
Information Security Control Assurance Analyst
Southern New Hampshire UniversityRole Snapshot
The Information Security Control Assurance Analyst ensures Southern New Hampshire University's compliance with legal, regulatory, and contractual information security requirements by leading security assessments and managing remediation efforts across the institution.
Job Description
Southern New Hampshire University is a team of innovators. World changers. Individuals who believe in progress with purpose. Since 1932, our people-centered strategy has defined us — and helped us grow a team that now serves over 180,000 learners worldwide. Our mission to transform lives is made possible by talented people who bring diverse industry experience, backgrounds and skills to the university. And today, we're ready to expand our reach. All we need is you. Make an impact — from near or far At SNHU, you'll have the option to work remotely in the following states: Alabama, Arizona, Arkansas, Delaware, Florida, Georgia, Hawaii, Idaho, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Mississippi, Missouri, Nebraska, New Hampshire, New Mexico, North Carolina, North Dakota, Ohio, Oklahoma, South Carolina, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, West Virginia, Wisconsin and Wyoming. We ask that our remote employees have access to a reliable internet connection and a dedicated, properly equipped workspace that is free of distractions. Employees must reside in, and work from, one of the above approved states. The opportunity The Information Security Control Assurance Analyst plays a critical role in ensuring the University's adherence to legal, regulatory, and contractual information security and data protection requirements. This position leads and supports security assessment and authorization activities, including the development and maintenance of system security plans, evaluation of technical, administrative, and physical security controls, and management of remediation efforts through Plans of Action and Milestones (POA&Ms). The Analyst serves as a key contributor to institutional risk management by identifying compliance gaps, assessing risk associated with control deficiencies, and providing clear, actionable reporting to leadership. This role partners closely with IT, Legal, Privacy, and business stakeholders to coordinate internal and external audits, respond to regulatory changes, and translate complex security and compliance requirements into practical, well documented policies, standards, and procedures that support the University's mission and operational needs. You will work 100% remotely from any of our approved states. #LI-Remote What You'll Do: Lead and perform information security risk and compliance assessments to evaluate the effectiveness of technical, administrative, and physical security controls across University systems and services. Develop, maintain, and review System Security Plans (SSPs), risk assessments, and supporting documentation in alignment with applicable security frameworks and regulatory requirements. Identify control gaps and security deficiencies, assess associated risk, and document findings with clear, actionable recommendations. Manage and oversee Plans of Action and Milestones (POA&Ms), including tracking remediation activities, validating corrective actions, and reporting progress to stakeholders. Coordinate and support internal and external audits and assessments, including evidence collection, validation, and response management. Monitor and interpret changes in federal and state information security and data privacy laws, regulations, and contractual requirements, and assess organizational impact. Develop, update, and maintain information security policies, standards, procedures, and governance documentation to ensure ongoing compliance and operational effectiveness. Partner closely with ISMO, Privacy, Legal, and business stakeholders to translate regulatory and security requirements into practical, implementable controls and processes. Prepare and deliver compliance, risk, and audit reporting to management and leadership to support informed decision-making. Contribute to continuous improvement of the University's information security governance, risk management, and compliance programs. What We're
Looking For: 3 years of experience in a related field Completion of a Bachelor's Degree or working toward a degree in a related field Equivalent of experience in lieu of degree acceptable Demonstrated understanding of technical, administrative, and physical information security controls and how they are applied to manage risk across enterprise systems and services. Strong knowledge of information security governance, risk management, and compliance principles, including the ability to assess control effectiveness and identify compliance gaps. Working knowledge of NIST frameworks and standards (including NIST SP 800-53, 800-171, and the Risk Management Framework) and their application in assessment, authorization, and continuous monitoring activities. Familiarity with federal and state regulatory requirements and higher education compliance obligations related to information security and data protection (e.g., GLBA, FERPA, Simplified FAFSA Act). Advanced understanding of information security policies, standards, procedures, and governance documentation, including development, maintenance, and implementation. Experience supporting internal and external audits, including evidence collection, documentation review, and response coordination. Ability to translate complex regulatory and technical security requirements into practical, implementable controls and processes for technical and non-technical stakeholders. Working understanding of IT service management concepts and best practices (e.g., ITIL) as they relate to security operations, controls, and risk management. We believe real innovation comes from inclusion - where different experiences, perspectives and talents are celebrated. So if you're wondering whether SNHU is right for you, take the leap and apply. You might be just the person we're looking for. If you have a disability and require a reasonable accommodation to fully engage in any part of the application or hiring process, please complete the Accommodation Request form or contact us at 603-626-9447. A member from the Employee Accommodation Support Center will be in contact with you within two business days to discuss your request. Compensation The annual pay range for this position is $60,209.00 - $96,352.00. Actual offer will be based on skills, qualifications, experience and internal equity, in addition to relevant business considerations. We expect this position to be hired in the following target hiring range $66,531.00 - $90,013.00. Exceptional benefits (because you’re exceptional) You’re the whole package. Your benefits should be, too. As a full-time employee at SNHU, you’ll get: High-quality, low-deductible medical insurance Low to no-cost dental and vision plans 5 weeks of paid time off (plus almost a dozen paid holidays) Employer-funded retirement Free tuition program Parental leave Mental health and wellbeing resources
