GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

JobsPennsylvaniaPennsylvaniaCyber Information Assurance Analyst

Cyber Information Assurance Analyst

Penn State University (ARL)
AI GovernanceSecretOn-siteFull-timePennsylvania

Penn State University (ARL) is hiring for the role of Cyber Information Assurance Analyst, Pennsylvania (On-site). This is an AI Governance role in the governance, risk, and compliance field. Review the full details below and apply directly with Penn State University (ARL).

Organization: Penn State University (ARL)Location: PennsylvaniaWorkplace: On-siteFocus: AI GovernancePosted: Aug 18, 2026
Penn State University (ARL) is hiring for this AI Governance role in Pennsylvania, one of the metros GRC Careers tracks for governance, risk, and compliance hiring. See other GRC roles in Pennsylvania →

APPLICATION INSTRUCTIONS: CURRENT PENN STATE EMPLOYEE (faculty, staff, technical service, or student), please login to Workday to complete the internal application process . Please do not apply here, apply internally through Workday. CURRENT PENN STATE STUDENT (not employed previously at the university) and seeking employment with Penn State, please login to Workday to complete the student application process. Please do not apply here, apply internally through Workday. If you are NOT a current employee or student, please click “Apply” and complete the application process for external applicants . Approval of remote and hybrid work is not guaranteed regardless of work location. For additional information on remote work at Penn State, see Notice to Out of State Applicants . ​ POSITION SPECIFICS ​ We are searching for a Cyber Information Assurance Analyst to join the Risk Management Department in the Applied Research Laboratory (ARL) at Penn State. The CIAA evaluates system and network environments to implement effective cybersecurity programs and determines security controls and policies based on best practices, regulations, and contractual requirements. This role includes managing compliance assessments, mitigating risks to information systems, and ensuring confidentiality, integrity, and availability. CMS Division leverages M&S expertise and other resources to deliver prototypes, demonstrations, and accelerated transitions of emerging research and technologies vital to national security needs, in addition to performing research, development, testing, and evaluations facilitating innovation in practice and development of critical, in-demand capabilities. ARL is an authorized DoD SkillBridge partner and welcomes all transitioning military members to apply You will: Conduct risk assessments and provide recommendations for system, network, and application design, implementation, and operation of departmental systems Conduct vulnerability assessments of departmental systems and networks to identify deviations from acceptable configurations or policies Meet with stakeholders regularly to assess needs and requirements at a departmental level Conduct vulnerability assessments of departmental systems and networks to identify deviations from acceptable configurations or policies Monitor the corrective actions of departmental system audits; draft documentation of Plan of Action and Milestones (POAM) for review Obtain certification and accreditation for departmental systems through the creation of process documentation support; may assist with unit or University wide process documentation Participate in the establishment of program control processes to ensure risk mitigation Perform periodic audits of departmental systems under general supervision Participate in the implementation of required policies, procedures, and configurations; make recommendations for improvements Participate in the preparation of requirements and procedures for forensic preservation Research and stay current on industry best practices Additional responsibilities for higher level position includes: Lead risk assessments and provide recommendations for system, network, and application design, implementation, and operation of unit-wide systems Lead vulnerability assessments of unit-wide systems and networks to identify deviations from acceptable configurations or policies; conduct assessments of non-standard systems Monitor the corrective actions of unit-wide system audits; develop and manage Plan of Action and Milestones (POAM) Meet with stakeholders regularly to assess needs and requirements at a unit-wide level Obtain certification and accreditation through the creation of process documentation; develop unit or University-wide process documentation Establish program control processes to ensure risk mitigation Perform periodic audits of systems Implement required policies, procedures, and configurations; make recommendations for improvements Develop requirements and procedures for forensic preservation Assist in the development of policy, process, and standards of Cyber Incident Response Team (CIRT) program and participate in CIRT activities as needed Assist in the development and delivery of information security training material May interface with external entities including law enforcement and intelligence/government agencies May provide guidance to lower level Analysts Required skills/knowledge areas include: Windows and Linux OS CI/CD pipeline Review of hardware and software vulnerabilities DoD Risk Management Framework (RMF) Understand and enforce policies and procedures within classified space Previous success with collaborations in a multi-disciplinary, team-oriented culture Assured Compliance Assessment Solution (ACAS) and Security Technical Implementation Guide (STIG) Ability to multitask multiple programs Security+, CAP, GSEC or equivalent Active security clearance, at the Top-Secret level and possession of or eligible for SCI level Preferred Skills/Knowledge Include: Development and maintenance of Security Assessment Plans, Risk Assessment Reports, and POAMs Containerized environments Gitlab and Ansible JIRA and Confluence Vulnerability scanning tools (ACAS, OpenSCAP, Trivy, Grype, etc.) Bachelors' degree in Information Technology, Cybersecurity or related field Your working location will be fully on-site located in State College, PA, but options exist for hybrid of on-site/work from home based on project-dependent ability. Questions related to flexible work should be directed to the hiring manager during the interview process. Travel is expected to be at 50% of the time to surrounding areas. MINIMUM EDUCATION, WORK EXPERIENCE & REQUIRED CERTIFICATIONS If filled as Cyber Security Information Analyst (ARL) - Intermediate Professional, this position requires:
Bachelor's Degree
1+ years of relevant experience; or an equivalent combination of education and experience accepted
Required Certifications:&#

Location and market context

This role is based in Pennsylvania on-site. Local candidates benefit from being close to Penn State University (ARL)'s teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About AI governance roles

AI governance sits at the intersection of policy, risk, and engineering. Teams are standing up model inventories, use-case intake and review, risk classification, and control monitoring as regulation and board scrutiny of AI intensify. Roles like this one are typically evaluated against frameworks such as NIST AI RMF, ISO/IEC 42001, the EU AI Act, and internal model-risk and privacy practices.

How to position yourself for this AI governance role

Strong candidates emphasize experience translating policy into operational controls, working across legal, compliance, security, product, and data teams, documenting AI system risks, and supporting governance processes. In your resume and outreach, tie your experience to how Penn State University (ARL) would apply NIST AI RMF, ISO/IEC 42001, the EU AI Act, and internal model-risk and privacy practices, and lead with concrete outcomes rather than duties.

Similar GRC roles

More GRC jobs in Pennsylvania

Want to be next in a role like this?

Roles like Cyber Information Assurance Analyst in Pennsylvania open regularly. Be first to know, privately. No current employer ever sees you looking.

New AI Governance roles, the moment they post. Tell us where to send them.

Unsubscribe anytime, one click.
Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.