Jobs and Careers
ED
Security and Compliance Analyst
Education at WorkUnited Statesfull_timeVerifiedPosted 18 Feb 2025
About the role
Education At Work (E@W) enables students from traditionally underserved communities to secure a high-quality post-graduation job through evidence informed work-based learning programs. E@W aims to equip students with the high-value skills and experiences sought in the professional world by offering meaningful work opportunities.
If you love the pursuit of excellence and are inspired by empowering a student-centered culture to fulfill the E@W mission, we invite you to learn more. We offer unique opportunities to work on rewarding projects in an environment that appreciates diversity, focuses on talent development, and recognizes and rewards exceptional work.
Job SummaryEducation at Work is committed to providing a secure and compliant IT environment that enables student employees and staff to focus on their mission. We are seeking a Cybersecurity & Compliance Analyst to strengthen our security posture, drive compliance initiatives, and safeguard critical systems supporting our student workforce. This role is instrumental in ensuring E@W meets and exceeds regulatory compliance standards such as PCI-DSS, SOC 2, and HIPAA, while also implementing robust security measures to protect our IT infrastructure from evolving cyber threats. If you are passionate about security, compliance, and making a tangible impact on an organization that supports students, this is the role for you.
If you love the pursuit of excellence and are inspired by empowering a student-centered culture to fulfill the E@W mission, we invite you to learn more. We offer unique opportunities to work on rewarding projects in an environment that appreciates diversity, focuses on talent development, and recognizes and rewards exceptional work.
Job SummaryEducation at Work is committed to providing a secure and compliant IT environment that enables student employees and staff to focus on their mission. We are seeking a Cybersecurity & Compliance Analyst to strengthen our security posture, drive compliance initiatives, and safeguard critical systems supporting our student workforce. This role is instrumental in ensuring E@W meets and exceeds regulatory compliance standards such as PCI-DSS, SOC 2, and HIPAA, while also implementing robust security measures to protect our IT infrastructure from evolving cyber threats. If you are passionate about security, compliance, and making a tangible impact on an organization that supports students, this is the role for you.
Compliance & Risk Management
- Lead and manage PCI-DSS, SOC 2, and HIPAA compliance efforts across IT infrastructure and operations.
- Work closely with internal teams and auditors to complete security and compliance assessments.
- Maintain and update policies, standards, and controls aligned with NIST 800-53, CIS benchmarks, and other industry frameworks.
- Develop a continuous compliance monitoring strategy, ensuring that controls are regularly tested and enforced.
- Create and maintain a risk register, identifying, assessing, and mitigating IT security risks.
- Ensure incident response plans align with compliance requirements and legal obligations.
Security Monitoring & Incident Response
- Utilize Microsoft Sentinel, Defender for Endpoint, and other SIEM tools to monitor for security threats.
- Investigate potential security incidents, perform root cause analysis, and recommend remediation strategies.
- Establish log management and retention policies to align with compliance mandates.
- Develop security dashboards and automated reports to track key security and compliance metrics.
Identity & Access Management (IAM) & Data Protection
- Enforce role-based access control (RBAC) and least privilege policies across Azure AD, Okta, and M365.
- Implement and enforce Multi-Factor Authentication (MFA) and Conditional Access policies.
- Ensure data encryption standards (in transit & at rest) meet compliance regulations.
- Conduct regular access reviews and remediate any unauthorized access.
IT Audits & Governance
- Lead internal IT audits to validate compliance with SOC 2, PCI-DSS, and HIPAA requirements.
- Prepare and coordinate third-party compliance audits, working directly with auditors and regulatory bodies.
- Ensure all IT policies and procedures remain current and align with compliance and regulatory requirements.
Security Awareness & Training
- Develop and implement security awareness training for employees and student workers.
- Conduct simulated phishing exercises to improve user awareness of cyber threats.
- Provide guidance on handling sensitive data to maintain compliance with data privacy laws.
Required Skills & Qualifications
- Bachelor’s degree in Cybersecurity, Information Security, IT, or equivalent experience.
- 3+ years of experience in cybersecurity, IT compliance, or risk management.
- Strong understanding of PCI-DSS, ISO 27001 SOC 2, HIPAA, and other regulatory frameworks.
- Experience with Azure AD, Microsoft Defender, Sentinel, and compliance automation tools.
- Knowledge of firewalls, network segmentation (VLANs, NSGs), and Zero Trust security models.
- Hands-on experience with audits, risk assessments, and third-party security evaluations.
- Excellent problem-solving and communication skills, with the ability to explain complex compliance topics to non-technical teams.
Preferred Certifications
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CISA (Certified Information Systems Auditor)
- CompTIA Security+
- Microsoft SC-200 (Security Operations Analyst)
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s