Security Awareness Analyst Senior
Job in
Charlottesville, Albemarle County, Virginia, 22901, USA
Listed on 2026-07-14
Listing for:
State of Virginia
Full Time
position Listed on 2026-07-14
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
This position requires to be on site once or twice a month. Preferred market DMV (DC, Maryland, Virginia).
Key Responsibilities
Enterprise Security Awareness & Training Program Leadership
* With guidance from the GRC Director, lead the UVA Health cybersecurity awareness and training program, including annual planning, execution, and continuous improvement.
* Develop and deliver role‑appropriate training for workforce members, including onboarding, annual refresher training, and targeted campaigns based on risk trends.
* Design, run, and continuously refine phishing simulation campaigns; analyze results, identify systemic risk patterns, and recommend corrective actions.
* Maintain program metrics and dashboards to demonstrate effectiveness, maturity, and risk reduction over time.
* Ensure documentation and evidence of training completion and program effectiveness are maintained to support audits and regulatory reviews.
Phishing & Social Engineering Risk Management
* Monitor and assess emerging phishing and social engineering techniques affecting healthcare organizations.
* Develop awareness content addressing real‑world attack scenarios (e.g., phishing, spear‑phishing, business email compromise, vishing, smishing).
* Partner with IT Security Operations and Incident Response teams to incorporate lessons learned from security incidents into training and awareness activities.
Compliance Assessments & Governance Support
* Serve as a senior contributor to cybersecurity and regulatory compliance assessments by coordinating evidence collection, validating control effectiveness, and supporting remediation tracking.
* Participate in periodic security risk assessments and governance activities aligned with UVA Health's cybersecurity risk management practices.
* Collaborate with Internal Audit, Compliance, and Privacy stakeholders to support internal and external audits and readiness activities.
Policy Development & Lifecycle Management
* Lead or co‑lead development, review, maintenance, and communication of IT security policies, standards, and procedures.
* Ensure policies reflect UVA Health governance expectations and are aligned with healthcare regulatory requirements and recognized cybersecurity frameworks.
* Coordinate policy lifecycle activities, including scheduled reviews, updates, approvals, and workforce communication.
Data Governance & Privacy Controls
* Apply and support cybersecurity controls related to data governance, data classification, and privacy protection for sensitive health and business information.
* Work closely with Privacy and Compliance teams to support appropriate handling of PHI and other regulated data across systems and workflows.
* Assist in identifying risks related to data access, use, and disclosure, and support mitigation strategies consistent with UVA Health standards.
Leadership & Collaboration
* Act as a subject matter expert and trusted advisor for security awareness, human‑centric risk, and governance topics across the health system.
* Influence without authority by partnering with clinical, operational, academic, and administrative stakeholders.
* Mentor junior staff or contribute expert guidance within cross‑functional initiatives as assigned.
MINIMUM REQUIREMENTS
Education:
Bachelor's degree
Experience:
5-7 years relevant experience. Relevant experience may be considered in lieu of a degree.
Licensure: CISSP or HCISPP required or actively working on and can demonstrate a plan to achieve
Preferred Qualifications
* Experience leading healthcare cybersecurity programs or academic health systems.
* Experience with phishing simulation platforms and awareness maturity metrics.
* Familiarity with NIST CSF, HIPAA security principles, and healthcare compliance expectations.
* Certifications such as CISSP, HCISP, CISM, CISA, Security + is preferred.
PHYSICAL DEMANDS
This is primarily a sedentary job involving extensive use of desktop computers. The job does occasionally require traveling some distance to attend…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×