×
Register Here to Apply for Jobs or Post Jobs. X

Security Analyst - Risk Management Program

Job in Midlothian, Chesterfield County, Virginia, 23112, USA
Listing for: Networking Technologies + Support
Full Time position
Listed on 2026-06-26
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 85000 - 100000 USD Yearly USD 85000.00 100000.00 YEAR
Job Description & How to Apply Below

NTS is seeking an experienced Security Analyst to support the Risk Management Program for a leading academic healthcare and research environment in Charlottesville, Virginia. This position will play a critical role in protecting clinical, research, and business information assets by conducting security risk assessments, evaluating security controls, supporting regulatory compliance initiatives, and partnering with stakeholders across healthcare, research, and technology teams.

The ideal candidate possesses a strong cybersecurity background combined with experience in risk management, governance, compliance, and project coordination within a healthcare, higher education, or regulated environment.

Risk Management & Security Assessments
  • Conduct security risk assessments for healthcare, research, and enterprise technology initiatives.
  • Evaluate risks related to confidentiality, integrity, and availability of protected health information (PHI), research data, and critical business systems.
  • Identify security gaps and develop risk-based recommendations for remediation.
  • Maintain risk registers, track mitigation activities, and support ongoing risk reporting.
  • Perform vendor and third‑party security reviews to assess organizational risk exposure.
Security Control Reviews
  • Review and validate technical, administrative, and physical security controls.
  • Assess compliance with organizational policies and regulatory requirements.
  • Evaluate security controls supporting research projects, clinical systems, cloud environments, and enterprise applications.
  • Collaborate with IT and security teams to ensure required controls are implemented and operating effectively.
  • Document findings, recommendations, and corrective action plans.
Governance, Risk & Compliance (GRC)
  • Support cybersecurity governance and risk management programs.
  • Assist with security audits, compliance reviews, and evidence collection activities.
  • Contribute to the development and maintenance of security standards, policies, and procedures.
  • Support compliance efforts related to HIPAA, NIST Cybersecurity Framework, NIST 800‑53, SOC 2, ISO 27001, and other applicable regulations and frameworks.
  • Participate in internal and external audit activities.
Project Management & Stakeholder Engagement
  • Serve as the cybersecurity representative on healthcare, research, and enterprise technology projects.
  • Coordinate security reviews throughout project life cycles, from planning through implementation.
  • Track security deliverables, timelines, risks, and dependencies.
  • Communicate security requirements and recommendations to technical and non‑technical stakeholders.
  • Facilitate cross‑functional collaboration to balance security requirements with operational and research objectives.
Research Security & Data Protection
  • Support data security reviews for research initiatives involving regulated, restricted, or sensitive information.
  • Assist with Data Security Plan reviews and risk evaluations for research projects.
  • Evaluate data protection controls supporting research environments and clinical studies.
  • Partner with investigators, compliance teams, and technology stakeholders to ensure secure handling of research data.
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Information Security, Computer Science, or a related field; equivalent experience may be considered.
  • 3+ years of cybersecurity, risk management, governance, compliance, or security operations experience.
  • Experience conducting security risk assessments and control reviews.
  • Strong understanding of healthcare security requirements and regulatory frameworks.
  • Knowledge of security technologies, risk management methodologies, and cybersecurity best practices.
  • Excellent written communication, documentation, and stakeholder engagement skills.
Preferred Qualifications
  • Experience supporting healthcare, academic medical centers, research institutions, or higher education environments.
  • Familiarity with IRB‑reviewed research, research security programs, and regulated research data.
  • Experience with security frameworks including NIST CSF, NIST 800‑53, CIS Controls, HIPAA, ISO 27001, and SOC 2.
  • Professional certifications such as…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary