Senior Security Analyst

The Ohio State University

Columbus (OH)

On-site

USD 103,000 - 135,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

The Ohio State University is seeking a Senior Security Analyst within the Office of Technology and Digital Innovation. The role designs, manages, and evolves the university's information security and privacy framework across campus and medical center, with autonomy to apply advanced industry knowledge to solve complex problems.

Responsibilities include leading risk assessments, mapping controls to standards, and providing guidance to researchers and system owners.

Qualifications

  • Bachelor’s degree or equivalent professional experience in information technology, cyber security, or related field.

Responsibilities

  • Own and operate ISPCR and align with institutional goals.
  • Map policies to standards and regulatory requirements.
  • Develop and implement compliance practices and metrics.
  • Lead large-scale risk assessments across campus.
  • Assess campus infrastructure, cloud environments, and vendors.
  • Provide actionable risk mitigation guidance to owners and teams.
  • Mentor peers across IT and security groups.
  • Explain risk to technical and non-technical stakeholders.
  • Persuade stakeholders to adopt secure practices.

Skills

Information security
Governance
Risk management
Compliance

Education

Bachelor’s degree in information technology, cyber security, computer science, or related field
Advanced degree (master’s or equivalent)
CISA
CRISC
CISM
CISSP

Tools

NIST SP 800-53
HIPAA/FERPA/GDLP controls

Job description

Job Title:Senior Security AnalystDepartment:OTDI | Governance and Risk Management

Senior Security Analyst Position Summary

The Senior Security Analyst is a high-impact, specialized position within The Ohio State University’s Office of Technology and Digital Innovation. This role is responsible for designing, managing, and evolving the comprehensive information security and privacy framework across the university and medical center. Operating with a high degree of autonomy, the Senior Security Analyst will apply advanced industry knowledge to solve highly complex problems, develop new risk models, establish precedents that safeguard the university's academic, research, and administrative environments, and lead technical focus groups to determine the applicability of industry standards to university business.

Key Responsibilities
  • Own and operate the university’s Information Security and Privacy Control Requirements (ISPCR), ensuring alignment with institutional goals.
  • Map institutional policies and controls to industry standards and regulatory requirements, such as NIST SP 800-53, NIST SP 800-171, CIS Benchmarks, HIPAA, FERPA, GLBA, and PCI-DSS.CIS Controls, ISO/IEC 27001, SOC 2, HIPAA, FERPA, GLBA, PCI DSS, or similar.
  • Develop, refine, and implement new compliance practices, processes, maturity models, and key performance metrics to measure framework effectiveness over time.
  • Lead highly complex, large-scope risk assessment initiatives that have a significant and long-term impact on the university’s risk posture.
  • Scope, execute, and oversee Tier 1, Tier 2, and Tier 3 risk assessments, evaluating critical campus infrastructure, cloud environments, third-party vendors, and research data environments.
  • Provide actionable, technically sound mitigation strategies to system owners, researchers, and technical teams to remediate identified gaps.
  • Provide guidance, mentorship, and technical oversight to less experienced colleagues across the distributed university IT and security organizations.
  • Convey difficult, highly complex, or sensitive risk information to diverse campus stakeholders and leadership, from technical system administrators to non-technical academic leadership.
  • Facilitate productive dialogue and use advanced communication skills to persuade others to adopt secure practices and consider alternative risk-treatment options.
Required Education & Experience
  • Bachelor’s degree in information technology, cyber security, computer science, or a related field (or equivalent professional experience).
  • Minimum of 6 years of direct experience in information security governance, risk, and compliance.
  • Full technology stack knowledge – broad understanding and ability to explain identity and access management (IAM), server, networking, application development and database concepts.
Preferred Education & Experience
  • 8 to 12 years of relevant governance, risk, and compliance (GRC) experience, ideally within a higher education, academic medical center, or highly decentralized corporate environment.
  • Advanced degree (master’s or equivalent) in a relevant technical or business field.
  • Active professional certifications such as CISA, CRISC, CISM, CISSP, or equivalent specialized GRC certifications.
  • Deep specialization in NIST SP 800-53 and HIPAA Security/Privacy Rules. Thorough understanding of how these controls apply to diverse IT environments (on-premises, cloud, SaaS).
  • Full technology stack experience – provides expert guidance to securely implement IAM, server, networking, application development and database services.

Function: Information Technology

Subfunction: Information Security and Risk Management

Career Band: Individual Contributor - Specialized

Proposed Career Level: S4

The salary range for this position is $103,000 -$134,500 and the offer for this position will be based on internal equity and the candidate's qualifications.

Function: Information Technology

Sub-function: Information Security and Risk Management

Career Band: Individual Contributor - Specialized

Career Level: S4

Location:Mount Hall (0311) Position Type:Regular Scheduled Hours:40 Shift:First Shift Final candidates are subject to successful completion of a background check. A drug screen or physical may be required during the post offer process.

Thank you for your interest in positions at The Ohio State University and Wexner Medical Center. Once you have applied, the most updated information on the status of your application can be found by visiting the Candidate Home section of this site. Please view your submitted applications by logging in and reviewing your status. For answers to additional questions please review the frequently asked questions.

The university is an equal opportunity employer, including veterans and disability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst
Senior Security Analyst

Ohio State University • Columbus (OH)

On-site
USD 103,000 - 135,000
Senior Security & Risk Analyst (GRC & Compliance)
Senior Security & Risk Analyst (GRC & Compliance)

Ohio State University • Columbus (OH)

On-site
USD 103,000 - 135,000
Senior Security & Risk Architect
Senior Security & Risk Architect

The Ohio State University • Columbus (OH)

On-site
USD 103,000 - 135,000
Sr. Compliance Investigator
Sr. Compliance Investigator

Inside Higher Ed • Columbus (OH)

On-site
USD 70,000 - 90,000
Generous retirement plans
Affordable health insurance
Paid vacation and sick leave
Senior Information Security Analyst
Senior Information Security Analyst

UMass Amherst • Amherst (MA)

Hybrid
USD 120,000 - 150,000
Senior Insurance Analyst
Senior Insurance Analyst

Inside Higher Ed • Columbus (OH)

On-site
USD 70,000 - 90,000
Generous retirement plan options
Affordable health insurance
Paid vacation and sick leave
Senior Data Management Analyst
Senior Data Management Analyst

Inside Higher Ed • Columbus (OH)

On-site
USD 75,000 - 99,000
Senior Information Systems Auditor
Senior Information Systems Auditor

The Ohio State University • North Carolina

Hybrid
USD 82,000 - 107,000
Senior Information Systems Auditor
Senior Information Systems Auditor

Ohio State University • Columbus (OH)

On-site
USD 82,000 - 107,000
Medical, dental and vision
Paid time off
Retirement plan
Chief Information Security Officer
Chief Information Security Officer

The Ohio State University • Columbus (OH)

On-site
USD 180,000 - 260,000