigns, and to track completion across the organization.


Minimum Work Experience:
  • Experience in cybersecurity operations, IT security analysis, risk management, or compliance enforcement.
  • Experience implementing and aligning controls with major security frameworks (e.g., NIST CSF, CIS Controls, PCI DSS, FERPA, HIPAA).
  • Hands-on experience using security, compliance, or administrative tools (e.g., KnowBe4, MS Attack Simulator, CIS CSAT, TeamDynamix)


Additional Considerations

Additional Considerations:
  • Experience working within a higher education institution or public sector environment.
  • One or more professional certifications such as CompTIA Security+, CompTIA Project+ or ITIL 4 Foundation.
  • Familiarity with GRC (Governance, Risk, and Compliance) platforms or learning management systems (e.g., Canvas).


Operation of a State Vehicle
No

Supervises Employees
No

Required Travel

n/a

Posting Detail Information

Posting Number
CLS_4773P

Recruitment Type
General Public - G

Number of Vacancies
1

Position End Date (if temporary)

Job Open Date
09/24/2026

Job Close Date
10/08/2026

Open Until Filled

Agency Website
www.nvcc.edu

Contact Name

Email

Phone Number

Special Instructions to Applicants

In support of the Commonwealth's commitment to inclusion, we are encouraging individuals with disabilities to apply through the Commonwealth's Alternative Hiring Process. To be considered for this opportunity, applicants will need to provide their AHP Letter (formerly called a Certificate of Disability) provided by the Department for Aging & Rehabilitative Services (DARS), or the Department for the Blind & Vision Impaired (DBVI). Service-Connected Veterans may also apply via the AHP if they also provide an AHP Letter. To request an AHP Letter, use this link: https://www.dars.virginia.gov/drs/cpid/PWContact.aspx or call DARS at 800-552-5019, or DBVI at 800-622-2155

Quicklink for Posting
https://jobs.vccs.edu/postings/101621

Similar Jobs

More Jobs at Virginia Community Colleges

More Education, Government & Non-Profit Jobs

Find similar IT Compliance Analyst jobs: