Lead Security Analyst

Ovative Group

$90K — $132K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2-5 years of experience in security analysis, GRC, IT audit, or compliance roles
  • Working knowledge of SOC 2, NIST CSF, or ISO 27001 frameworks
  • Experience with security questionnaires, vendor assessments, or audits
  • Familiarity with data privacy laws like CCPA and GDPR
  • Hands-on experience with generative AI tools and interests in AI governance
  • Strong written communication skills, particularly in simplifying technical outcomes
  • Excellent organization and detail orientation, able to manage multiple projects effectively

Responsibilities

  • Own client security questionnaires, developing a reusable answer library
  • Conduct vendor security assessments and track ongoing vendor risks
  • Run SOC 2 compliance operations and support audit processes
  • Maintain and update the risk register while preparing quarterly reviews
  • Drive the policy lifecycle including reviews and exception tracking
  • Support client contractual security obligation reviews with contracts team
  • Manage AI tool intake process, conducting risk assessments, and documentation

Benefits

  • Transparent view of compensation components including base salary and annual bonus
  • Comprehensive benefits package
  • Opportunity for professional development and growth within the company
  • Supportive work culture focused on security awareness and effective training programs
  • Access to cutting-edge technology and tools in AI governance and security compliance
Full Job Description
About the Role
Ovative Group is seeking a Security Analyst to join our growing Information Security team. Reporting to the Head of Information Security and Privacy, this role
owns the operational core of our governance, risk, and compliance program - client security questionnaires, vendor assessments, and SOC 2 operations - and builds out new capabilities in AI governance and enablement. The ideal candidate is a strong writer, highly organized, comfortable engaging both technical and non-technical stakeholders, and genuinely excited about helping a company adopt AI quickly and safely.

Responsibilities
Governance, Risk, and Compliance
  • Own client security questionnaires end to end; build and maintain a reusable answer library to make each response faster and more consistent
  • Conduct vendor security assessments for new vendors and renewals; maintain ongoing vendor risk tracking
  • Run SOC 2 compliance operations, including evidence collection, control monitoring, and audit support
  • Maintain the risk register: track remediation owners and progress, and prepare quarterly risk reviews
  • Drive the policy lifecycle: annual reviews, redline recommendations, and exception tracking
  • Support review of client contractual security obligations in partnership with our contracts administration team
  • Support data privacy compliance operations (CCPA, GDPR, etc.), including data inventory and mapping, subprocessor tracking, and data subject request support


AI Governance and Enablement
  • Operate the AI tool and vendor intake process: triage requests, run security and risk reviews, and document decisions
  • Conduct AI risk assessments using our risk methodology - threat modeling, control analysis, and risk scenarios - and help mature it into a repeatable framework
  • Build and maintain our AI inventory of approved tools, agents, and connectors; monitor for unapproved AI use
  • Maintain AI usage policies and standards, and manage the exception process
  • Support access reviews for AI agents and connectors, including what data non-human identities can reach
  • Deliver secure-AI enablement: training, office hours, and onboarding users to approved tools
  • Track the evolving AI regulatory and framework landscape (EU AI Act, NIST AI RMF, OWASP GenAI Security) and the AI governance sections appearing in client questionnaires


Security Awareness and Training
  • Manage the security awareness training program, including content updates, completion tracking, and new-hire onboarding
  • Run phishing simulation campaigns, reporting, and follow-up coaching
  • Own security communications and the intake channel for employee security questions


Identity and Access Governance
  • Coordinate and execute periodic user access reviews and validate offboarding completion
  • Review third-party application and OAuth grants across M365 and Google environments


Reporting and Security Operations Support
  • Build and maintain security metrics and dashboards covering operational trends, compliance posture, and training completion; support leadership reporting
  • Produce periodic threat intelligence digests for the team
  • Depending on experience and interest, support security alert triage, incident documentation, and tabletop exercise coordination
  • Support business continuity and disaster recovery plan maintenance and test coordination


Skills and Qualifications
  • Two-year or four-year degree in information security, information technology, business, or related field; or 3+ years of equivalent experience
  • 2-5 years of experience in a security analyst, GRC, IT audit, compliance, or similar role title and level will be commensurate with experience
  • Working knowledge of security and compliance frameworks such as SOC 2, NIST CSF, or ISO 27001
  • Experience responding to security questionnaires, conducting vendor assessments, or supporting audits
  • Familiarity with data privacy regulations (CCPA, GDPR, etc.)
  • Hands-on experience using generative AI tools, and a strong interest in AI governance and safe adoption
  • Excellent written communication - much of this work is turning technical reality into clear, accurate answers
  • Strong organization and attention to detail, with the ability to manage many parallel workstreams
  • Ability to work effectively with technical and non-technical stakeholders across the business


Preferred Qualifications
  • Certifications such as Security+, CISA, CRISC, or CIPP
  • Experience with compliance automation platforms (Vanta, Drata, or similar)
  • Familiarity with AI governance frameworks (NIST AI RMF, ISO/IEC 42001, OWASP GenAI Security)
  • Exposure to security operations tooling (SIEM, EDR) and alert triage
  • Experience with M365 and Google Workspace administration or security configuration
  • Basic scripting skills (Python or similar) for reporting and automation
  • Experience working with personal information or other regulated data

Pay Transparency
At Ovative, we offer a transparent view into three core components of your total
compensation package: Base Salary, Annual Bonus, and Benefits. The salary range for this position below is inclusive of an annual bonus. Actual offers are made with consideration for relevant experience and anticipated impact. Additional benefits information is provided below.

For our senior security analyst positions, our compensation ranges from $90,000 to $132,000, which is inclusive of a 20% bonus.

Similar Jobs

More Jobs at Ovative Group

More Information Technology Jobs

Find similar Lead Security Analyst jobs: