Lead Security Analysis

Ross Stores, Inc.

Dublin (CA)

Hybrid

USD 124,700 - 212,800

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ross Stores, Inc. is seeking a Lead, Security Analysis to join the Cybersecurity Risk Management group in Dublin, CA. You will lead IT security risk assessments, drive risk mitigation, and develop metrics and reporting across the enterprise.

You will oversee insider threat programs, policy updates, and security awareness initiatives for corporate and overseas offices, guiding projects and vendor risk processes.

Qualifications

  • Five years of experience within Information Technology with at least 3 in Security and/or Risk Management.
  • Bachelor's degree preferred or equivalent combination of education and relevant experience.
  • Strong understanding of security governance, compliance and risk management principles.
  • Proficient in Microsoft Word, Excel, PowerPoint.
  • Excellent analytical, organizational and communication skills.
  • Strong Project Management skills.

Responsibilities

  • Provides subject matter expertise in all aspects of risk management, including performing risk assessments to proactively identify current and future security issues/vulnerabilities and recommend remediation strategies.
  • Leads insider risk programs by identifying improvements and establishing supporting processes across the enterprise.
  • Identifies and implements improvements to enhance the Cybersecurity Risk Management program through optimization of processes, solutions, policies, procedures, KPIs, and other techniques.
  • Develops standards to support vendor selection and RFP process and participates in product and vendor selection process to provide subject matter expertise on Information security risk and compliance.
  • Maintains risk register and develops Cybersecurity Risk Management metrics and reports. Collaborates with Compliance Manager, Secure SDLC Manager, Information Security, and IT groups to gather and analyze metrics.
  • Leads information security awareness programs by regularly conducting exercises to educate employees of information security and best practices.
  • Monitors current and proposed laws, regulations, industry standards, and ethical requirements related to information security and privacy.
  • Lead and perform end‑to‑end risk assessments across business processes, applications, infrastructure, cloud environments, and third‑party/vendor ecosystems.

Skills

Security governance
Risk assessments
Project management
Communication

Education

Bachelor's degree or equivalent

Tools

CISSP
CRISC
UNIX
Windows
Oracle
MS SQL

Job description

Our Values Start With Our People

Bring your talents to Ross, our leading off‑price retail chain with over 2,200 stores, and a strong track record of success and growth. Our focus has always been bringing our customers a constant stream of high‑quality brands and on‑trend merchandise at extraordinary savings. All while providing a fun and exciting treasure hunt experience.

As Part of Our Team, You Will Experience
  • Success. Our winning team pursues excellence while learning and evolving
  • Career growth. We develop industry‑leading talent because Ross grows when our people grow
  • Teamwork. We work together to solve the hard problems and find the right solution
  • Our commitment to Diversity, Equality & Inclusion, and our community. We celebrate the backgrounds, identities, and ideas of those who work and shop with us because our differences make us stronger. We strive to be a positive force in our community.

Our Corporate headquarters are in Dublin, CA, we have 3 buying offices in key markets in New York City, Los Angeles, and Boston, and 8 distribution centers nationwide. With 2025 revenues of $22.8 billion, we are a Fortune 500 company who is committed to providing an inclusive work environment with continuous learning opportunities and development for our teams.

General Purpose

The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group responsible for leading and executing IT security risk management and governance processes within the organization. This includes performing risk assessments, tracking mitigation efforts and developing risk metrics and risk reports. This position is also responsible for leading security risk related projects and enhancing programs, such as business process risk assessments, insider threat management, updating security policies and standards, and executing security awareness programs for corporate as well as overseas offices.

The base salary range for this role is $124,700 - $212,800. The range is dependent on factors including, but not limited to, experience, skills, qualifications, relevant education, certifications, seniority, and location. The range listed is just one component of the total compensation package for employees. Other rewards vary by position and location.

Essential Functions
  • Provides subject matter expertise in all aspects of risk management, including performing risk assessments to proactively identify current and future security issues/vulnerabilities and recommend remediation strategies.
  • Leads insider risk programs by identifying improvements and establishing supporting processes across the enterprise.
  • Identifies and implements improvements to enhance the Cybersecurity Risk Management program through optimization of processes, solutions, policies, procedures, KPIs, and other techniques.
  • Develops standards to support vendor selection and RFP process and participates in product and vendor selection process to provide subject matter expertise on Information security risk and compliance.
  • Maintains risk register and develops Cybersecurity Risk Management metrics and reports. Collaborates with Compliance Manager, Secure SDLC Manager, Information Security, and IT groups to gather and analyze metrics.
  • Leads information security awareness programs by regularly conducting exercises to educate employees of information security and best practices.
  • Monitors current and proposed laws, regulations, industry standards, and ethical requirements related to information security and privacy.
  • Lead and perform end‑to‑end risk assessments across business processes, applications, infrastructure, cloud environments, and third‑party/vendor ecosystems.
Competencies

People: Building Effective Teams, Developing Talent, Collaboration

Self: Leading by Example, Communicates Effectively, Ensures Accountability and Execution, Manages Conflict

Business: Business Acumen, Plans, Aligns and Prioritizes, Organizational Agility

Position‑related Competencies: Technical Competence and Expertise, Analysis / Judgement, Communication, Customer Service

Qualifications And Special Skills Required
  • Five years of experience within Information Technology with at least 3 in Security and/or Risk Management.
  • Bachelor's degree preferred or equivalent combination of education and relevant experience.
  • Strong understanding of security governance, compliance and risk management principles.
  • Proficient in Microsoft Word, Excel, PowerPoint.
  • Excellent analytical, organizational and communication skills.
  • Strong Project Management skills.
Preferred Qualifications
  • CISSP (Certified Information Systems Security Professional)
  • CRISC (Certified in Risk and Information Systems Control)
  • Working knowledge of UNIX and Windows.
  • Firewalls, VPN, PKI, IPS.
  • Oracle, MS SQL.
  • Virtualization Security.
  • Software programming skills.
Physical Requirements / ADA

Job requires ability to work in an office environment, primarily on a computer. Requires sitting, standing, walking, hearing, talking on the telephone, attending in‑person meetings, typing, and working with paper/files. Consistent timeliness and regular attendance. Vision requirements: Ability to see information in print and/or electronically. This role requires regular in‑office presence, including to engage in in‑person team interaction, meetings and collaboration, client support, mentoring, coaching, and/or feedback. However, this role can perform duties effectively using a combination of in‑office and remote work.

Supervisory Responsibilities

N/A

Disclaimer

This job description is a summary of the primary duties and responsibilities of the job and position. It is not intended to be a comprehensive or all‑inclusive listing of duties and responsibilities. Contents are subject to change at management's discretion.

Ross is an equal employment opportunity employer. We consider individuals for employment or promotion according to their skills, abilities and experience. We believe that it is an essential part of the Company's overall commitment to attract, hire and develop a strong, talented and diverse workforce. Ross is committed to complying with all applicable laws prohibiting discrimination based on race, color, religious creed, age, national origin, ancestry, physical, mental or developmental disability, sex (which includes pregnancy, childbirth, breastfeeding and medical conditions related to pregnancy, childbirth or breastfeeding), veteran status, military status, marital or registered domestic partnership status, medical condition (including cancer or genetic characteristics), genetic information, gender, gender identity, gender expression, sexual orientation, as well as any other category protected by federal, state or local laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Analysis
Lead Security Analysis

Ross Stores • Dublin (CA)

Hybrid
USD 124,700 - 212,800
Security Engineer II (Threat Hunter)
Security Engineer II (Threat Hunter)

Ross Stores • Dublin (CA)

On-site
USD 108,000 - 205,000
Security Engineer II
Security Engineer II

Ross Stores, Inc. • Dublin (CA)

Hybrid
USD 124,000 - 213,000
Lead, Store Initiatives and Continuous Improvement
Lead, Store Initiatives and Continuous Improvement

Ross Stores, Inc. • Dublin (CA)

Hybrid
USD 97,000 - 146,000
Lead, Store Initiatives and Continuous Improvement
Lead, Store Initiatives and Continuous Improvement

Ross Stores • Dublin (CA)

Hybrid
USD 97,000 - 146,000
Lead, IT Applications
Lead, IT Applications

Ross Stores, Inc. • Fort Mill (SC)

On-site
USD 120,000 - 155,000
Senior Manager, Loss Prevention Outreach & Engagement
Senior Manager, Loss Prevention Outreach & Engagement

Ross Stores • Dublin (CA)

Hybrid
USD 113,200 - 172,600
Career growth opportunities
Diversity and Inclusion commitment
Tablets for employee engagement
Lead, IT Applications
Lead, IT Applications

Ross Stores • Dublin (CA)

Hybrid
USD 114,300 - 195,000
Senior Analyst, Store Finance
Senior Analyst, Store Finance

Ross Stores, Inc. • Dublin (CA)

Hybrid
USD 81,000 - 122,000
Senior Manager, Store Initiatives and Continuous Improvement (Self-Checkout)
Senior Manager, Store Initiatives and Continuous Improvement (Self-Checkout)

Ross Stores, Inc. • Dublin (CA)

Hybrid
USD 125,000 - 207,000