×
Register Here to Apply for Jobs or Post Jobs. X

Security Awareness Analyst Senior

Job in Charlottesville, Albemarle County, Virginia, 22905, USA
Listing for: University of Virginia
Full Time position
Listed on 2026-07-05
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Assist Director Information Technology Security to implement information security plan and maintain application accesses for Information Systems supported by UVa Health System Computing Services.

** Key Responsibilities*
* ** Enterprise Security Awareness & Training Program Leadership*
* + With guidance from the GRC Director, lead the UVA Health cybersecurity awareness and training program, including annual planning, execution, and continuous improvement.

+ Develop and deliver role‑appropriate training for workforce members, including onboarding, annual refresher training, and targeted campaigns based on risk trends.

+ Design, run, and continuously refine phishing simulation campaigns; analyze results, identify systemic risk patterns, and recommend corrective actions.

+ Maintain program metrics and dashboards to demonstrate effectiveness, maturity, and risk reduction over time.

+ Ensure documentation and evidence of training completion and program effectiveness are maintained to support audits and regulatory reviews.

** Phishing & Social Engineering Risk Management*
* + Monitor and assess emerging phishing and social engineering techniques affecting healthcare organizations.

+ Develop awareness content addressing real‑world attack scenarios (e.g., phishing, spear‑phishing, business email compromise, vishing, smishing).

+ Partner with IT Security Operations and Incident Response teams to incorporate lessons learned from security incidents into training and awareness activities.

** Compliance Assessments & Governance Support*
* + Serve as a senior contributor to cybersecurity and regulatory compliance assessments by coordinating evidence collection, validating control effectiveness, and supporting remediation tracking.

+ Participate in periodic security risk assessments and governance activities aligned with UVA Health's cybersecurity risk management practices.

+ Collaborate with Internal Audit, Compliance, and Privacy stakeholders to support internal and external audits and readiness activities.

** Policy Development & Lifecycle Management*
* + Lead or co‑lead development, review, maintenance, and communication of IT security policies, standards, and procedures.

+ Ensure policies reflect UVA Health governance expectations and are aligned with healthcare regulatory requirements and recognized cybersecurity frameworks.

+ Coordinate policy lifecycle activities, including scheduled reviews, updates, approvals, and workforce communication.

** Data Governance & Privacy Controls*
* + Apply and support cybersecurity controls related to data governance, data classification, and privacy protection for sensitive health and business information.

+ Work closely with Privacy and Compliance teams to support appropriate handling of PHI and other regulated data across systems and workflows.

+ Assist in identifying risks related to data access, use, and disclosure, and support mitigation strategies consistent with UVA Health standards.

** Leadership & Collaboration*
* + Act as a subject matter expert and trusted advisor for security awareness, human‑centric risk, and governance topics across the health system.

+ Influence without authority by partnering with clinical, operational, academic, and administrative stakeholders.

+ Mentor junior staff or contribute expert guidance within cross‑functional initiatives as assigned.

MINIMUM REQUIREMENTS

*
* Education:

** Bachelor's degree

*
* Experience:

** 5-7 years relevant experience. Relevant experience may be considered in lieu of a degree.

** Licensure:
** CISSP or HCISPP required or actively working on and can demonstrate a plan to achieve

** Preferred Qualifications*
* + Experience leading healthcare cybersecurity programs or academic health systems.

+

Experience with phishing simulation platforms and awareness maturity metrics.

+ Familiarity with NIST CSF, HIPAA security principles, and healthcare compliance expectations.

+ Certifications such as CISSP, HCISP, CISM, CISA, Security + is preferred.

** PHYSICAL DEMANDS*
* This is primarily a sedentary job involving extensive use of desktop computers. The job does occasionally require traveling some distance to attend meetings, and programs.

The pay range…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary