Lead Security Analyst

Jobtailor

Illinois

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a Security Analyst to own client security questionnaires, run vendor assessments, and manage SOC 2 operations. You will maintain risk registers, drive policy lifecycle, and support data privacy, while collaborating with contracts and AI governance teams.

The role emphasizes safeguarding data, translating complex requirements into actionable controls, and enabling safe AI adoption across the organization.

Qualifications

  • 2–5 years of experience in security analyst, GRC, IT audit, compliance, or similar role.
  • Two-year or four-year degree in information security, information technology, business, or related field; or 3+ years of equivalent experience.
  • Working knowledge of SOC 2, NIST CSF, or ISO 27001.

Responsibilities

  • Own client security questionnaires end to end; build and maintain a reusable answer library to make each response faster and more consistent
  • Conduct vendor security assessments for new vendors and renewals; maintain ongoing vendor risk tracking
  • Run SOC 2 compliance operations, including evidence collection, control monitoring, and audit support
  • Maintain the risk register: track remediation owners and progress, and prepare quarterly risk reviews
  • Drive the policy lifecycle: annual reviews, redline recommendations, and exception tracking
  • Support review of client contractual security obligations in partnership with our contracts administration team
  • Support data privacy compliance operations (CCPA, GDPR, etc.), including data inventory and mapping, subprocessor tracking, and data subject request support
  • Operate the AI tool and vendor intake process: triage requests, run security and risk reviews, and document decisions
  • Conduct AI risk assessments using our risk methodology — threat modeling, control analysis, and risk scenarios — and help mature it into a repeatable framework
  • Build and maintain our AI inventory of approved tools, agents, and connectors; monitor for unapproved AI use
  • Maintain AI usage policies and standards, and manage the exception process
  • Support access reviews for AI agents and connectors, including what data non-human identities can reach
  • Manage the security awareness training program, including content updates, completion tracking, and new-hire onboarding
  • Coordinate and execute periodic user access reviews and validate offboarding completion

Skills

SOC 2 Compliance
Vendor Security
AI governance
Security awareness
Written communication

Education

Related bachelor’s or associate degree

Tools

Contract Management Systems
Audit Tools
Evidence Collection
AI Tools

Job description

  • Own client security questionnaires end to end; build and maintain a reusable answer library to make each response faster and more consistent
  • Conduct vendor security assessments for new vendors and renewals; maintain ongoing vendor risk tracking
  • Run SOC 2 compliance operations, including evidence collection, control monitoring, and audit support
  • Maintain the risk register: track remediation owners and progress, and prepare quarterly risk reviews
  • Drive the policy lifecycle: annual reviews, redline recommendations, and exception tracking
  • Support review of client contractual security obligations in partnership with our contracts administration team
  • Support data privacy compliance operations (CCPA, GDPR, etc.), including data inventory and mapping, subprocessor tracking, and data subject request support
  • Operate the AI tool and vendor intake process: triage requests, run security and risk reviews, and document decisions
  • Conduct AI risk assessments using our risk methodology — threat modeling, control analysis, and risk scenarios — and help mature it into a repeatable framework
  • Build and maintain our AI inventory of approved tools, agents, and connectors; monitor for unapproved AI use
  • Maintain AI usage policies and standards, and manage the exception process
  • Support access reviews for AI agents and connectors, including what data non-human identities can reach
  • Manage the security awareness training program, including content updates, completion tracking, and new-hire onboarding
  • Coordinate and execute periodic user access reviews and validate offboarding completion
Requirements
  • 2–5 years of experience in a security analyst, GRC, IT audit, compliance, or similar role
  • Two-year or four-year degree in information security, information technology, business, or related field; or 3+ years of equivalent experience
  • Working knowledge of security and compliance frameworks such as SOC 2, NIST CSF, or ISO 27001
  • Experience responding to security questionnaires, conducting vendor assessments, or supporting audits
  • Familiarity with data privacy regulations (CCPA, GDPR, etc.)
  • Hands‑on experience using generative AI tools, and a strong interest in AI governance and safe adoption
  • Excellent written communication
  • Strong organization and attention to detail, with the ability to manage many parallel workstreams
  • Ability to work effectively with technical and non-technical stakeholders across the business
Core Competencies

Demonstrates expertise in security and compliance operations, including SOC 2, NIST CSF, and ISO 27001 frameworks, while effectively managing vendor assessments and data privacy regulations such as CCPA and GDPR. Proficient in utilizing generative AI tools for risk assessments and governance, with strong organizational skills to handle multiple workstreams.

Highest-signal resume keywords
  • SOC 2 Compliance Operations
  • Vendor Security Assessments
  • Data Privacy Regulations (CCPA, GDPR)
  • Generative AI Tools Experience
  • Security Awareness Training Management
ATS Optimization Keywords
Hard Skills
  • Security Analyst
  • GRC
  • IT Audit
  • Compliance Frameworks
  • Risk Assessment
  • Vendor Risk Tracking
  • Control Monitoring
  • Evidence Collection
  • Threat Modeling
  • Data Inventory and Mapping
Soft Skills
  • Excellent Written Communication
  • Strong Organization
  • Attention to Detail
  • Stakeholder Collaboration
  • Ability to Manage Parallel Workstreams
Industry Keywords
  • Security Questionnaires
  • Policy Lifecycle Management
  • Risk Register Maintenance
  • Data Subject Request Support
  • Subprocessor Tracking
Tools & Technologies
  • AI Tools
  • Security Awareness Training Programs
  • Risk Methodology Frameworks
  • Audit Support Tools
  • Contract Management Systems
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Information Security Officer – CISO
Chief Information Security Officer – CISO

Jobtailor • Salt Lake City (UT)

On-site
USD 180,000 - 240,000
Security GRC Specialist
Security GRC Specialist

Jobtailor • South San Francisco (CA)

On-site
USD 170,000 - 210,000
Senior IT Risk and Compliance Engineer
Senior IT Risk and Compliance Engineer

Jobtailor • Hartford (CT)

On-site
USD 120,000 - 180,000
Senior GRC Specialist
Senior GRC Specialist

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Senior AI Security Automation Engineer
Senior AI Security Automation Engineer

Jobtailor • Massachusetts

On-site
USD 180,000 - 260,000
Field Security Specialist – Cyber Security Solutions Engineer
Field Security Specialist – Cyber Security Solutions Engineer

Jobtailor • California (MO)

On-site
USD 120,000 - 170,000
Lead Security Analyst, Research Computing
Lead Security Analyst, Research Computing

Jobtailor • Knoxville (TN)

On-site
USD 110,000 - 160,000
Chief Information Security Officer
Chief Information Security Officer

Jobtailor • Kentucky

On-site
USD 180,000 - 240,000
Head of Information Security
Head of Information Security

Jobtailor • Seattle (WA)

On-site
USD 150,000 - 210,000
Data Security Administrator
Data Security Administrator

Jobtailor • City of Syracuse (NY)

Hybrid
USD 90,000 - 120,000