Logo for National University

Cybersecurity Risk Analyst

Role overview

Qualifications

  • Bachelor´s degree in a related field preferred
  • Minimum of three (3) years of experience in governance, risk, and compliance and/or information security or audit required
  • Experience with third-party GRC and vendor management platforms preferred
  • Advanced knowledge and understanding of NIST Cybersecurity Framework and NIST SP 800-53 controls preferred

Responsibilities

  • Collaborates with university business and academic leaders to identify and enhance existing control processes
  • Evaluates the effectiveness of existing security controls and recommends enhancements to mitigate identified risks
  • Administers audit and security governance, risk, and compliance (GRC) tools
  • Supports the implementation and ongoing maintenance of controls aligned with CMMC and NIST SP 800-171 requirements

Key facts

Other skills

  • Communication
  • Teamwork
  • Critical Thinking
  • Customer Service

About the company

National University logo

National University

Higher Education

At National University, we believe it’s not just about the degrees our students earn, but the degree to which they use them. Since 1971, we have supported working professionals who want to be a powerful force for positive change. That’s why we make education accessible to adults who live and work in the real world. It’s why we were the first to develop a flexible, one-class-per-month format. It’s why we offer more than 120 graduate and undergraduate degree programs. And it’s why we will continue to innovate and leave a mark on people who will one day leave their mark on the world. We embrace diversity. Because it brings a new perspective to every industry. Our classes and faculty are made up of an eclectic mix of people who reflect our different communities and have the influence to shape where we’re headed. We do all this because we care. About our students. Our staff. Our supporters and our community. We are a private, nonprofit institution that does not answer to shareholders. We invest our money back into making improvements so that the people who come here can do the same. We know our legacy does not end when our students graduate. It begins.

Company details

Company typeLarge
IndustryHigher Education
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Compensation Range:

Annual Salary: $62,579.00 - $84,480.00

Position Summary

As a member of the Information Security team the Cyber Risk Analyst assists in enhancing our information security, information governance, privacy, compliance, and risk management procedures. This role will report to the Director, Information Security and closely collaborate with Technology Solutions, Product Management, Legal, and other colleagues to identify flaws and vulnerabilities in university and vendor systems to proactively develop solutions that mitigate risk. This role will support compliance efforts aligned with federal cybersecurity requirements, including NIST SP 800-171 and the Cybersecurity Maturity Model Certification (CMMC), where applicable.

Essential Functions:

  • Collaborates with university business and academic leaders to identify and enhance existing control processes.
  • Identifies and enhances existing control processes with university business and academic leaders.
  • Improves internal control.
  • Evaluates the effectiveness of existing security controls and recommends enhancements to mitigate identified risks.
  • Administers audit and security governance, risk, and compliance (GRC) tools, to document, maintain, and enhance controls.
  • Administers third party risk management tools.
  • Maintains knowledge of key NIST controls and enhances IT controls and policies accordingly.
  • Manages and maintains the controls of the IT audit program.
  • Prepares team members and necessary materials for audit meetings (e.g., control design walkthroughs), follow-up requests, and testing.
  • Builds testing and validation of IT General Control (ITGC) processes for internal audit.
  • Reviews auditor requests to ensure they are appropriately scoped and reasonable and reviews the completeness and accuracy of audit evidence and materials provided by internal team members prior to auditor submission.
  • Partners with senior leaders to ensure team member accountability for completing audit assignments on time with the appropriate level of priority, thoroughness, and accuracy, according to documented procedures.
  • Identifies and ranks the inventory of third parties that pose a risk to the university.
  • Supports the implementation and ongoing maintenance of controls aligned with CMMC and NIST SP 800-171 requirements.
  • Assists in preparing for and supporting CMMC readiness assessments and external audits, including documentation, evidence collection, and gap remediation tracking.
  • Collaborates with internal stakeholders and third-party vendors to ensure alignment with federal data protection requirements (e.g., Controlled Unclassified Information - CUI) where applicable.
  • Contributes to the development and operationalization of CMMC aligned policies, standards, and procedures within the university’s information security program.
  • Identifies and ranks the inventory of third parties that pose a risk to the university.
  • Collects the necessary security and auditing information from third parties, analyzes, and recommends its implementation as a control.
  • Manages the maturation of the third-party risk management program through the development of standard operating procedures.
  • Subject matter expert (SME) for security needs and ensures best practices are effectively communicated and implemented.
  • Provides an exceptional level of customer service and support to all business units and other internal and external contacts and responds in a timely manner to customer service feedback.
  • Stays updated on changes in cybersecurity regulations and adjusts risk management strategies accordingly.
  • Ensures compliance with relevant cybersecurity regulations, standards, and best practices.
  • Performs other duties as assigned.

Supervisory Responsibilities: N/A

Requirements:

Education & Experience:

  • Bachelor´s degree in a related field preferred.
  • Minimum of three (3) years of experience in governance, risk, and compliance and/or information security or audit required.
  • Experience with third-party GRC and vendor management platforms preferred.
  • Advanced knowledge and understanding of NIST Cybersecurity Framework and NIST SP 800-53 controls preferred.
  • Prior knowledge of NIST Special Publications 800-53 and 800-171 and familiarity with Cybersecurity Maturity Model Certification (CMMC) is preferred.
  • Experience supporting regulated environments or compliance frameworks (e.g., CMMC, federal contracts, or CUI handling requirements) is a plus
  • Experience in higher education preferred.
  • Experience working in a technology-driven enterprise preferred.

Competencies/Technical/Functional Skills:

  • Advanced knowledge and understanding of NIST Cybersecurity Framework and NIST SP 800-53 controls.
  • Expertise in complex business processes and technological risks.
  • Ability to apply critical thinking skills and a high attention to details to identify appropriate resolutions.
  • Self-starter that possesses a strong desire to seek optimal solutions and share discovery with colleagues.
  • Advanced written and verbal communication skills.
  • Ability to participate as an active team member of the Business Unit, Department, and University to work toward a common goal.
  • Deep understanding of security technologies including firewalls, proxies, SIEM, IDPs, and antivirus software.
  • Advanced understanding of third-party risk management.
  • Knowledge of penetration testing, network security, and common techniques to expose and correct security flaws.
  • Working knowledge of compliance frameworks and control mapping across NIST CSF, NIST SP 800-171, and CMMC domains.
  • Actively seeks opportunities to influence, build effective relationships and gain alignment with peers, functional partners and/or external partners to accomplish business objectives.
  • Accepts personal accountability, proactively seeks resolution for personal limitations head-on; and supports honesty and respect towards others, the company and oneself.
  • Develops new insights into situations; questions conventional approaches; encourages new ideas and innovations; designs and implements new or cutting-edge programs and processes.  Ability to generate and/or recognize imaginative or creative solutions that generate successful outcomes.
  • Strong interpersonal skills and the ability to effectively communicate with a wide range of individuals of constituencies in a diverse community. Ability to communicate well orally and in writing.  Ability to develop and use empathetic listening skills, communicate with clarity, and maintain an attitude that conveys respect, assistance, honesty, and resourcefulness.

Location: Remote, USA

Travel: No Travel Required

#LI-Remote

Candidate receiving offers will be offered a salary/pay rate commensurate with experience that vary based on a candidate’s qualifications, skills, and competencies.  Absent exceptional circumstances, candidates will be offered a salary within this range for this position. The minimum salary will be offered based on the minimum exemption threshold based on state of residency. Base pay is one component of National University’s total rewards package, as we are dedicated to supporting the needs of the “whole you” with our holistic approach to employee benefits by offering comprehensive well-being benefits for you and your family.  For full details about our benefit plan offerings, please visit benefits.nu.edu. For Part-time benefits, please click here.

National University is committed to maintaining a high-quality workforce representative of the populations we serve. National University employs more than 4,500 faculty and staff and serves over 45,000 students. We are united in our mission to meet the global education demands of the 21st Century and are dedicated to creating a supportive academic and work environment that allows students, faculty and staff to develop their interests and talents while experiencing a sense of community. With programs available both online and at our many campus locations, National University is a leader in creating innovative solutions to education and meeting the needs of our student population, including adult learners and working professionals.

National University (NU) is proud to be an equal opportunity employer and does not discriminate against any employee or applicant per applicable federal, state and local laws. At NU, a mix of highly talented, innovative and creative people come together to make the impact of a lifetime for each of our student learners. All qualified applicants will receive equal consideration for employment, education, and admission at National University.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Risk Management Specialist Related jobs

Other jobs at National University

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.