Senior Analyst, Information Assurance
Listed on 2026-02-12
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, IT Business Analyst
The Role in Brief
Senior Analyst, Information Assurance
The Senior Information Assurance Analyst will be responsible for assessing the risks associated with EAB technology applications and platforms and/or third-party service providers that support those platforms. The Senior Information Assurance Analyst will also support and contribute to business continuity management and planning activities, conduct and support information security audits, assess risks associated with third-party service providers, develop security awareness training content, and support the measuring and reporting of key risk indicators and metrics across the enterprise.
This individual will be a valued member of the EAB Information Security team. We work to keep our partners and EAB colleagues safe from cyber-attacks and prevent the theft of data and intellectual property. We think big and strategic but aren't afraid to get into the weeds. Relationship building and stakeholder management across teams is integral to our continued success. We believe that diversity makes for better, more creative solutions to tough problems.
We're easy to work with and eager to help. Most importantly, we work every day to contribute to the mission of making education smarter and our communities stronger. If this sounds like you, we'd love to talk to you.
This position is located in Washington, DC or Richmond, VA.
Primary Responsibilities- Plan and execute the day-to-day activities of Information Technology (IT) audit engagements, including scope development and developing annual audit plans.
- Perform IT risk assessments and audits of internal initiatives and critical third party/vendor relationships against criteria descending from industry standard information security frameworks and industry regulations, such as ISO/IEC 27001, NIST SP 800-53, FAIR, SSAE 18 SOC II Type I and Type II, DoD compliance frameworks (e.g., NIST 800-171, CMMC, FedRAMP), NIST CSF, FERPA, and privacy regulations like GDPR and CCPA
- Review vendor security documentation, questionnaires, and attestations; assess risk impact and recommend risk treatment options.
- Support RFPs/security questionnaires (HECVATs, CAIQ, custom questionnaires) from clients with clear SLAs and maintain upkeep of Security & Compliance Trust portals.
- Support security assessments for DoD or federally funded service offerings, including understanding data classification and safeguarding requirements.
- Evaluate the design and effectiveness of technology controls throughout the business cycle
- Identify control gaps and risks, recommend mitigation strategies, and track remediation activities through closure.
- Communicate IT audit findings and mitigation strategies to senior management, technology leaders, and the CISO
- Help identify performance improvement opportunities across EAB business units
- Assist in the development of risk treatment plans to address areas of strategic and tactical IT and information risks in both business operations and technology paradigms
- Assist with the development and maintenance of information security policies and standards
- Support development and maintenance of an information security compliance and metrics program for consistent management reporting of risks to sensitive information and technology resources across the enterprise
- Help with prospective hiring and mentoring opportunities as the program scales and grows
- Bachelor's degree in Computer Science, Information Systems, or equivalent professional experience
- Minimum of 3+ years of experience as an IT auditor, security analyst, or related field
- Knowledge of information security and IT risk management concepts and practices including frameworks and regulatory regimes
- Ability to work in a fast-paced business environment with global, geographically distributed teams
- Strong understanding of cloud infrastructure and cloud-based SaaS environments
- Exceptional interpersonal skills with ability to gain the confidence and respect of technology leaders and senior level executives
- Excellent organizational direction, time management, problem-solving, prioritization, leadership, and interpersonal skills while proactively seeking input
- Stro…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).