Information Security Analyst

Rice Park Capital Managment LP

Minneapolis (MN)

Hybrid

USD 90,000 - 130,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical, Dental, Vision Insurance
PTO & Paid Holidays
Company Paid Life Insurance
Long-Term Disability
401(k) with employer match

Job summary

Rice Park Capital Managment LP is seeking an Information Security Analyst to own the GRC program, coordinating with an MSSP for ongoing security operations. You will drive policy governance, risk assessments, and regulatory compliance (SOC 2, GLBA) across the organization.

Responsibilities include managing the MSSP, performing internal risk assessments, and supporting due diligence with investors and lenders.

Qualifications

  • Bachelor’s degree in Information Technology, Risk Management, Business, Cybersecurity, or related field
  • 2+ years of information security governance, risk, or compliance (GRC) experience
  • Working knowledge of SOC 2, ISO 27001, NIST CSF, and GLBA
  • Experience with risk assessments, audits, access reviews, and vendor due diligence
  • Strong policy writing, documentation, and project management skills
  • Familiarity with SIEM outputs (MSSP handles operations)
  • Strong organizational and communication skills; vendor management
  • Nice-to-have: SQL/Python for reporting
  • Nice-to-have: CISA/CRISC or similar certification

Responsibilities

  • Own and mature the information security GRC program, including policy governance and risk assessments
  • Manage the MSSP relationship; ensure SLAs and coverage gaps are addressed
  • Lead SOC 2, GLBA compliance efforts; collect evidence and remediate gaps
  • Conduct internal/external risk assessments, audits, and maintain risk register
  • Develop and execute BIA, business continuity planning, and risk management activities
  • Manage investor/lender/security due diligence requests and questionnaires
  • Oversee user access reviews outside MSSP scope; design cadence and controls
  • Lead security awareness initiatives and vendor coordination

Skills

GRC experience
Vendor management
Policy writing
SOC 2 knowledge
Risk assessments
Communication
SQL/Python scripting
CISA/CRISC cert

Education

Bachelor’s degree in IT/Risk/Cybersecurity

Tools

SIEM

Job description

POSITION DESCRIPTION:

We are seeking a motivated, detail-oriented Information Security Analyst to own and mature Rice Park’s information security governance, risk, and compliance (“GRC”) program. This is a governance and risk management role, not a security operations role: Rice Park engages a third-party managed security services provider (“MSSP”) to handle day-to-day SIEM monitoring, alert triage, and SOC-level response.

This position is the internal owner of that vendor relationship and of Rice Park’s broader InfoSec program — ensuring the MSSP is delivering against its scope, identifying and closing the gaps the vendor does not cover (e.g., access reviews, policy governance, internal risk assessments), and driving Rice Park’s compliance posture across frameworks such as SOC 2 and GLBA, as well as investor and lender due diligence requirements.

The Information Security Analyst will work closely with the head of IT and coordinate across the organization to manage risk, maintain governance documentation, and ensure Rice Park meets its regulatory, contractual, and investor-facing security obligations.

DUTIES AND RESPONSIBILITIES:
Vendor & Security Program Management
  • Serve as the primary internal owner of the relationship with Rice Park’s managed security services provider (MSSP), ensuring SLAs are met and proactively identifying coverage gaps
  • Coordinate third-party penetration testing engagements, including scoping, scheduling, documentation, and remediation tracking
  • Track and drive remediation of findings from the MSSP, internal audits, and vulnerability scans
Governance, Risk & Compliance
  • Own and maintain the information security policy and procedure suite, including annual review and approval cycles
  • Lead SOC 2, GLBA, and related compliance efforts, including evidence collection, control testing, and remediation of gaps
  • Conduct internal and external risk assessments and audits, and maintain the enterprise risk register
  • Support the development and execution of Business Impact Analyses (BIA), business continuity planning, and related risk management activities
  • Manage investor, lender, and other counterparty information security due diligence requests and questionnaires, on both an ad hoc and annual basis
Access & Control Oversight
  • Own the user access review program across systems and applications — an area outside the MSSP’s scope — including designing the review cadence and ensuring appropriate controls are documented and enforced
  • Serve as the internal escalation point of contact for the MSSP during a security incident, coordinating internal response, documentation, and communication
Awareness & Continuous Improvement
  • Maintain and deliver Rice Park’s security awareness training and phishing simulation program
  • Collaborate with internal teams across the organization to promote security awareness and ensure adherence to security policies and protocols
  • Stay current on cybersecurity trends, regulatory developments, and industry best practices relevant to Rice Park’s risk profile
  • Undertake other related duties as assigned to support business operations and evolving organizational needs
QUALIFICATIONS:
  • Bachelor’s degree in Information Technology, Risk Management, Business, Cybersecurity, or a related field (or equivalent experience)
  • 2+ years of experience in information security governance, risk, or compliance (GRC); experience managing an MSSP or other outsourced security vendor relationship is a strong plus
  • Working knowledge of regulatory and compliance frameworks such as SOC 2, ISO 27001, NIST CSF, and GLBA
  • Experience conducting or supporting risk assessments, audits, access reviews, and third-party/vendor due diligence
  • Strong policy writing, documentation, and project management skills
  • Familiarity with SIEM and security tooling output sufficient to interpret and act on vendor reporting (hands‑on SIEM operation is not required — that is handled by our MSSP)
  • Strong organizational and communication skills; comfort managing vendors and driving cross‑functional accountability
  • Ability to handle sensitive information with discretion and professionalism
  • Nice to have: exposure to a scripting or programming language (e.g., SQL, Python) for reporting and data analysis
  • Nice to have: CISA, CRISC, or a similar governance-oriented certification
POSITION DETAILS:

This is a full-time position with competitive compensation (salary & bonus) and a comprehensive benefits package including:

  • Medical, Dental, Vision Insurance Options
  • Paid Time Off and Paid Holidays
  • Company Paid Life Insurance
  • Long-Term Disability
  • 401(k) with employer match

Work Location: Plymouth, MN or Charlotte, NC (hybrid)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

InfoSec GRC & Vendor Risk Analyst – Hybrid
InfoSec GRC & Vendor Risk Analyst – Hybrid

Rice Park Capital Managment LP • Minneapolis (MN)

Hybrid
USD 90,000 - 130,000
Medical, Dental, Vision Insurance
PTO & Paid Holidays
Company Paid Life Insurance
+2
Senior GRC Analyst
Senior GRC Analyst

Sky Mavis • Tulsa (OK)

On-site
USD 80,000 - 110,000
Discretionary annual bonus
Comprehensive benefits package
Flexible spending accounts
Senior GRC Analyst
Senior GRC Analyst

Sky Mavis • St. Louis (MO)

On-site
USD 85,000 - 110,000
Comprehensive benefits package
Discretionary annual bonus
Flexible spending accounts
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
Senior GRC Analyst
Senior GRC Analyst

Gilder Search Group • Atlanta (GA)

On-site
USD 90,000 - 120,000
Discretionary Annual Bonus
Comprehensive Benefits Package
401k and PTO
Senior GRC Analyst
Senior GRC Analyst

Gilder Search Group • St. Louis (MO)

On-site
USD 80,000 - 100,000
Discretionary Annual Bonus
Comprehensive Benefits Package
Generous PTO and paid company holidays
Senior GRC Analyst
Senior GRC Analyst

Gilder Search Group • Phoenix (AZ)

On-site
USD 80,000 - 120,000
Comprehensive Benefits Package
Discretionary Annual Bonus
Flexible Spending Accounts
Senior GRC Analyst
Senior GRC Analyst

Sky Mavis • Phoenix (AZ)

On-site
USD 90,000 - 130,000
Discretionary Annual Bonus
Comprehensive Benefits Package including Medical, Dental, and Vision
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 95,000 - 116,000
Hybrid work model
Relocation assistance
Certification sponsorship
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000