Full Job Description
Lead IT Security Risk Analyst
City: REMOTE
Job Description:
Job Summary
The IT Security Risk Analyst is a recognized subject matter expert under limited oversight from their supervisor that provides information security risk assessment and compliance consulting services that contribute to a comprehensive information security risk management program. As a primary responsibility, this position provides Purdue IT International Organization for Standardization (ISO) related certification and Business Continuity/Disaster Recovery (BC/DR) subject matter expertise (SME) to the university. This involves a combination of leading, coordinating, and executing programs associated with SME.
The position also leads the execution of security and compliance (e.g., HIPAA, FERPA, GLBA, PCI, and other relevant regulations or standards) risk assessments as required by the University and as requested to improve information security posture. This position provides consulting on appropriate administrative, technical, and physical security controls for implementation to address security and compliance requirements. This position includes analyzing and interpreting information to document findings that are presented to management and technical staff. The position provides awareness training of security policies, tools, methodologies, and best practices. This position will monitor developments regarding laws and regulations, especially those associated with areas of SME, that could impact the organization and recommend measurable changes where necessary.
What We're Looking For
Education and Experience Required:
- A Bachelor's degree in relevant field, including Business, Computer Science, Engineering, Computer/Information Technology, or Information Security
- Equivalent combination of education and/or experience may be accepted
- At least six (6) years of progressive technical information security and/or IT compliance experience
- Experience:
- in performing information security risk and compliance assessments
- working with structured management systems or regulatory frameworks (e.g., ISO, NIST)
- participating in complex security initiatives in a large organization with varied teams and stakeholders
- contributing to and presenting security awareness information
Preferred
- Higher education work experience
- Technical security certifications in information security, risk compliance, or related discipline (e.g., CISSP or GIAC)
- Experience:
- supporting ISO 9001, ISO/IEC 20000-1, or ISO/IEC 27001 certification programs
- coordinating audits and BC/DR governance
Skills Required:
- Strong ability in developing, documenting, implementing, and monitoring information security plans or technology control plans
- Expert ability to communicate effectively with both technical and non-technical audiences at various levels within the organization
- Strong and detailed analysis, decision making, problem solving and customer service skills
- Keen attention to detail
- A broad understanding of technology
- Ability to work independently and within a team environment
- Must be able to work on site for assessments
Additional Information:
- Purdue University will not sponsor employment authorization for this position
- A background check will be required for employment in this position
- FLSA: Exempt (Not Eligible for Overtime)
- Retirement Eligibility: Immediate Defined Contribution by the university
- Benefit Statement: Purdue University offers a substantial Benefit Package including medical, dental, and vision insurance as well as a generous paid time off package for sick and vacation days