IT Compliance Analyst (BHJOB1435_35649)

Astyra Corporation
Harrisburg, PA, United States
27 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$35,360.0 - $45,760.0
Working hours
Regular working hours
Job source

Tech stack

Data Analysis Software Documentation Cyber Security Electronic Mailing Phishing Tools for Reporting

Job description

  • Under the direction of the IT Compliance and Risk Manager this position serves as a Security Awareness and Compliance Analyst.
  • The GRC function provides governance risk evaluation and compliance oversight to support informed decision-making and the responsible adoption of technology across the Commonwealth.
  • The Security Awareness and Compliance Analyst administers the organization’s Security Awareness and Phishing Program and supports governance risk and compliance initiatives.
  • The employee develops and coordinates security awareness activities manages phishing simulation campaigns analyzes program effectiveness and supports regulatory reporting while contributing to the overall maturity of the GRC program.

Responsibilities:

  • Administers and maintains the enterprise Security Awareness Program.
  • Plans coordinates and executes phishing simulation campaigns.
  • Tracks analyzes and reports security awareness and phishing metrics using established reporting tools.
  • Develops and distributes security awareness communications and educational materials.
  • Coordinates required cybersecurity awareness training activities across the organization.
  • Maintains awareness program documentation and records to support compliance and audit requirements.
  • Assists with preparation of reports supporting regulatory requirements audits and management reviews.
  • Recommends improvements to awareness activities based on metrics emerging threats and industry best practices.
  • Assists with governance risk and compliance initiatives as assigned.
  • Participates in continuous improvement activities supporting the organization’s cybersecurity program.
  • Performs related work as assigned.

Skills:

  • Plans, coordinates, and executes phishing simulation campaigns., Required
  • Administers and maintains the enterprise Security Awareness Program., Required
  • Develops and distributes security awareness communications and educational materials., Required
  • Maintains awareness program documentation and records to support compliance and audit requirements., Required
  • Assists with preparation of reports supporting regulatory requirements, audits, and management reviews., Required
  • Recommends improvements to awareness activities based on metrics, emerging threats, and industry best practices., Required
  • Knowledge and Abilities
  • Information security awareness principles
  • Cybersecurity fundamentals
  • Security awareness and phishing simulation platforms
  • Reporting and data analysis techniques
  • Compliance and audit support activitie
  • Ability to:
  • Coordinate multiple projects and training activities
  • Analyze program metrics and identify trends
  • Communicate effectively with diverse audiences
  • Develop user-friendly educational materials
  • Establish productive working relationships with agency staff

Proper email communication will only be done to and from @astyra.com email addresses. Please ensure you are communicating with approved Astyra recruiters by checking this point when receiving offers and messages from us. Please ensure you are communicating within these guidelines and proper channels for the quickest possible interview consideration!

Requirements

  • Are you a U.S. Citizen or Permanent Resident?
  • How many years of experience do you have with creating plans, coordinating, and executing phishing simulation campaigns?
  • How many years of experience do you have developing and distributing security awareness communications and educational materials?
  • How many years of experience do you have with assisting with preparation of reports supporting regulatory requirements, audits, and management reviews?
  • How many years of experience do you have in administering and maintaining a nenterprise Security Awareness Program?

Work Location: Hybrid remote in Harrisburg, PA 17120

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • Vision insurance
  • Dental insurance, * 401(k)
  • Dental insurance
  • Health insurance
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:48 min

Automating exploratory data analysis within training pipelines

Dora Petrella · World Congress 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

3:29 min

Forecasting organizational cybersecurity risks through public employee reviews

Videos

See all

Related articles

See all