Cybersecurity Risk Analyst
Job Description
National University is seeking a Cyber Risk Analyst to join the Information Security team. The role emphasizes information security governance, privacy, compliance, and risk management with a focus on NIST SP 800-171 and CMMC compliance. The selected candidate will identify vulnerabilities and develop risk mitigation strategies to strengthen university controls. This is a remote position with a yearly compensation range of USD 62,579 to 84,480.
Responsibilities
- Collaborate with university business and academic leaders to identify and strengthen existing control processes
- Strengthen internal controls across the organization
- Evaluate the effectiveness of current security controls and propose enhancements to mitigate identified risks
- Administer audit and security governance, risk, and compliance tools to document, maintain, and improve controls
- Administer third party risk management tools
- Maintain knowledge of key NIST controls and update IT controls and policies accordingly
- Manage and maintain the IT audit program controls
- Prepare team members and materials for audit meetings, follow-up requests, and testing
- Develop testing and validation for IT General Controls (ITGC) processes used by internal audit
- Review auditor requests for appropriate scope and reasonableness and verify audit evidence and materials provided by internal team members
- Partner with senior leaders to ensure timely completion of audit assignments with appropriate priority, thoroughness, and accuracy
- Identify and rank third parties that pose a risk to the university
- Support the implementation and ongoing maintenance of controls aligned with CMMC and NIST SP 800-171 requirements
- Assist in preparing for and supporting CMMC readiness assessments and external audits, including documentation and gap remediation tracking
- Collaborate with internal stakeholders and third-party vendors to align with federal data protection requirements where applicable
- Contribute to the development and operationalization of CMMC aligned policies, standards, and procedures within the information security program
- Collect, analyze, and translate third-party security and auditing information into actionable controls
- Advance the maturation of the third-party risk management program through standard operating procedures
- Serve as a subject matter expert for security needs and promote best practices across teams
- Provide exceptional customer service and timely responses to inquiries from business units and other contacts
- Stay apprised of changes in cybersecurity regulations and adapt risk management strategies accordingly
- Ensure ongoing compliance with relevant cybersecurity regulations, standards, and best practices
- Perform other duties as assigned
Requirements
- Bachelor’s degree in a related field preferred
- Minimum of three years of experience in governance, risk and compliance and/or information security or audit
- Experience with third-party GRC and vendor management platforms preferred
- Advanced knowledge of the NIST Cybersecurity Framework and NIST SP 800-53 controls preferred
- Knowledge of NIST SP 800-53 and 800-171 and familiarity with Cybersecurity Maturity Model Certification (CMMC) preferred
- Experience supporting regulated environments or compliance frameworks (for example CMMC, federal contracts, or CUI handling) is a plus
- Experience in higher education preferred
- Experience working in a technology-driven enterprise preferred
Technologies
- NIST Cybersecurity Framework
- NIST SP 800-53
- NIST SP 800-171
- Cybersecurity Maturity Model Certification (CMMC)
- Firewalls
- Proxies
- SIEM
- IDPs
- Antivirus software
Compensation
Annual Salary: USD 62,579.00 – 84,480.00
Location
Remote, USA
Travel
No Travel Required