Information Assurance; IA Analyst
Listed on 2026-06-22
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, IT Business Analyst
Information Assurance (IA) Analyst
The Information Assurance (IA) Analyst will be responsible for assessing the risks associated with EAB technology applications and platforms and/or third‑party service providers that support those platforms. The IA Analyst will also support and contribute to business continuity management and planning activities, conduct information security audits, assess risks associated with third‑party service providers, develop and deliver security awareness training content, and participate in the measurement and reporting of key risk indicators and metrics across the organization.
This role is designed for an early‑career professional looking to build a foundation in cybersecurity governance, risk management, compliance, and information assurance.
This position is located in Washington, D.C. or Richmond, VA.
Primary Responsibilities- Participate in the day‑to‑day execution of Information Technology (IT) audit engagements, including supporting audit scoping activities and annual audit planning
- Perform IT risk assessments of internal initiatives and critical third‑party vendor relationships against criteria from information security frameworks and industry regulations, such as ISO/IEC 27001, NIST SP 800‑53, SSAE 18 SOC II Type I and Type II, DoD compliance frameworks (e.g., NIST 800‑171, CMMC, FedRAMP), NIST CSF, FERPA, and privacy regulations like GDPR and CCPA
- Review vendor security documentation, questionnaires, and attestations; assess risk impact and recommend risk treatment options
- Support RFPs/security questionnaires (HECVATs, CAIQ, custom questionnaires) from clients with clear SLAs and maintain upkeep of Security & Compliance Trust portals
- Evaluate the design and effectiveness of technology controls throughout the business cycle
- Support assessments of emerging technologies, including AI‑enabled systems, to identify security, privacy, and compliance risks
- Assist in the development and delivery of security awareness training content to new hires and existing employees including security newsletters, Lunch & Learns, online training modules, etc.
- Identify control gaps and risks, recommend mitigation strategies, and track remediation activities through closure
- Communicate IT audit findings and mitigation strategies to senior management, technology leaders, and the CISO
- Assist in the development of risk treatment plans to address areas of strategic and tactical IT and information risks in both business operations and technology paradigms
- Assist with the development and maintenance of information security policies and standards
- Participate in mentoring opportunities as the program scales and grows
- Stay informed on cybersecurity trends, threats, and emerging technologies
- Bachelor’s degree in computer science, information systems, information technology, or equivalent professional experience
- 0‑2+ years of experience in cybersecurity, IT audit, or related field
- Foundational knowledge of information security and IT risk management concepts and practices including frameworks and regulatory requirements
- Ability to work in a fast‑paced business environment with global, geographically distributed teams
- Basic understanding of cloud infrastructure and cloud‑based SaaS environments
- Exceptional interpersonal skills with ability to gain the confidence and respect of technology leaders and senior‑level executives
- Excellent organizational, time management, problem‑solving, prioritization, leadership, and interpersonal skills while proactively seeking input
- Strong verbal and written communication skills, technical knowledge, and the ability to write at a publication quality level to communicate findings and recommendations to EAB's senior management team
- Comfortable collaborating with IT, Product, Legal, and Commercial teams to support sales enablement opportunities
- Willingness to learn new skills, research new technologies, frameworks, and get better every day
- Professional experience in conducting IT or operational risk assessments or IT auditing through examination and analysis of internal controls and business risks
- Experience in supporting security compliance as…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).