IT Security Risk and Compliance Analyst

Virginia Tech

$80K — $94K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Master's degree or equivalent education and experience
  • Experience in IT security reviews, risk assessments, or audits
  • Strong grasp of key information security concepts
  • Ability to raise security practice awareness among technical teams
  • Familiarity with security frameworks like NIST and PCI-DSS
  • Effective communication skills for diverse audiences
  • Strong organizational and time-management abilities

Responsibilities

  • Conduct IT security assessments and risk reviews for various departments
  • Evaluate third-party technology solutions for compliance
  • Develop asset inventories and assess endpoint security controls
  • Create and maintain documentation for IT Risk and Compliance programs
  • Identify automation opportunities to enhance process efficiency
  • Provide training and outreach to the university community
  • Coordinate updates for the IT Continuity of Operations plan

Benefits

  • Hybrid work model with required on-site presence at least once a week
  • Opportunity for professional development and training
  • Engagement with a diverse university community
  • Chance to work within a supportive IT risk and compliance team
  • Possibility for involvement in disaster recovery planning initiatives
Full Job Description
IT Security Risk and Compliance Analyst

Job no: 537580
Work type: Administrative & Professional
Senior management: Vice President-Info Technology
Department: IT Security
Location: Blacksburg, Virginia, Hybrid
Categories: Information Systems / Technology

Job Description

Under the guidance of the Associate Director of IT Risk and Compliance, the IT Security Risk and Compliance Analyst will carry out IT security assessment activities including IT risk assessments and security reviews for university departments, as well as evaluations of third-party technology solutions, to ensure alignment with university policies, standards, and external compliance regulations wherever applicable. Assessment activities may include a wide variety of tasks depending on the scope of the review and the IT capabilities within university departments (e.g., developing asset inventory, assessing endpoint and application security controls and configurations, examining procedures, etc.).

The analyst will be expected to contribute to the creation and maintenance of documentation/procedures in support of the IT Risk and Compliance program and to identify opportunities to leverage automation to enhance data consistency and process efficiency within the program and across other university IT services. The analyst may provide training and outreach to the university community as needed and may also be called on to coordinate updates for the IT Continuity of Operations plan and to assist units within the Division of Information Technology as they conduct disaster recovery planning or on other security-related initiatives as requested.

Required Qualifications
• Master's degree, or a combination of education, training, and progressive experience that equates to a Master's degree.
• Demonstrated experience performing IT security reviews, risk assessments, or audits
• Strong understanding of key information security concepts and fundamentals
• Experience in creating awareness of security practices across multiple technical teams
• Knowledge of security frameworks and standards, including NIST, PCI-DSS, ISO 27001, CIS Critical Security Controls, NIST Cybersecurity Framework (NIST CSF), etc.
• Ability to effectively communicate across a broad range of campus audiences
• Exceptional organizational and time-management skills

Preferred Qualifications
• Professional certification such as CISA, CISM, CRISC, or CISSP
• Experience performing security assessments of SaaS services
• Knowledgeable of relevant compliance regulations (e.g., FERPA, GLBA)
• Experience with GRC and Information security tools/technologies to collect and maintain security and risk information
• Experience with automation using common scripting tools (e.g., Python, PowerShell, Bash, etc.)
• Experience with data analysis and manipulation
• Experience managing IT security risk or compliance in a higher education setting

Work Location

Candidates must be available for on-site work in Blacksburg, VA as needed, with at least one on-site day per week.

Overtime Status

Exempt: Not eligible for overtime

Appointment Type

Regular

Salary Information

$80,000 - $94,000

Hours per week

40

Review Date

9/24/2026

Additional Information

Sponsorship is not available for this role.

The successful candidate will be required to have a criminal conviction check.

Advertised: September 17, 2026
Applications close: September 24, 2026 Eastern Daylight Time

Whatsapp Facebook LinkedIn Email App

Similar Jobs

More Jobs at Virginia Tech

More Information Technology Jobs

Find similar IT Security Risk and Compliance Analyst jobs: