IT Policy and Compliance Analyst
Listed on 2026-09-06
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Business Analyst
IT Policy and Compliance Analyst
Information Technology
IT Policy and Compliance Analyst
Location:
Harrisonburg, Virginia, United States
Position Type:
Full-Time (Salaried)
Employer:
James Madison University
Working Title:
IT Policy and Compliance Analyst
State Role
Title:
Information Technology Specialist II
Position Type:
Full-time Staff (Classified)
Position Status:
Full-Time
FLSA Status:
Exempt:
Not Eligible for Overtime
College/Division:
Information Technology
Department: 100784 – IT Policy and Compliance
Pay Band: 5
Pay Rate: $65,000 - $70,000
Is this a JMU only position? No
Is this a grant-funded position? No
Is this a Conflict of Interest designated position? No
Beginning Review Date: 9/17/2026
About JMU:
At James Madison University (JMU), we're more than just a publicly funded institution — we're a vibrant, welcoming community located on a stunning campus where innovation, collaboration, and personal growth thrive. Our mission is to prepare students for a bright future, and we believe that starts with supporting the people who make it all possible: our employees. Why Work at JMU?
We offer a comprehensive benefits package designed to support your professional journey and personal wellbeing:
- Generous Leave:
Enjoy paid vacation, sick leave, parental leave, community service leave, and 19 paid holidays annually. - Comprehensive Health Coverage:
Access high-quality health insurance options that fit your needs. - Retirement Options:
Plan for your future with retirement benefits through the Virginia Retirement System. - Employee Well-Being:
Our Balanced Dukes program promotes wellness and work-life integration through resources, events, and support. - Tuition Waiver Program:
Advance your education with our tuition waiver program for undergraduate and graduate courses taken at JMU.
At JMU, we believe in Being the Change — and that starts with creating an environment where you can grow, contribute meaningfully, and feel supported every step of the way. Discover what makes JMU a great place to work: bit.ly/JMUEmployment
General Information:
James Madison University is accepting applications for an Information Technology Policy and Compliance Analyst to provide support for Information Technology's Third-Party Vendor Management Program. The successful candidate will assist IT in ensuring compliance with applicable information technology regulations, policies, and standards. This position is eligible for a hybrid work schedule.
Duties and Responsibilities:
- Prepare information security operations reviews of on-premises and cloud-based IT systems and services to ensure alignment with university polices and compliance regulations.
- Perform annual reviews of existing systems to ensure continued information security compliance.
- Analyze SOC 2 or other independent security audit reports that attest to a vendor's security policies, procedures, and controls.
- Provide assistance with IT's Third-Party Vendor Management Program by serving as a member of the Technology Review Board.
- Educate and provide guidance to key partners related to JMU's information technology risk management requirements.
- Assist with the administration of IT's security awareness and compliance training program.
- Ensure information technology compliance records are organized and complete in accordance with applicable regulations, policies, standards, and best practices.
- Demonstrate honesty, integrity, and confidentiality in the handling of university and vendor data.
Qualifications:
- Required Qualifications:
- Demonstrated knowledge or experience in computer science, information technology, technical writing, business administration, or related field.
- Experience with information technology vendor risk assessment or vendor compliance.
- Strong security awareness and experience interpreting technical information, especially related to information technology best practices.
- Excellent writing skills, with the ability to create clear requirements, specifications, and documentation.
- Ability to effectively communicate, verbally and in writing, complex, technical information to both technical and non-technical audiences.
- Exceptional organization, time management, and prioritization skills.
- Ability to work independently with limited supervision as well as in teams.
- Detail-oriented and able to work with a high degree of accuracy.
- Proficient with Microsoft Excel, Word, SharePoint, and Teams.
- Additional Considerations:
- Familiarity with requirements related to information technology regulations and standards including GLBA, PCI, ISO 27001 and 27002, HIPAA, HITECH, GDPR, Title II, AI governance, etc.
- Experience analyzing SOC 2 or other independent security audit reports that attest to a vendor's security policies, procedures, and controls.
- Experience with information technology policies and procedures.
- Experience with language and terms used in contracts, licenses, and other legal documents related to information technology.
- Experience with supporting security awareness and other compliance training programs.
Additional Posting…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).