The employee develops and coordinates security awareness activities, manages phishing simulation campaigns, analyzes program effectiveness, and supports regulatory reporting while contributing to the overall maturity of the GRC program. Job Description: Position Summary: Under the direction of the IT Complianceand Risk Manager, this position serves as a Security Awareness and Compliance Analyst within the Enterprise Information Security Office (EISO), supporting the Commonwealth's Governance, Risk, and Compliance (GRC) Department.