IT Compliance Specialist

DevCare Solutions
Harrisburg, PA, United States
26 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$49,920.0 - $62,400.0
Working hours
Regular working hours
Job source

Tech stack

Software Documentation Information Security Management Smartsuite Phishing

Job description

We are seeking a Security Awareness & Compliance Analyst to support the Commonwealth of Pennsylvania’s Enterprise Information Security Office (EISO) within the Governance, Risk, and Compliance (GRC) function.

This position will focus on administering the organization’s Security Awareness and Phishing Program while supporting cybersecurity governance, risk, compliance, audit, and continuous improvement initiatives.

The ideal candidate will have hands-on experience with security awareness programs, phishing simulations, cybersecurity training, compliance reporting, security metrics, and audit support., * Administer and maintain the enterprise Security Awareness Program.

  • Plan, coordinate, and execute phishing simulation campaigns.
  • Track, analyze, and report security awareness and phishing metrics.
  • Monitor campaign results and identify trends and areas for improvement.
  • Develop and distribute security awareness communications and educational materials.
  • Coordinate required cybersecurity awareness training across the organization.
  • Maintain security awareness documentation and records for compliance and audit purposes.
  • Assist with regulatory reporting, audits, management reviews, and compliance activities.
  • Recommend improvements to security awareness initiatives based on metrics, emerging threats, and industry best practices.
  • Support Governance, Risk, and Compliance (GRC) initiatives as assigned.
  • Participate in cybersecurity program maturity and continuous improvement activities.
  • Collaborate with agency staff and stakeholders across the organization.
  • Perform other related duties as assigned.

Requirements

Candidates should have experience with one or more of the following:

  • Security Awareness Programs
  • Phishing Simulation Campaigns
  • Cybersecurity Awareness Training
  • Security Awareness Communications
  • Security Compliance
  • GRC / Governance, Risk & Compliance
  • Audit and regulatory support
  • Security metrics and reporting
  • Risk assessment and cybersecurity fundamentals

Required Experience

The successful candidate should be able to demonstrate experience in:

  • Planning, coordinating, and executing phishing simulation campaigns
  • Administering and maintaining an enterprise Security Awareness Program
  • Developing and distributing security awareness communications and educational materials
  • Maintaining program documentation and records for compliance and audits
  • Preparing reports for regulatory requirements, audits, and management reviews
  • Using security awareness metrics, emerging threats, and industry best practices to recommend program improvements

Preferred Skills

Experience with security awareness or phishing simulation platforms such as KnowBe4, Proofpoint, Cofense, Hoxhunt, or similar tools is highly desirable.

Additional experience with the following is a plus:

  • Security awareness metrics and dashboards
  • Cybersecurity training platforms
  • GRC tools
  • Security compliance frameworks
  • Risk assessments
  • Audit preparation
  • Regulatory reporting
  • Security communications and employee education

Benefits & conditions

$24 - $30 an hour - Full-time, Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Platform compliance and security certifications for sensitive data

Chad Carlson · World Congress 2021

1:58 min

Measuring productivity gains from agent-assisted code refactoring

Dr. Alexander Wachtel Dr. Alexander Wachtel +1 · World Congress 2025

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:32 min

The danger of unverified assumptions in critical systems

Luís Ventura Luís Ventura · World Congress 2024

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

Videos

See all

Related articles

See all