IT Security Governance Analyst

StratAcuity Staffing Partners Inc
  • Richmond, VA
  • $37–$47 Per Hour
3 days ago

Job Description

Job#: 3053764

Job Description:

Position Summary

Everforth is seeking an IT Security Governance Analyst to support an enterprise cybersecurity program by administering and improving governance, risk, compliance, privacy, and security assurance activities. The position works with system owners, data owners, project teams, vendors, operational IT teams, and partners to ensure organizational systems, data, services, and interconnections are assessed, documented, governed, and maintained in alignment with applicable requirements. This role protects sensitive offender, victim, employee, health, criminal justice, and organizational information while helping to make practical, risk-informed decisions.

Work includes new and existing systems, cloud and vendor services, integrations, agreements, emerging technologies, and enterprise security initiatives.

Essential Duties and Responsibilities

The statements below describe the principal duties of the position and are not intended to be all-inclusive.

  • Conduct and coordinate security risk assessments, Business Impact Analyses, data classifications, privacy reviews, control assessments, and security feasibility reviews for new and existing systems, applications, services, integrations, and technology initiatives.
  • Maintain risk registers, assessment records, corrective-action plans, exceptions, evidence repositories, and follow-up activities in Archer GRC and other approved tools. Track remediation commitments, due dates, residual risk, and required executive decisions.
  • Apply and interpret organizational and agency requirements, including VITA SEC530, NIST guidance, CIS Controls, DoD STIGs, CJIS and VCIN requirements, and applicable HIPAA, PCI, FERPA, FTI, privacy, and contractual obligations.
  • Partner with system owners and data owners to establish ownership, classify information, document security plans and controls, complete periodic reviews, and maintain evidence needed for authorization, audit, and ongoing compliance.
  • Review vendor and third-party security documentation, including SOC reports, security questionnaires, architecture and data-flow information, contracts, MOUs, MOAs, NDAs, and other interconnection documentation. Identify conditions, gaps, compensating controls, and escalation needs.
  • Support interconnection and data-sharing governance by reviewing MOUs and related agreements for security, privacy, least-privilege, data-handling, access-control, incident-notification, and annual-review requirements.
  • Coordinate audit, assessment, and oversight activities; collect and validate evidence; respond to inquiries; document findings; and manage corrective actions through closure with internal audit and other authorized reviewers.
  • Develop, maintain, and communicate security policies, standards, procedures, guidelines, templates, and governance processes. Recommend practical improvements that strengthen compliance and reduce risk.
  • Support the organizational security awareness and training program, including targeted compliance training, acknowledgements, tracking, reporting, and education for system owners, technical staff, and other stakeholders.
  • Perform governance reviews for emerging technology and artificial intelligence initiatives. Evaluate business purpose, data sensitivity, privacy, security, human oversight, vendor assurances, risks, and required approvals; document outcomes and handoffs.
  • Assist with security planning for continuity, incident response, disaster recovery, business continuity, audit logging, configuration and hardening, access reviews, vendor management, and other control areas.
  • Prepare accurate executive, management, and organizational reporting on governance workload, system inventory, risks, findings, remediation progress, compliance status, metrics, and program priorities.
  • Provide clear security guidance to project teams, operational IT, procurement, business units, and vendors. Facilitate meetings, communicate requirements professionally, and escalate unresolved risk or noncompliance through established channels.
  • Participate in incident and post-incident governance activities as assigned, including documentation review, control-gap identification, privacy or regulatory coordination, and corrective-action tracking.
  • Perform other related duties and special projects in support of the IT Security Governance program.

Knowledge, Skills, and Abilities

  • Knowledge of cybersecurity governance, risk management, compliance, privacy, third-party risk, and audit practices.
  • Knowledge of security frameworks and standards such as NIST 800-53, VITA SEC530, CIS Controls, CJIS and VCIN requirements, HIPAA, PCI, FERPA, FTI, and related requirements.
  • Ability to analyze technical and business information, identify risk, distinguish control gaps from acceptable residual risk, and recommend clear, defensible actions.
  • Ability to develop and maintain professional documentation, including assessment reports, risk registers, security plans, policies, procedures, executive briefings, and audit evidence.
  • Ability to manage multiple complex assignments, prioritize work under deadlines, and follow through on actions involving many stakeholders.
  • Ability to communicate effectively with executives, technical teams, vendors, auditors, and nontechnical business partners.
  • Ability to handle sensitive information with sound judgment, discretion, and a service-oriented approach.

Minimum Qualifications

  • Considerable experience in information security, cybersecurity governance, IT risk management, compliance, audit, privacy, or a closely related IT discipline.
  • Working knowledge of security assessment methodologies, control validation, risk documentation, and remediation tracking.
  • Experience interpreting and applying security policies, standards, and regulatory or contractual requirements.
  • Demonstrated ability to prepare clear written analyses, reports, and stakeholder communications.
  • An equivalent combination of education, training, and experience may be considered.

Preferred Qualifications

  • Experience in Virginia state government, corrections, criminal justice, public safety, healthcare, or another highly regulated environment.
  • Experience with Archer GRC or another governance, risk, and compliance platform.
  • Experience with VITA security governance processes, Commonwealth of Virginia requirements, or CJIS and VCIN compliance.
  • Relevant certifications such as Security Plus, CISM, CRISC, CISSP, CISA, HCISPP, or comparable credentials.
  • Experience with vendor risk management, AI governance, privacy impact reviews, or interconnection agreement reviews.

Working Conditions and Requirements

This position performs primarily professional office and computer-based work and may require participation in meetings, assessments, audits, training, and operational activities at organizational locations or with partners. The incumbent must be able to maintain confidentiality, meet required background and access standards, and comply with all applicable policies.

Performance Expectations

Success in this position is demonstrated through timely, high-quality governance reviews; complete and defensible documentation; consistent stakeholder coordination; effective tracking of risks and corrective actions; reliable audit readiness; and measurable improvement in the organizational security posture.

Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.

Everforth Apex uses a virtual recruiter as part of the application process. Click here for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at https://www.apexsystems.com/privacy-policy

Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.

Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.

If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at [email protected] or 804-523-8228. Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.

UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.

Employee Type:

Contract

Location:

Richmond, VA, US

Job Type:

Date Posted:

September 30, 2026

Pay Range:

$37 - $47 per hour

Similar Jobs

  • Data Governance Analyst
  • IT Governance Analyst
  • Data Governance Analyst
  • AI Governance Analyst
  • DMZ Governance Analyst

Numbers & Facts

LocationRichmond, VA
Salary$37–$47 Per Hour

Skills

  • Access Controlunmatched
  • Analysis Skillsunmatched
  • Artificial Intelligence (AI)unmatched
  • Auditingunmatched
  • Business Analysisunmatched
  • Business impact analysis (BIA)unmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Career Counselingunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • CompTIA Security+unmatched
  • Computer Securityunmatched
  • Corrective Actionunmatched
  • Criminal Justiceunmatched
  • Customer Support/Serviceunmatched
  • Data Analysisunmatched
  • Disaster Recoveryunmatched
  • Documentationunmatched
  • Documentation Reviewunmatched
  • Emerging Technologyunmatched
  • Enterprise Application Integration (EAI)unmatched
  • Enterprise Protectionunmatched
  • Establish Prioritiesunmatched
  • Family Educational Rights and Privacy Act (FERPA)unmatched
  • Feasibility Analysisunmatched
  • Follow Throughunmatched
  • Geneticsunmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • IT Governanceunmatched
  • IT Procurementunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internal Auditunmatched
  • Internet Securityunmatched
  • Legalunmatched
  • Maintain Complianceunmatched
  • Metricsunmatched
  • Organizational Development/Managementunmatched
  • PCIunmatched
  • Privacy Controlsunmatched
  • Privacy Regulationsunmatched
  • Public Healthunmatched
  • Public Safetyunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Securities and Exchange Commission (SEC)unmatched
  • Security Analysisunmatched
  • Security Complianceunmatched
  • Security Monitoringunmatched
  • State Governmentunmatched
  • Technical Analysisunmatched
  • Technical Supportunmatched
  • Time Managementunmatched
  • Training Programunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Validation Documentationunmatched
  • Vendor/Supplier Evaluationunmatched
  • Vendor/Supplier Managementunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder