Senior Analyst, Information Assurance
Listed on 2026-01-25
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, IT Business Analyst
AtEAB , our mission is to make education smarter and our communities stronger. We work with more than 2,800 institutions to drive transformative change through data-driven insights and best-in-class capabilities. From kindergarten to college to career, EAB partners with leaders and practitioners to accelerate progress and drive results across enrollment, student success, institutional strategy, data analytics, and advancement. We work with each partner differently, tailoring our portfolio of research, technology, and marketing and enrollment solutions to meet the unique needs of every leadership team, as well as the students and employees they serve.
At EAB, we serve not only our partner institutions but each other—that's why we are always working to make sure our employees love their jobs and are invested in their communities. See how we've been recognized for this dedication to our employees by checking out our recent awards .
For more information, visit our careers page.
The Role in Brief Senior Analyst, Information AssuranceThe Senior Information Assurance Analyst will be responsible for assessing the risks associated with EAB technology applications and platforms and/or third-party service providers that support those platforms. The Senior Information Assurance Analyst will also support and contribute to business continuity management and planning activities, conduct and support information security audits, assess risks associated with third-party service providers, develop security awareness training content, and support the measuring and reporting of key risk indicators and metrics across the enterprise.
This individual will be a valued member of the EAB Information Security team. We work to keep our partners and EAB colleagues safe from cyber-attacks and prevent the theft of data and intellectual property. We think big and strategic but aren’t afraid to get into the weeds. Relationship building and stakeholder management across teams is integral to our continued success. We believe that diversity makes for better, more creative solutions to tough problems.
We’re easy to work with and eager to help. Most importantly, we work every day to contribute to the mission of making education smarter and our communities stronger. If this sounds like you, we’d love to talk to you.
This position is located in Washington, DC or Richmond, VA.
Primary Responsibilities:- Plan and execute the day-to-day activities of Information Technology (IT) audit engagements, including scope development and developing annual audit plans.
- Perform IT risk assessments and audits of internal initiatives and critical third party/vendor relationships against criteria descending from industry standard information security frameworks and industry regulations, such as ISO/IEC 27001, NIST SP 800-53, FAIR, SSAE 18 SOC II Type I and Type II, DoD compliance frameworks (e.g., NIST 800-171, CMMC, FedRAMP), NIST CSF, FERPA, and privacy regulations like GDPR and CCPA
- Review vendor security documentation, questionnaires, and attestations; assess risk impact and recommend risk treatment options.
- Support RFPs/security questionnaires (HECVATs, CAIQ, custom questionnaires) from clients with clear SLAs and maintain upkeep of Security & Compliance Trust portals.
- Support security assessments for DoD or federally funded service offerings, including understanding data classification and safeguarding requirements.
- Evaluate the design and effectiveness of technology controls throughout the business cycle
- Identify control gaps and risks, recommend mitigation strategies, and track remediation activities through closure.
- Communicate IT audit findings and mitigation strategies to senior management, technology leaders, and the CISO
- Help identify performance improvement opportunities across EAB business units
- Assist in the development of risk treatment plans to address areas of strategic and tactical IT and information risks in both business operations and technology paradigms
- Assist with the development and maintenance of information security policies and standards
- Support development and maintenance of an information security compliance and metrics program for…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).