Senior Security Analyst

Jobtailor

Columbus (OH)

On-site

USD 120,000 - 155,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Jobtailor is seeking a senior Information Security and Compliance leader to oversee ISPCR and align policies with industry standards. You will drive risk assessments across campus infrastructure, cloud environments, and vendors, delivering mitigation strategies and governance that inform leadership decisions.

With 6+ years in GRC, you will mentor colleagues, communicate complex risk to diverse stakeholders, and advance security maturity across university operations.

Qualifications

  • Bachelor’s degree in information technology, cyber security, computer science, or a related field (or equivalent professional experience).
  • Minimum of 6 years of direct experience in information security governance, risk, and compliance.
  • Broad understanding of IAM, server, networking, application development, and database concepts.
  • Final candidates must successfully complete a background check.
  • Preferred: 8 to 12 years of relevant governance, risk, and compliance (GRC) experience.
  • Preferred: Advanced degree in a relevant technical or business field.
  • Preferred: Active professional certifications such as CISA, CRISC, CISM, CISSP, or equivalent specialized GRC certifications.
  • Preferred: Deep specialization in NIST SP 800-53 and HIPAA Security/Privacy Rules.

Responsibilities

  • Own and operate the university’s Information Security and Privacy Control Requirements (ISPCR).
  • Map institutional policies and controls to industry standards and regulatory requirements.
  • Develop, refine, and implement compliance practices, processes, maturity models, and key performance metrics.
  • Lead complex, large-scope risk assessment initiatives.
  • Scope, execute, and oversee Tier 1, Tier 2, and Tier 3 risk assessments across campus infrastructure, cloud environments, third-party vendors, and research data environments.
  • Provide technically sound mitigation strategies to system owners, researchers, and technical teams.
  • Provide guidance, mentorship, and technical oversight to less experienced colleagues.
  • Communicate complex or sensitive risk information to technical and non-technical stakeholders and leadership.
  • Facilitate dialogue and persuade stakeholders to adopt secure practices and consider alternative risk-treatment options.

Skills

Information Security Governance
Risk Assessment Initiatives
NIST SP 800-53
Compliance Practices
Identity and Access Management
Cloud Environments
Database Concepts
Networking Concepts
Application Development
Mitigation Strategies
Performance Metrics

Education

Bachelor’s degree in IT / Cyber Security / CS
Advanced degree (Master’s) preferred

Job description

Own and operate the university’s Information Security and Privacy Control Requirements (ISPCR)
Map institutional policies and controls to industry standards and regulatory requirements, including NIST SP 800-53, NIST SP 800-171, CIS Benchmarks, HIPAA, FERPA, GLBA, PCI-DSS, CIS Controls, ISO/IEC 27001, and SOC 2
Develop, refine, and implement compliance practices, processes, maturity models, and key performance metrics
Lead complex, large-scope risk assessment initiatives
Scope, execute, and oversee Tier 1, Tier 2, and Tier 3 risk assessments across campus infrastructure, cloud environments, third-party vendors, and research data environments
Provide technically sound mitigation strategies to system owners, researchers, and technical teams
Provide guidance, mentorship, and technical oversight to less experienced colleagues
Communicate complex or sensitive risk information to technical and non-technical stakeholders and leadership
Facilitate dialogue and persuade stakeholders to adopt secure practices and consider alternative risk-treatment options

Requirements
  • Bachelor’s degree in information technology, cyber security, computer science, or a related field (or equivalent professional experience)
  • Minimum of 6 years of direct experience in information security governance, risk, and compliance
  • Broad understanding of identity and access management (IAM), server, networking, application development, and database concepts
  • Final candidates must successfully complete a background check
  • Preferred: 8 to 12 years of relevant governance, risk, and compliance (GRC) experience
  • Preferred: Advanced degree (master’s or equivalent) in a relevant technical or business field
  • Preferred: Active professional certifications such as CISA, CRISC, CISM, CISSP, or equivalent specialized GRC certifications
  • Preferred: Deep specialization in NIST SP 800-53 and HIPAA Security/Privacy Rules
  • Preferred: Expert guidance on securely implementing IAM, server, networking, application development, and database services
Core Competencies

Demonstrates expertise in Information Security Governance, Risk, and Compliance (GRC) with a strong focus on NIST SP 800-53, HIPAA, and risk assessment methodologies. Capable of developing and implementing compliance practices while effectively communicating complex risk information to diverse stakeholders.

Highest-signal resume keywords
  • Information Security Governance
  • Risk Assessment Initiatives
  • NIST SP 800-53
  • Compliance Practices Development
  • Identity and Access Management
ATS Optimization Keywords
Hard Skills
  • Information Security Governance
  • Risk Assessment
  • Compliance Practices
  • Identity and Access Management
  • Cloud Environments
  • Database Concepts
  • Networking Concepts
  • Application Development
  • Mitigation Strategies
  • Performance Metrics
Soft Skills
  • Mentorship
  • Communication
  • Persuasion
  • Stakeholder Engagement
  • Technical Oversight
Certifications & Qualifications
  • CISA
  • CRISC
  • CISM
  • CISSP
Industry Keywords
  • NIST SP 800-171
  • CIS Benchmarks
  • HIPAA
  • FERPA
  • GLBA
  • PCI-DSS
  • CIS Controls
  • ISO/IEC 27001
  • SOC 2
  • Governance, Risk, and Compliance
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Lead
GRC Lead

Jobtailor • Houston (TX)

On-site
USD 120,000 - 180,000
Manager – Cybersecurity Fusion Center
Manager – Cybersecurity Fusion Center

Jobtailor • West Valley City (UT)

On-site
USD 190,000 - 240,000
Information Security Specialist – Technology Asset Governance, Risk Management
Information Security Specialist – Technology Asset Governance, Risk Management

Jobtailor • Town of Florida (NY)

Hybrid
USD 120,000 - 180,000
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Information Security Specialist – Regional
Information Security Specialist – Regional

Jobtailor • Missouri

On-site
USD 90,000 - 130,000
Senior Information Security Analyst – CSIRT
Senior Information Security Analyst – CSIRT

Jobtailor • Mount Laurel Township (NJ)

On-site
USD 110,000 - 170,000
VP – AI Security and Data Protection Governance and Controls
VP – AI Security and Data Protection Governance and Controls

Jobtailor • United States

On-site
USD 180,000 - 280,000
Staff Risk Expert
Staff Risk Expert

Jobtailor • Herndon (VA)

On-site
USD 110,000 - 160,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Information Security Officer
Information Security Officer

Jobtailor • Massachusetts

On-site
USD 200,000 - 320,000