Senior IT and Security Governance Analyst

Communication Service for the Deaf
United States
13 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$80,000.0 - $90,000.0
Working hours
Regular working hours
Languages
American Sign Language
Job source

Tech stack

Amazon Web Services Microsoft Azure Backup Devices Software as a Service Cloud Computing Cloud Computing Security Cyber Security Continuous Integration Data Governance Identity and Access Management IT Management Information Technology Operations
+16 more
Information Systems Security Architecture Professional Key Management Network Security PCI Data Security Standards Systems Development Life Cycle Role-Based Access Control Security Information and Event Management Software Engineering Data Streaming Software Vulnerability Management Data Logging Data Processing Information Technology Operational Systems Data Management Vulnerability Analysis

Job description

The Senior IT & Security Governance Analyst is responsible for advancing technology governance, security, and operational maturity initiatives across corporate IT, cloud and product environments, and operational systems. This role serves as a subject matter expert in governance, security controls, data stewardship, and operational risk management, partnering across the organization to strengthen processes, improve resilience, and support sustainable growth.

This position operationalizes compliance frameworks as structured tools to enhance efficiency, accountability, and resilience-leveraging them to improve processes, mitigate risk, and elevate overall technology governance rather than treating compliance as the sole objective., * Contribute to the development and maintenance of the organization’s IT and security roadmap aligned with mission priorities and partner obligations.

  • Maintain the technology risk register, including security, data, vendor, and operational risks, while tracking remediation activities.
  • Develop, document, and maintain IT and security policies, standards, and procedures.
  • Maintain system ownership documentation, governance records, and technology inventories.
  • Prepare technology governance metrics, risk reports, and audit readiness documentation for leadership.

Data Governance & System Oversight

  • Implement and maintain data classification, access governance, and retention standards.
  • Document and maintain key data flows across internal systems, partner integrations, and cloud environments.
  • Evaluate encryption, logging, and access controls to ensure alignment with data sensitivity and contractual requirements.
  • Partner with Engineering and program teams to implement secure, scalable system design practices.
  • Maintain architecture documentation, data flow diagrams, and security control mappings.

Identity, Access & Organizational IT Foundations

  • Administer identity and access management processes, including SSO, MFA, least privilege, access reviews, and joiner-mover-leaver workflows.
  • Coordinate endpoint and device management practices including MDM, encryption, patching, configuration baselines, and endpoint protection.
  • Evaluate SaaS governance practices and recommend improvements to reduce shadow IT risk.
  • Validate backup, recovery, and resilience capabilities for critical systems.
  • Serve as a technical resource for departments on security and data handling best practices.

Cloud, Application & Vulnerability Management

  • Partner with Engineering to implement Secure SDLC practices.
  • Coordinate vulnerability management activities, including scanning, triage, prioritization, remediation tracking, and verification.
  • Maintain cloud security guardrails, including IAM standards, key management, logging, monitoring, and network security controls.
  • Participate in secure architecture and security reviews for new systems and major technology initiatives.

Incident Response, Vendor Risk & Partner Assurance

  • Maintain incident response documentation, runbooks, and severity classifications.
  • Coordinate tabletop exercises and track remediation activities through completion.
  • Support business continuity and disaster recovery testing and validation.
  • Coordinate vendor and partner security assessments and document remediation activities.
  • Support audits, customer security questionnaires, and partner assurance initiatives.
  • Partner with Legal and business stakeholders to implement data protection and security requirements.
  • Other duties as assigned.

Requirements

  • Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field, or a minimum of five (5) years of progressively responsible experience in IT governance, cybersecurity, IT operations, or risk management.
  • Experience working across multiple IT and security domains.
  • Strong understanding of IAM principles including SSO, MFA, least privilege, and access reviews.
  • Working knowledge of logging, endpoint security, encryption, backup management, vulnerability management, and network security.
  • Experience implementing IT, data, or security governance initiatives.
  • Demonstrated ability to analyze complex technical risks and develop practical recommendations.
  • Proven ability to independently lead cross-functional technical initiatives while collaborating effectively.
  • Experience supporting audits or security frameworks such as PCI DSS, SOC 2, ISO 27001, NIST 800-53 Rev. 5, or HIPAA-adjacent controls (preferred).
  • Experience with AWS, Azure, or GCP and CI/CD environments (preferred).
  • Experience with MDM, EDR, SIEM, vulnerability scanners, and related tooling (preferred).
  • Familiarity with secure software development practices and threat modeling (preferred).
  • Relevant certifications such as Security+, SSCP, GSEC, or equivalent; CISSP, CISM, or CCSP preferred.
  • Experience supporting grant-funded initiatives, multi-partner collaborations, or externally funded programs.
  • Ability to communicate effectively in American Sign Language (preferred)

Benefits & conditions

United States Remote $80,000 - $90,000 a year

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:11 min

Establishing secure recovery factors without password fallbacks

Clemens Hübner Clemens Hübner · WWC 2023

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · WWC 2025

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

5:00 min

Managing complex state with scope-based resource management

Bjarne Stroustrup · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all