Information Security Risk and Compliance Analyst
Department of the Treasury · Richmond, VA · Virginia
- Role
- Software engineer
- First seen
- Sep 28, 2026
- Closes
- Oct 11, 2026
- Salary
- $85,000 - $110,000; Commensurate with experience
Apply on the Virginia portal
Applications go through the state’s official system — CivicWorks only tracks the posting.
Summary
The Information Security Risk and Compliance Analyst supports the Virginia Department of the Treasury's cybersecurity and risk management operations, protecting the Commonwealth's financial systems and technology infrastructure. This mid-level role involves application security, security awareness training, risk management, and compliance activities including System Security Plans, vulnerability assessments, and audit coordination. The position is located in Richmond, Virginia with up to two days per week of telework available.
Key qualifications
- Understanding of cybersecurity principles including network security, access control, malware/phishing threats, and incident response basics
- Knowledge of NIST security frameworks and compliance standards
- Experience developing System Security Plans in accordance with SEC 530 Standard or similar
- Excellent written communication skills and strong analytical and problem-solving abilities
- Experience with Role-Based Access Control (RBAC), Least Privilege Principles, and Segregation of Duties
- Familiarity with Multi-Factor Authentication (MFA) and governance/risk/compliance tools such as Archer
Summarized by CivicWorks from the state’s posting — check the official listing for full details.
Tracked by CivicWorks from Virginia’s public career portal. Posting data refreshes daily; this page disappears when the posting closes.