Security Analyst (IT Risk)

Ross Stores

Dublin (CA)

Hybrid

USD 90,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Ross Stores is seeking a Security Risk Analyst to execute IT risk management processes, including risk assessments, mitigation tracking, and risk reporting. You will support security risk projects such as monitoring DLP events, third‑party risk assessments, and policy updates.

You will maintain risk metrics, collaborate with IT groups, and help drive security awareness programs while staying current with laws and standards in information security and privacy.

Qualifications

  • Minimum 3 years of Information Technology Security.
  • Strong understanding of security governance, compliance and risk management principles.
  • Working knowledge of UNIX and Windows.
  • Firewalls, VPN, PKI, IPS.
  • Oracle, MS SQL.
  • Virtualization Security.
  • Proficient in Microsoft Word, Excel, PowerPoint.
  • Excellent analytical, organizational and communication skills.
  • Strong Project Management skills.

Responsibilities

  • Performs risk assessments to identify current and future security vulnerabilities.
  • Performs third party risk assessment and related contracts to ensure security controls.
  • Provides support to IT during product and vendor selection and offers SME on information security risk and compliance.
  • Maintains IT Risk Management metrics and reporting across IT groups.
  • Maintains risk assessment tools to improve efficiency and governance.
  • Maintains information security policies, standards and procedures.
  • Maintains information security awareness programs and training.
  • Monitors laws, regulations, standards, and ethical requirements related to information security and privacy.

Skills

Information security
Risk management
Project management
Analytical thinking
Communication
Collaboration
Leadership
Business acumen

Education

Bachelor's degree or equivalent
CISSP certification
CRISC certification
CompTIA Security+

Tools

UNIX
Windows
Oracle
MS SQL
Firewalls
VPN
PKI
IPS
Virtualization
MS Office

Job description

GENERAL PURPOSE

The Security Risk Analyst is responsible for executing IT risk management processes within Ross. This includes performing risk assessments, tracking mitigation efforts and developing risk metrics and risk reports. This position is also responsible for executing security risk related projects and programs, such as monitoring DLP events, third-party risk assessments, updating security policies and procedures and executing security awareness programs.

ESSENTIAL FUNCTIONS
  • Performs risk assessments to identify current and future security vulnerabilities.
  • Performs Third Party risk assessment and related contracts agreements to ensure necessary security controls have been included as part of services and capabilities for the protection of organization assets
  • Provides support to IT during product and vendor selection process and provide subject matter expertise on Information security risk and compliance
  • Maintains related IT Risk Management metrics and reporting. Collaborates with IT Compliance Manager, Secure SDLC Manager, Information Security, and IT groups to gather and analyze metrics.
  • Maintains risk assessments related tools with the goal of improving efficiency, reducing costs, improving agility and optimizing information technology governance, risk, and controls management processes, while providing an overall view of the organization’s risk profile.
  • Maintains Information security policies, standards and procedures
  • Maintains information security awareness programs, regularly conducting exercise to educate employees of the information security and best practices.
  • Monitors current and proposed laws, regulations, industry standards, and ethical requirements related to information security and privacy.
COMPETENCIES
  • Building Effective Teams
  • Collaboration
  • Leading by Example
  • Communicates Effectively
  • Ensures Accountability & Execution
  • Manages Conflict
  • Business Acumen
  • Plans, Aligns & Prioritizes
  • Organizational Agility
QUALIFICATIONS & SPECIAL SKILLS REQUIRED
  • Minimum 3 years of Information Technology Security, at least 1 with large enterprise organizations
  • Strong understanding of security governance, compliance and risk management principles.
  • Working knowledge of UNIX and Windows
  • Firewalls, VPN, PKI, IPS
  • Oracle, MS SQL
  • Virtualization Security
  • Proficient in Microsoft Word, Excel, PowerPoint
  • Excellent analytical, organizational and communication skills
  • Strong Project Management skills
EDUCATION / CERTIFICATIONS

Required

  • Bachelor’s degree or equivalent combination of education and relevant experience

Preferred

  • CISSP (Certified Information Systems Security Professional) Preferred
  • CRISC (Certified in Risk and Information Systems Control (CRISC) Preferred
  • CompTIA Security + Preferred
PHYSICAL REQUIREMENTS
  • Consistent timeliness and regular attendance
  • However, this role can perform duties effectively using a combination of in-office and remote work
  • Job requires ability to work in an office environment, primarily on a computer
  • Requires sitting, standing, walking, hearing, talking on the telephone, attending in-person meetings, typing, and working with paper/files, etc
  • This role requires regular in-office presence, including to engage in in-person team interaction, meetings and collaboration, client support, mentoring, coaching, and/or feedback
  • Vision requirements: Ability to see information in print and/or electronically
SUPERVISORY RESPONSIBILITIES

N/A

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Security Analysis
Lead Security Analysis

Ross Stores, Inc. • Dublin (CA)

Hybrid
USD 125,000 - 213,000
Senior IT Security Analyst
Senior IT Security Analyst

Trident Care • United States

On-site
USD 120,000 - 150,000
Senior IT Security Analyst
Senior IT Security Analyst

TridentCare • United States

On-site
USD 110,000 - 150,000
Security Analyst
Security Analyst

Indigo Beam LLC • St. Louis (MO)

On-site
USD 75,000 - 100,000
IT Risk Services Analyst
IT Risk Services Analyst

Integrated Resources Inc. • Painted Post (NY)

On-site
USD 75,000 - 100,000
Information Security Risk Analyst
Information Security Risk Analyst

Compunnel, Inc. • San Francisco (CA)

On-site
USD 90,000 - 120,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Security Analyst
Security Analyst

Peyton Resource Group • Arlington (TX)

On-site
USD 70,000 - 90,000
Information Security Risk Analyst I
Information Security Risk Analyst I

Nationwide Children's Hospital • United States

On-site
USD 65,000 - 100,000
Health insurance
Retirement plan
Cyber Security Analyst
Cyber Security Analyst

Holland & Hart LLP • Denver (CO)

On-site
USD 90,000 - 120,000