Information Security Risk Analyst 2

University of Minnesota

Minneapolis (MN)

Hybrid

USD 85,000 - 95,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Retirement contribution
Vacation days
Tuition assistance
Health benefits
Wellness program
Disability insurance
Merit increase

Job summary

University of Minnesota's University Information Security is seeking an Information Security Risk Analyst to enhance the university's security posture through risk assessments, standards development, and exception management.

You will evaluate the information security posture of colleges and administrative units, analyze controls, and help shape a risk-based security program across the entire University system, collaborating with diverse stakeholders.

Qualifications

  • Bachelor's degree in a related field and 2 years of relevant work experience or a Master's degree.
  • 1 year experience in information security risk assessment, audit, quality assurance, or similar.
  • Excellent communication (oral, written, presentation), interpersonal and consultative skills.

Responsibilities

  • Conduct information security assessments utilizing ISO 27001 / 27002, NIST 800-171 or other appropriate information security control structures; develop risk remediation plans, and facilitate risk remediation efforts.
  • Facilitate the information security risk management program by identifying areas most in need of risk assessment, coordinating risk assessments with other information security risk analysts, and consulting with information security architects.
  • Monitor and advise on information security needs for systems and processes at the University of Minnesota to ensure the information security controls for the campuses are consistent and appropriate.
  • Consult with administrative and collegiate units to address policy and process‑related information security risks identified through the information security risk and exception management programs.
  • Collaborate with stakeholders by translating complex technical vulnerabilities and control deficiencies into clear, business‑risk language for non‑technical academic and administrative leaders.
  • Assist with development and maintenance of information security policies, standards, guidelines and procedures, based on industry best practices and compliance requirements.
  • Maintain a strong working knowledge of regulatory frameworks impacting higher education, including GLBA, PCI and FERPA while building knowledge of applicable security standards (SANS, OWASP, NIST).

Skills

Information security risk assessment
Communication skills
Consultative skills

Education

Bachelor's degree in a related field
Master's degree

Job description

About the Job

Position Type: Full‑time regular in Twin Cities.

Please note that this position is not eligible for H‑1B or Green Card sponsorship. This position does not offer a STEM OPT training program.

The University of Minnesota is committed to fostering local talent through employment opportunities. While this position utilizes a hybrid work modality, prospective applicants must be located either in the state of Minnesota or near the Wisconsin border or otherwise open to relocation.

Position Overview

The University of Minnesota's University Information Security seeks an Information Security Risk Analyst who will improve the information security of the University through information security risk assessments, security standards development, and exception management.

The Information Security Risk Analyst will assess the information security posture of collegiate and administrative units by conducting information security risk assessments, including analyzing security controls and processes, interviewing subject matter experts, and helping to shape a risk‑based approach to security across the entire University system.

Why Join Our Team?

As a Risk Analyst at the University of Minnesota, you won't just be checking boxes on a spreadsheet. You will act as a trusted consultant across a massive ecosystem – ranging from cutting‑edge research labs and medical clinics to athletics and student services. Your work directly protects the privacy of our 50,000+ students and safeguards groundbreaking academic research.

Job Responsibilities

Security Analysis – 80%

  • Conduct information security assessments utilizing ISO 27001 / 27002, NIST 800-171 or other appropriate information security control structures; develop risk remediation plans, and facilitate risk remediation efforts.
  • Facilitate the information security risk management program by identifying areas most in need of risk assessment, coordinating risk assessments with other information security risk analysts, and consulting with information security architects.
  • Monitor and advise on information security needs for systems and processes at the University of Minnesota to ensure the information security controls for the campuses are consistent and appropriate.
  • Consult with administrative and collegiate units to address policy and process‑related information security risks identified through the information security risk and exception management programs.
  • Collaborate with stakeholders by translating complex technical vulnerabilities and control deficiencies into clear, business‑risk language for non‑technical academic and administrative leaders.
  • Assist with development and maintenance of information security policies, standards, guidelines and procedures, based on industry best practices and compliance requirements.
  • Maintain a strong working knowledge of regulatory frameworks impacting higher education, including GLBA, PCI and FERPA while building knowledge of applicable security standards (SANS, OWASP, NIST).

Procedural Support – 20%

  • Facilitate the exception management process by tracking exceptions to information security policies and standards, evaluating associated risks by working with the other information security staff, and coordinating communication with the risk owner.
  • Assist with information security reviews of vendors and suppliers.
  • We Offer:
    • University paid contribution (10% of your salary) to your retirement account – vested immediately.
    • 22 paid vacation days per year, in addition to sick leave and 11 paid holidays.
    • Reduced tuition opportunities covering 75% – 100% of eligible tuition.
    • Excellent and affordable health care benefits.
    • Wellness program with opportunity to earn lower health care rates.
    • Free disability insurance.
    • Annual merit increase program.
Pay and Benefits

Pay Range: $85,000 – $95,000; depending on education/qualifications/experience

Time Appointment: 100% Appointment

Position Type: Faculty and P&A Staff

The University offers a comprehensive benefits package that includes:

  • Competitive wages, paid holidays, and generous time off
  • Continuous learning opportunities through professional training and degree‑seeking programs supported by the Regents Tuition Benefit Program
  • Low‑cost medical, dental, and pharmacy plans
  • Healthcare and dependent care flexible spending accounts
  • University HSA contributions
  • Disability and employer‑paid life insurance
  • Employee wellbeing program
  • Excellent retirement plans with employer contribution
  • Public Service Loan Forgiveness (PSLF) opportunity
  • Financial counseling services
  • Employee Assistance Program with eight sessions of counseling at no cost
  • Employee Transit Pass with free or reduced rates in the Twin Cities metro area
While our salary ranges provide a framework, it is important to note that most of the time, the initial pay may not reach the maximum of the range. This approach ensures that compensation reflects the value and unique contributions of each candidate while maintaining equity within our organization. As part of our commitment to fair and equitable compensation, please be aware that the salary offered to incoming candidates will be based on their individual credentials and experience.
Qualifications

Required Qualifications:

  • Bachelor's degree in a related field and 2 years of relevant work experience or a Master's degree.
  • 1 year experience in information security risk assessment, audit, quality assurance, or similar.
  • Excellent communication (oral, written, presentation), interpersonal and consultative skills.

Preferred Qualifications:

  • Relevant work experience in a technical role, such as enterprise system management, or working within an IT‑role in higher education
  • Knowledge of information security standards (e.g., ISO 27001/27002, NIST 800-171.), rules and regulations related to information security and data confidentiality (e.g., FERPA, GLBA, PCI DSS, HIPAA)
  • CISSP, CISA, or other security certifications are desirable.
  • Strong capability to analyze complex, ambiguous situations and synthesize conflicting information into clear, data‑driven risk recommendations.
  • Demonstrated ability to look beyond surface‑level technical symptoms to identify underlying root causes of systemic risk.
Employment Requirements

Any offer of employment is contingent upon the successful completion of a background check. Our presumption is that prospective employees are eligible to work here. Criminal convictions do not automatically disqualify finalists from employment.

EEO Statement

The University recognizes and values the importance of diversity and inclusion in enriching the employment experience of its employees and in supporting the academic mission. The University of Minnesota provides equal access to and opportunity in its programs, facilities, and employment without regard to race, color, creed, religion, national origin, gender, age, marital status, disability, public assistance status, veteran status, sexual orientation, gender identity, or gender expression. To learn more about diversity at the U: http://diversity.umn.edu

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Risk Analyst 2
Information Security Risk Analyst 2

University of Minnesota • Saint Paul (MN)

On-site
USD 85,000 - 95,000
Retirement contributions 10%
Vacation days
Reduced tuition
+4
InfoSec Risk Analyst II — Protect Campus Data & Privacy
InfoSec Risk Analyst II — Protect Campus Data & Privacy

University of Minnesota • Minneapolis (MN)

Hybrid
USD 85,000 - 95,000
Retirement contribution
Vacation days
Tuition assistance
+4
Information Security Risk Analyst II – Risk & Compliance
Information Security Risk Analyst II – Risk & Compliance

University of Minnesota • Saint Paul (MN)

Hybrid
USD 85,000 - 95,000
Retirement contributions 10%
Vacation days
Reduced tuition
+4
Information Security Analyst IV
Information Security Analyst IV

Utah • Salt Lake City (UT), Northern (KY)

Hybrid
USD 102,000 - 117,000
Payroll Accounting Business/Systems Analyst 2
Payroll Accounting Business/Systems Analyst 2

University of Minnesota • Minneapolis (MN)

On-site
USD 75,000 - 89,000
Hybrid work model
Competitive wages
Tuition benefits
+2
Reporting Accounting Business/Systems Analyst 2
Reporting Accounting Business/Systems Analyst 2

University of Minnesota • Minneapolis (MN)

On-site
USD 75,000 - 89,000
Competitive wages and holidays
Tuition benefits
Healthcare plans
+3
Procurement Business/Systems Analyst 2
Procurement Business/Systems Analyst 2

University of Minnesota • Saint Paul (MN)

On-site
USD 75,000 - 89,000
Continuous learning opportunities
Low-cost medical, dental, and pharmacy
HSA contributions
+2
IT Pro 2-BI & Data Analysis
IT Pro 2-BI & Data Analysis

University of Minnesota • Minneapolis (MN)

On-site
USD 69,000 - 80,000
PSLF opportunity
Tuition benefit program
Health & dental plans
+2
Security Supervisor
Security Supervisor

University of Minnesota • Minneapolis (MN)

On-site
USD 33,000 - 54,000
Competitive wages
Paid holidays
Generous time off
+12
IT Pro 2-BI & Data Analysis
IT Pro 2-BI & Data Analysis

University of Minnesota • Saint Paul (MN)

On-site
USD 69,000 - 80,000