> Markdown version of [/jobs/ext/3095586-it-compliance-analyst](https://www.wearedevelopers.com/jobs/ext/3095586-it-compliance-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Compliance Analyst - **Company:** Virginia Community Colleges - **Location:** Alexandria, VA, United States (Remote available) - **Experience:** Starter - **Salary:** $95,000.0 - $105,000.0 - **Contract:** Internship / Graduate position - **Skills:** CompTIA Security+, Cyber Security, Learning Management Systems, Digital Assets, IT Management, PCI Data Security Standards, Phishing, Comptia Project+, Information Technology, CIS Benchmarks, Software Version Control - **Published:** September 26, 2026 - **Apply:** https://www.careerjet.com/job/us1e0c0892fb876f1ce302fd022a947025/eaa ## About the Role * Knowledge, and a capability for clear, concise technical reporting and cross-functional collaboration. * Knowledge of IT cybersecurity and privacy principles, including the control requirements of FERPA, HIPAA, PCI DSS, GLBA, and CIS Controls. * Demonstrated analytical skills and attention to detail in reviewing cybersecurity policies, procedures, and standards; conducting maturity and risk assessments; and managing supporting compliance evidence. * Ability to collaborate with technical teams, vendors, and third-party providers to validate controls and collect compliance evidence (e.g., HECVAT questionnaires, SOC 2 / reports) in support of the Third-Party Risk Management program. * Ability to administer security awareness and compliance training programs, including phishing simulations and institution-wide campaigns, and to track completion across the organization. Minimum Work Experience: * Experience in cybersecurity operations, IT security analysis, risk management, or compliance enforcement. * Experience implementing and aligning controls with major security frameworks (e.g., NIST CSF, CIS Controls, PCI DSS, FERPA, HIPAA). * Hands-on experience using security, compliance, or administrative tools (e.g., KnowBe4, MS Attack Simulator, CIS CSAT, TeamDynamix), * Experience working within a higher education institution or public sector environment. * One or more professional certifications such as CompTIA Security+, CompTIA Project+ or ITIL 4 Foundation. * Familiarity with GRC (Governance, Risk, and Compliance) platforms or learning management systems (e.g., Canvas). Operation of a State Vehicle No, * * Do you have hands-on experience using security, compliance, or administrative tools (e.g., KnowBe4, MS Attack Simulator, CIS CSAT, TeamDynamix)? ## Description Does this position have telework options? -Telework options are subject to change based on business needs- No Does this position have a bilingual or multilingual skill requirement or preference? Work Schedule Monday thru Friday (Standard work week). 8 hours per day. Sensitive Position No, The IT Compliance Analyst is responsible for protecting the organization's digital assets by implementing, monitoring, and maintaining robust cybersecurity controls, systems, and compliance processes. This role ensures that the institution's information technology systems, processes, and data practices comply with applicable federal and state regulations, industry standards, and institutional policies., * Regulatory Compliance & Policy Management: Performs regular reviews, updates, and version control of cybersecurity policies, procedures, standards, guidelines, and supporting documentation. * Vendor & Third-Party Risk Management (TPRM): Review, update, and maintain Third-Party Risk Management (TPRM) policies and processes. * Cybersecurity Assessments & Internal Controls Preparedness: Track gaps in Internal Controls, ensuring timely follow-up by responsible parties, and prepare readiness reports for senior IT leadership. * Security Awareness & Compliance Training: Develop and deliver IT compliance and data privacy training programs (e.g., FERPA, cybersecurity awareness); and track completion rates institution wide. * Risk Management & Data Privacy: Conduct periodic IT risk assessments and Privacy Impact Assessments Special Assignments May be required to perform other duties as assigned. May be required to assist the agency or state government generally in the event of an emergency declaration by the Governor., Applicant Documents Required Documents * Resume Optional Documents * Cover Letter/Letter of Application * Other Document * Alternative Hiring Process Letter * SF-50 (Documentation of involuntary separation from Federal Agency), Overview: GovCIO is seeking a Junior Management Analyst to support mission-critical IT programs for the U.S. Coast Guard (USCG). This position will serve as a key operational res… + 3 days ago