Senior Security Analyst

Ohio State University

Columbus (OH)

On-site

USD 103,000 - 135,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

The Ohio State University’s Office of Technology and Digital Innovation is seeking a Senior Security Analyst to design, manage, and evolve the information security and privacy framework across the university and medical center.

This role requires strong governance, risk management and compliance expertise, with leadership of Tier 1–3 assessments and cross-team collaboration. A bachelor’s degree and 6+ years in GRC are required.

Qualifications

  • Bachelor’s degree in information technology, cyber security, computer science or related field.
  • Minimum of 6 years of direct experience in information security governance, risk, and compliance.
  • Full technology stack knowledge: IAM, servers, networking, application development, databases.

Responsibilities

  • Own and operate IS/privacy control requirements (ISPCR) ensuring alignment with institutional goals.
  • Map policies and controls to standards like NIST SP 800-53, HIPAA, FERPA, ISO 27001, SOC 2.
  • Lead risk assessments (Tier 1-3) across campus infrastructure, cloud, and third-party vendors.
  • Provide actionable mitigation strategies to system owners and technical teams.
  • Mentor and guide less experienced colleagues across IT and security groups.
  • Communicate complex risk information to diverse stakeholders and leadership.

Skills

Information security governance
Risk assessment
Compliance management
Communication to stakeholders

Education

Bachelor’s degree in IT/Cyber security

Tools

GRC tools

Job description

Screen reader users may encounter difficulty with this site. For assistance with applying, please contact hr-accessibleapplication@osu.edu . If you have questions while submitting an application, please review these frequently asked questions .Current Employees and Students:If you are currently employed or enrolled as a student at The Ohio State University, please l og in to Workday to use the internal application process.Welcome to The Ohio State University's career site. We invite you to apply to positions of interest. In order to ensure your application is complete, you must complete the following:Ensure you have all necessary documents available when starting the application process. You can review the additional job description section on postings for documents that may be required.Prior to submitting your application, please review and update (if necessary) the information in your candidate profile as it will transfer to your application.Job Title:Senior Security AnalystDepartment:OTDI | Governance and Risk ManagementSenior Security Analyst Position SummaryThe Senior Security Analyst is a high-impact, specialized position within The Ohio State University’s Office of Technology and Digital Innovation. This role is responsible for designing, managing, and evolving the comprehensive information security and privacy framework across the university and medical center. Operating with a high degree of autonomy, the Senior Security Analyst will apply advanced industry knowledge to solve highly complex problems, develop new risk models, establish precedents that safeguard the university's academic, research, and administrative environments, and lead technical focus groups to determine the applicability of industry standards to university business.Key Responsibilities• Own and operate the university’s Information Security and Privacy Control Requirements(ISPCR), ensuring alignment with institutional goals.• Map institutional policies and controls to industry standards and regulatory requirements,such as NIST SP 800-53, NIST SP 800-171, CIS Benchmarks, HIPAA, FERPA, GLBA,and PCI-DSS.CIS Controls, ISO/IEC 27001, SOC 2, HIPAA, FERPA, GLBA, PCI DSS,or similar.• Develop, refine, and implement new compliance practices, processes, maturity models,and key performance metrics to measure framework effectiveness over time.• Lead highly complex, large-scope risk assessment initiatives that have a significant andlong-term impact on the university’s risk posture.• Scope, execute, and oversee Tier 1, Tier 2, and Tier 3 risk assessments, evaluating criticalcampus infrastructure, cloud environments, third-party vendors, and research dataenvironments.• Provide actionable, technically sound mitigation strategies to system owners, researchers,and technical teams to remediate identified gaps.• Provide guidance, mentorship, and technical oversight to less experienced colleaguesacross the distributed university IT and security organizations.• Convey difficult, highly complex, or sensitive risk information to diverse campusstakeholders and leadership, from technical system administrators to non-technicalacademic leadership.• Facilitate productive dialogue and use advanced communication skills to persuadeothers to adopt secure practices and consider alternative risk-treatment options.Required Education & Experience• Bachelor’s degree in information technology, cyber security, computer science, or arelated field (or equivalent professional experience).• Minimum of 6 years of direct experience in information security governance, risk, andcompliance. • Full technology stack knowledge – broad understanding and ability to explain identityand access management (IAM), server, networking, application development anddatabase concepts.Preferred Education & Experience• 8 to 12 years of relevant governance, risk, and compliance (GRC) experience, ideallywithin a higher education, academic medical center, or highly decentralized corporateenvironment.• Advanced degree (master’s or equivalent) in a relevant technical or business field.• Active professional certifications such as CISA, CRISC, CISM, CISSP, or equivalentspecialized GRC certifications.• Deep specialization in NIST SP 800-53 and HIPAA Security/Privacy Rules. Thoroughunderstanding of how these controls apply to diverse IT environments (on-premises,cloud, SaaS).• Full technology stack experience – provides expert guidance to securely implement IAM,server, networking, application development and database services.Function: Information TechnologySubfunction: Information Security and Risk ManagementCareer Band: Individual Contributor - SpecializedProposed Career Level: S4Additional Information:The salary range for this position is $103,000 -$134,500 and the offer for this position will be based on internal equity and the candidate's qualifications.Function: Information TechnologySub-function: Information Security and Risk ManagementCareer Band: Individual Contributor - SpecializedCareer Level: S4Location:Mount Hall (0311)Position Type:RegularScheduled Hours:40Shift:First ShiftFinal candidates are subject to successful completion of a background check. A drug screen or physical may be required during the post offer process.Thank you for your interest in positions at The Ohio State University and Wexner Medical Center. Once you have applied, the most updated information on the status of your application can be found by visiting the Candidate Home section of this site. Please view your submitted applications by logging in and reviewing your status. For answers to additional questions please review the frequently asked questions .The university is an equal opportunity employer, including veterans and disability.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst
Senior Security Analyst

The Ohio State University • Columbus (OH)

On-site
USD 103,000 - 135,000
Sr. Apps Development Analyst - OSU Health Plan
Sr. Apps Development Analyst - OSU Health Plan

Ohio State University • Columbus (OH)

Hybrid
USD 85,000 - 110,000
Affordable health insurance options
Paid vacation and sick leave
Retirement plan options with employer contribution
Sr. Compliance Investigator
Sr. Compliance Investigator

Inside Higher Ed • Columbus (OH)

On-site
USD 70,000 - 90,000
Generous retirement plans
Affordable health insurance
Paid vacation and sick leave
Clinical Applications Analyst
Clinical Applications Analyst

Ohio State University • Columbus (OH), Northern (KY)

Hybrid
USD 65,000 - 90,000
Retirement benefits
Health insurance (dental/vision/prescr
Paid time off
+1
Senior Insurance Analyst
Senior Insurance Analyst

Inside Higher Ed • Columbus (OH)

On-site
USD 70,000 - 90,000
Generous retirement plan options
Affordable health insurance
Paid vacation and sick leave
Research Senior Technician - Pathology
Research Senior Technician - Pathology

Ohio State University • Columbus (OH)

On-site
USD 50,000 - 70,000
Medical, dental, and vision coverage
Paid time off including sick and vacation
State retirement plan options
IT Process Engineer
IT Process Engineer

Ohio State University • Columbus (OH)

Hybrid
USD 90,000 - 130,000
Retirement benefits
Health insurance
Vacation and paid time off
+4
Senior Security & Risk Analyst (GRC & Compliance)
Senior Security & Risk Analyst (GRC & Compliance)

Ohio State University • Columbus (OH)

On-site
USD 103,000 - 135,000
Assistant Radiation Safety Officer
Assistant Radiation Safety Officer

Ohio State University • Columbus (OH)

On-site
USD 111,000 - 146,000
Comprehensive benefits package
Opportunities for professional development
Professional development opportunities
Enterprise Applications Developer 4
Enterprise Applications Developer 4

Ohio State University • Columbus (OH)

Hybrid
USD 120,000 - 150,000