Position Summary: Under the direction of the IT Compliance and Risk Manager, this position serves as a Security Awareness and Compliance Analyst within the Enterprise Information Security Office (EISO), supporting the Commonwealth's Governance, Risk, and Compliance (GRC) Department. The GRC function provides governance, risk evaluation, and compliance oversight to support informed decision-making and the responsible adoption of technology across the Commonwealth.
The Security Awareness and Compliance Analyst administers the organization's Security Awareness and Phishing Program and supports governance, risk, and compliance initiatives. The employee develops and coordinates security awareness activities, manages phishing simulation campaigns, analyzes program effectiveness, and supports regulatory reporting while contributing to the overall maturity of the GRC program.
Description of Major Duties:
Administers and maintains the enterprise Security Awareness Program.
Plans, coordinates, and executes phishing simulation campaigns.
Tracks, analyzes, and reports security awareness and phishing metrics using established reporting tools.
Develops and distributes security awareness communications and educational materials.
Coordinates required cybersecurity awareness training activities across the organization.
Maintains awareness program documentation and records to support compliance and audit requirements.
Assists with preparation of reports supporting regulatory requirements, audits, and management reviews.
Recommends improvements to awareness activities based on metrics, emerging threats, and industry best practices.
Assists with governance, risk, and compliance initiatives as assigned.
Participates in continuous improvement activities supporting the organization's cybersecurity program.
Performs related work as assigned.
Knowledge and Abilities
Knowledge of:
Information security awareness principles
Cybersecurity fundamentals
Security awareness and phishing simulation platforms
Reporting and data analysis techniques
Compliance and audit support activities
Ability to:
Coordinate multiple projects and training activities
Analyze program metrics and identify trends
Communicate effectively with diverse audiences
Develop user-friendly educational materials
Establish productive working relationships with agency staff
Required/Desired Skills:
Plans, coordinates, and executes phishing simulation campaigns.
Administers and maintains the enterprise Security Awareness Program.
Develops and distributes security awareness communications and educational materials.
Maintains awareness program documentation and records to support compliance and audit requirements.
Assists with preparation of reports supporting regulatory requirements, audits, and management reviews.
Recommends improvements to awareness activities based on metrics, emerging threats, and industry best practices.
Numbers & Facts
Location
Harrisburg, PA
Skills
Analysis Skillsunmatched
Auditingunmatched
Best Practicesunmatched
Campaignsunmatched
Communication Skillsunmatched
Communications Security (COMSEC)unmatched
Continuous Improvementunmatched
Data Analysisunmatched
Decision Supportunmatched
Documentationunmatched
Employee Relationsunmatched
Enterprise Protectionunmatched
Information/Data Security (InfoSec)unmatched
Internet Securityunmatched
Maintain Complianceunmatched
Metricsunmatched
Multitaskingunmatched
Phishingunmatched
Program Evaluationunmatched
Project/Program Coordinationunmatched
Regulatory Complianceunmatched
Regulatory Reportsunmatched
Regulatory Requirementsunmatched
Reporting Skillsunmatched
Riskunmatched
Risk Analysisunmatched
Risk Managementunmatched
Security Analysisunmatched
Simulationunmatched
Trend Analysisunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.