IT Compliance Analyst

Virginia Community Colleges

• $95K — $105K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in cybersecurity operations, IT security analysis, risk management, or compliance enforcement.
  • Proficient in implementing controls aligned with NIST CSF, PCI DSS, FERPA, and HIPAA frameworks.
  • Hands-on experience with security and compliance tools like KnowBe4 and MS Attack Simulator.
  • Strong analytical skills with a focus on detail in cybersecurity policy review and risk assessments.
  • Ability to report technical findings clearly and to collaborate cross-functionally.
  • Familiarity with Governance, Risk, and Compliance (GRC) platforms.

Responsibilities

  • Perform regular reviews and updates of cybersecurity policies and procedures.
  • Manage Third-Party Risk Management (TPRM) processes and documentation.
  • Identify and track gaps in internal controls, preparing reports for IT leadership.
  • Develop and deliver compliance and data privacy training programs across the institution.
  • Conduct periodic IT risk assessments and Privacy Impact Assessments.

Benefits

  • Full-time employment with a standard Monday to Friday schedule.
  • Opportunities for professional development within the agency.
  • Engagement in important cybersecurity initiatives within the education sector.
Full Job Description
Posting Details

Posting Summary

Working Title
IT Compliance Analyst

Role Title
Policy Planning Spcialst II

Role Code
19132-FP

FLSA
Exempt

Pay Band
05

Position Number
28000957

Agency
Northern VA Community College

Division
NV280-VP of College Computing

Work Location
Fairfax County - 059

Hiring Range
$95,000 - $105,000

Emergency/Essential Personnel
No

EEO Category
5-Paraprofessionals

Full Time or Part Time
Full Time

Does this position have telework options? -Telework options are subject to change based on business needs-
No

Does this position have a bilingual or multilingual skill requirement or preference?

Work Schedule

Monday thru Friday (Standard work week). 8 hours per day.

Sensitive Position
No

Job Description

General Description:
The IT Compliance Analyst is responsible for protecting the organization's digital assets by implementing, monitoring, and maintaining robust cybersecurity controls, systems, and compliance processes. This role ensures that the institution's information technology systems, processes, and data practices comply with applicable federal and state regulations, industry standards, and institutional policies.

Duties and Responsibilities:
  • Regulatory Compliance & Policy Management: Performs regular reviews, updates, and version control of cybersecurity policies, procedures, standards, guidelines, and supporting documentation.
  • Vendor & Third-Party Risk Management (TPRM): Review, update, and maintain Third-Party Risk Management (TPRM) policies and processes.
  • Cybersecurity Assessments & Internal Controls Preparedness: Track gaps in Internal Controls, ensuring timely follow-up by responsible parties, and prepare readiness reports for senior IT leadership.
  • Security Awareness & Compliance Training: Develop and deliver IT compliance and data privacy training programs (e.g., FERPA, cybersecurity awareness); and track completion rates institution wide.
  • Risk Management & Data Privacy: Conduct periodic IT risk assessments and Privacy Impact Assessments


Special Assignments

May be required to perform other duties as assigned. May be required to assist the agency or state government generally in the event of an emergency declaration by the Governor.

KSA's/Required Qualifications

KSA Requirements:
  • Knowledge, and a capability for clear, concise technical reporting and cross-functional collaboration.
  • Knowledge of IT cybersecurity and privacy principles, including the control requirements of FERPA, HIPAA, PCI DSS, GLBA, and CIS Controls.
  • Demonstrated analytical skills and attention to detail in reviewing cybersecurity policies, procedures, and standards; conducting maturity and risk assessments; and managing supporting compliance evidence.
  • Ability to collaborate with technical teams, vendors, and third-party providers to validate controls and collect compliance evidence (e.g., HECVAT questionnaires, SOC 2 / reports) in support of the Third-Party Risk Management program.
  • Ability to administer security awareness and compliance training programs, including phishing simulations and institution-wide campaigns, and to track completion across the organization.


Minimum Work Experience:
  • Experience in cybersecurity operations, IT security analysis, risk management, or compliance enforcement.
  • Experience implementing and aligning controls with major security frameworks (e.g., NIST CSF, CIS Controls, PCI DSS, FERPA, HIPAA).
  • Hands-on experience using security, compliance, or administrative tools (e.g., KnowBe4, MS Attack Simulator, CIS CSAT, TeamDynamix)


Additional Considerations

Additional Considerations:
  • Experience working within a higher education institution or public sector environment.
  • One or more professional certifications such as CompTIA Security+, CompTIA Project+ or ITIL 4 Foundation.
  • Familiarity with GRC (Governance, Risk, and Compliance) platforms or learning management systems (e.g., Canvas).


Operation of a State Vehicle
No

Supervises Employees
No

Required Travel

n/a

Posting Detail Information

Posting Number
CLS_4773P

Recruitment Type
General Public - G

Number of Vacancies
1

Position End Date (if temporary)

Job Open Date
09/24/2026

Job Close Date
10/08/2026

Open Until Filled

Agency Website
www.nvcc.edu

Contact Name

Email

Phone Number

Special Instructions to Applicants

In support of the Commonwealth's commitment to inclusion, we are encouraging individuals with disabilities to apply through the Commonwealth's Alternative Hiring Process. To be considered for this opportunity, applicants will need to provide their AHP Letter (formerly called a Certificate of Disability) provided by the Department for Aging & Rehabilitative Services (DARS), or the Department for the Blind & Vision Impaired (DBVI). Service-Connected Veterans may also apply via the AHP if they also provide an AHP Letter. To request an AHP Letter, use this link: https://www.dars.virginia.gov/drs/cpid/PWContact.aspx or call DARS at 800-552-5019, or DBVI at 800-622-2155

Quicklink for Posting
https://jobs.vccs.edu/postings/101621

Similar Jobs

More Jobs at Virginia Community Colleges

More Healthcare Jobs

Find similar IT Compliance Analyst jobs: