About this role
Everforth is seeking an IT Security Governance Analyst to support an enterprise cybersecurity program by administering and improving governance, risk, compliance, privacy, and security assurance activities. The position works with system owners, data owners, project teams, vendors, operational IT teams, and partners to ensure organizational systems, data, services, and interconnections are assessed, documented, governed, and maintained in alignment with applicable requirements. This role protects sensitive offender, victim, employee, health, criminal justice, and organizational information while helping to make practical, risk-informed decisions.
Work includes new and existing systems, cloud and vendor services, integrations, agreements, emerging technologies, and enterprise security initiatives.
Essential Duties and Responsibilities
The statements below describe the principal duties of the position and are not intended to be all-inclusive.
- Conduct and coordinate security risk assessments, Business Impact Analyses, data classifications, privacy reviews, control assessments, and security feasibility reviews for new and existing systems, applications, services, integrations, and technology initiatives.
- Maintain risk registers, assessment records, corrective-action plans, exceptions, evidence repositories, and follow-up activities in Archer GRC and other approved tools. Track remediation commitments, due dates, residual risk, and required executive decisions.
- Apply and interpret organizational and agency requirements, including VITA SEC530, NIST guidance, CIS Controls, DoD STIGs, CJIS and VCIN requirements, and applicable HIPAA, PCI, FERPA, FTI, privacy, and contractual obligations.
- Partner with system owners and data owners to establish ownership, classify information, document security plans and controls, complete periodic reviews, and maintain evidence needed for authorization, audit, and ongoing compliance.
- Review vendor and third-party security documentation, including SOC reports, security questionnaires, architecture and data-flow information, contracts, MOUs, MOAs, NDAs, and other interconnection documentation. Identify conditions, gaps, compensating controls, and escalation needs.
- Support interconnection and data-sharing governance by reviewing MOUs and related agreements for security, privacy, least-privilege, data-handling, access-control, incident-notification, and annual-review requirements.
- Coordinate audit, assessment, and oversight activities; collect and validate evidence; respond to inquiries; document findings; and manage corrective actions through closure with internal audit and other authorized reviewers.
- Develop, maintain, and communicate security policies, standards, procedures, guidelines, templates, and governance processes. Recommend practical improvements that strengthen compliance and reduce risk.
- Support the organizational security awareness and training program, including targeted compliance training, acknowledgements, tracking, reporting, and education for system owners, technical staff, and other stakeholders.
- Perform governance reviews for emerging technology and artificial intelligence initiatives. Evaluate business purpose, data sensitivity, privacy, security, human oversight, vendor assurances, risks, and required approvals; document outcomes and handoffs.
- Assist with security planning for continuity, incident response, disaster recovery, business continuity, audit logging, configuration and hardening, access reviews, vendor management, and other control areas.
- Prepare accurate executive, management, and organizational reporting on governance workload, system inventory, risks, findings, remediation progress, compliance status, metrics, and program priorities.
- Provide clear security guidance to project teams, operational IT, procurement, business units, and vendors. Facilitate meetings, communicate requirements professionally, and escalate unresolved risk or noncompliance through established channels.
- Participate in incident and post-incident governance activities as assigned, including documentation review, control-gap identification, privacy or regulatory coordination, and corrective-action tracking.
- Perform other related duties and special projects in support of the IT Security Governance program.
Knowledge, Skills, and Abilities
- Knowledge of cybersecurity governance, risk management, compliance, privacy, third-party risk, and audit practices.
- Knowledge of security frameworks and standards such as NIST 800-53, VITA SEC530, CIS Controls, CJIS and VCIN requirements, HIPAA, PCI, FERPA, FTI, and related requirements.
- Ability to analyze technical and business information, identify risk, distinguish control gaps from acceptable residual risk, and recommend clear, defensible actions.
- Ability to develop and maintain professional documentation, including assessment reports, risk registers, security plans, policies, procedures, executive briefings, and audit evidence.
- Ability to manage multiple complex assignments, prioritize work under deadlines, and follow through on actions involving many stakeholders.
- Ability to communicate effectively with executives, technical teams, vendors, auditors, and nontechnical business partners.
- Ability to handle sensitive information with sound judgment, discretion, and a service-oriented approach.
Minimum Qualifications
- Considerable experience in information security, cybersecurity governance, IT risk management, compliance, audit, privacy, or a closely related IT discipline.
- Working knowledge of security assessment methodologies, control validation, risk documentation, and remediation tracking.
- Experience interpreting and applying security policies, standards, and regulatory or contractual requirements.
- Demonstrated ability to prepare clear written analyses, reports, and stakeholder communications.
- An equivalent combination of education, training, and experience may be considered.
Preferred Qualifications
- Experience in Virginia state government, corrections, criminal justice, public safety, healthcare, or another highly regulated environment.
- Experience with Archer GRC or another governance, risk, and compliance platform.
- Experience with VITA security governance processes, Commonwealth of Virginia requirements, or CJIS and VCIN compliance.
- Relevant certifications such as Security Plus, CISM, CRISC, CISSP, CISA, HCISPP, or comparable credentials.
- Experience with vendor risk management, AI governance, privacy impact reviews, or interconnection agreement reviews.
Working Conditions and Requirements
This position performs primarily professional office and computer-based work and may require participation in meetings, assessments, audits, training, and operational activities at organizational locations or with partners. The incumbent must be able to maintain confidentiality, meet required background and access standards, and comply with all applicable policies.
Performance Expectations
Success in this position is demonstrated through timely, high-quality governance reviews; complete and defensible documentation; consistent stakeholder coordination; effective tracking of risks and corrective actions; reliable audit readiness; and measurable improvement in the organizational security posture.
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click here for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at https://www.apexsystems.com/privacy-policy
Everforth Apex
Benefits
- Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDH)