About the Role
Seeking an Information Security Analyst to support governance, risk, compliance, and privacy initiatives. This role will help develop policies, maintain security standards, and ensure projects and vendor engagements meet security requirements. First two weeks onsite for onboarding.
- Support information security and privacy efforts across systems, projects, and vendors.
- Maintain documentation within a GRC system.
- Develop/maintain System Security Plans (SSPs).
- Provide ISO representation on major projects.
- Draft policies, standards, and procedures.
- Review vendor/contract documents for security compliance.- 3+ years in information security (GRC focus).
- Knowledge of security frameworks (NIST, ISO 27001, COBIT, etc.).
- Strong organizational and communication skills.
- Experience drafting policies and creating diagrams/flowcharts.
- Bachelor’s in CS, IS, or related field.
- CISA, CISSP, or equivalent certification.
- Experience in financial services.
- Knowledge of cloud, application security, and regulatory/privacy compliance (GDPR, PCI, CCPA, VCDPA, etc.).
Work Location: Hybrid remote in Richmond, VA 23220