hirly

Communication Service for the Deaf, Inc

IT & Security Governance Analyst

Remote

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Communication Service for the Deaf, Inc first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included
Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Mid level
Work mode
Remote-friendly
First seen by hirly
7 Oct 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Description

The IT & Security Governance Analyst supports technology governance, security, and operational maturity initiatives across corporate IT, cloud and product environments, and operational systems. This role works across the organization to strengthen governance processes, maintain security controls and documentation, support data stewardship, and identify and track technology risks.

This position helps operationalize compliance frameworks as practical tools to improve efficiency, accountability, risk management, and resilience, rather than treating compliance as the sole objective.

IT Governance, Risk & Reporting

  • Support the development and maintenance of the organization's IT and security roadmap aligned with mission priorities and partner obligations.
  • Maintain the technology risk register, including security, data, vendor, and operational risks, and track remediation activities.
  • Assist with developing, documenting, and maintaining IT and security policies, standards, and procedures.
  • Maintain system ownership documentation, governance records, and technology inventories.
  • Prepare technology governance metrics, risk reports, and audit readiness documentation.

Data Governance & System Oversight

  • Support implementation and maintenance of data classification, access governance, and retention standards.
  • Document and maintain key data flows across internal systems, partner integrations, and cloud environments.
  • Review encryption, logging, and access controls for alignment with data sensitivity and contractual requirements.
  • Partner with Engineering and program teams to support secure and scalable system practices.
  • Maintain architecture documentation, data flow diagrams, and security control mappings.

Identity, Access & Organizational IT Foundations

  • Support identity and access management processes, including SSO, MFA, least privilege, access reviews, and joiner-mover-leaver workflows.
  • Coordinate endpoint and device management practices, including MDM, encryption, patching, configuration baselines, and endpoint protection.
  • Review SaaS governance practices and recommend improvements to reduce shadow IT risk.
  • Support validation of backup, recovery, and resilience capabilities for critical systems.
  • Provide guidance to departments on security and data handling best practices.

Cloud, Application & Vulnerability Management

  • Partner with Engineering to support Secure SDLC practices.
  • Coordinate vulnerability management activities, including scanning, triage, remediation tracking, and verification.
  • Support cloud security practices related to IAM, key management, logging, monitoring, and network security.
  • Participate in security and architecture reviews for new systems and major technology initiatives.

Incident Response, Vendor Risk & Partner Assurance

  • Maintain incident response documentation, runbooks, and severity classifications.
  • Support tabletop exercises and track remediation activities.
  • Assist with business continuity and disaster recovery testing.
  • Coordinate vendor and partner security assessments and remediation tracking.
  • Support audits, customer security questionnaires, and partner assurance initiatives.
  • Partner with Legal and business stakeholders to support implementation of data protection and security requirements.
  • Other duties as assigned.

Requirements

  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or a minimum of one (1) year of relevant experience in IT governance, cybersecurity, IT operations, or risk management.
  • Experience working across multiple IT or security domains.
  • Understanding of IAM principles, including SSO, MFA, least privilege, and access reviews.
  • Working knowledge of areas such as logging, endpoint security, encryption, backup management, vulnerability management, and network security.
  • Experience supporting IT, data, or security governance initiatives.
  • Ability to analyze technical risks and develop practical recommendations.
  • Ability to coordinate cross-functional initiatives and work effectively with technical and non-technical stakeholders.
  • Experience supporting audits or security frameworks such as PCI DSS, SOC 2, ISO 27001, NIST 800-53 Rev. 5, or HIPAA-adjacent controls preferred.
  • Experience with AWS, Azure, or GCP and CI/CD environments preferred.
  • Experience with MDM, EDR, SIEM, vulnerability scanners, or related tooling preferred.
  • Familiarity with secure software development practices and threat modeling preferred.
  • Relevant certifications such as Security+, SSCP, GSEC, or equivalent preferred.
  • Experience supporting grant-funded initiatives, multi-partner collaborations, or externally funded programs preferred.
  • Ability to communicate effectively in American Sign Language preferred.
Original posting on Communication Service for the Deaf, Inc's site ↗

Listed on hirly, a job board. hirly is not the employer: Communication Service for the Deaf, Inc is hiring for this role.

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job