Compensation Range:
Position Summary
As a member of the Information Security team the Cyber Risk Analyst assists in enhancing our information security, information governance, privacy, compliance, and risk management procedures. This role will report to the Director, Information Security and closely collaborate with Technology Solutions, Product Management, Legal, and other colleagues to identify flaws and vulnerabilities in university and vendor systems to proactively develop solutions that mitigate risk. This role will support compliance efforts aligned with federal cybersecurity requirements, including NIST SP 800-171 and the Cybersecurity Maturity Model Certification (CMMC), where applicable.
Essential Functions:
- Collaborates with university business and academic leaders to identify and enhance existing control processes.
- Identifies and enhances existing control processes with university business and academic leaders.
- Improves internal control.
- Evaluates the effectiveness of existing security controls and recommends enhancements to mitigate identified risks.
- Administers audit and security governance, risk, and compliance (GRC) tools, to document, maintain, and enhance controls.
- Administers third party risk management tools.
- Maintains knowledge of key NIST controls and enhances IT controls and policies accordingly.
- Manages and maintains the controls of the IT audit program.
- Prepares team members and necessary materials for audit meetings (e.g., control design walkthroughs), follow-up requests, and testing.
- Builds testing and validation of IT General Control (ITGC) processes for internal audit.
- Reviews auditor requests to ensure they are appropriately scoped and reasonable and reviews the completeness and accuracy of audit evidence and materials provided by internal team members prior to auditor submission.
- Partners with senior leaders to ensure team member accountability for completing audit assignments on time with the appropriate level of priority, thoroughness, and accuracy, according to documented procedures.
- Identifies and ranks the inventory of third parties that pose a risk to the university.
- Supports the implementation and ongoing maintenance of controls aligned with CMMC and NIST SP 800-171 requirements.
- Assists in preparing for and supporting CMMC readiness assessments and external audits, including documentation, evidence collection, and gap remediation tracking.
- Collaborates with internal stakeholders and third-party vendors to ensure alignment with federal data protection requirements (e.g., Controlled Unclassified Information - CUI) where applicable.
- Contributes to the development and operationalization of CMMC aligned policies, standards, and procedures within the university’s information security program.