NIKE, Inc

Principal Information Security Analyst - Information Risk Management

NIKE, Inc$149K — $313K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's in Business Information Management, Computer Science, or related field; equivalent experience considered
  • 8+ years in information security or risk management with advancing responsibilities
  • 3+ years leading vendor or third-party risk assessments in large enterprises
  • Strong understanding of information security frameworks like NIST and ISO 27000
  • Proven experience in designing and operationalizing TPRM programs
  • Exceptional analytical and problem-solving capabilities for complex enterprise issues
  • Superb communication skills, especially in executive settings.

Responsibilities

  • Lead high-complexity third-party risk management assessments and initiatives
  • Implement standardized vendor risk-profiling methodologies across Nike's vendor landscape
  • Establish mandatory control effectiveness standards for vendor onboarding
  • Develop metrics and reporting for TPRM and executive visibility
  • Perform thorough risk assessments for potential and existing vendor relationships
  • Collaborate across multiple functions including Legal and Procurement to enhance vendor lifecycle governance
  • Mentor team members on risk assessment methodology and team communications.

Benefits

  • Remote work flexibility (except in South Dakota, Vermont, and West Virginia)
  • Professional development opportunities and mentorship
  • Collaboration with diverse, cross-functional teams
  • Ability to influence security strategy at a leading global brand
  • Participation in high-impact projects with visibility to executive leadership.
Full Job Description
Open to remote work except in South Dakota, Vermont and West Virginia.

The annual base salary for this position ranges from $149,100.00 in our lowest geographic market to $313,900.00 in our highest geographic market. Actual salary will vary based on a candidate's location, qualifications, skills and experience.

Information about benefits can be found here.

WHAT YOU WILL WORK ON

This role works with the Information Risk Management team to identify, assess, elevate visibility to, and remediate information security risks across Nike's technology landscape. As a Principal-level contributor, you will lead high-complexity assessments, shape team methodology, mentor analysts, and own key TPRM program initiatives.

Key responsibilities include:
Third-Party Risk Management Program Leadership
  • Advance TPRM capability maturity by designing and implementing program rigor beyond control self-assessments, including vendor risk profiling, risk-based controls testing, and tiered assurance requirements
  • Establish and operationalize a standardized vendor risk-profiling methodology (e.g., data sensitivity, criticality, regulatory impact) to consistently categorize vendors by inherent risk tier and drive risk-based assessment prioritization
  • Define and implement tiered assurance requirements so that higher-risk vendors undergo deeper validation (evidence reviews, control testing, security baseline documentation) while lower-risk vendors follow appropriately scaled processes
  • Introduce targeted validation of high-impact controls (e.g., access management, data protection, availability) for critical suppliers, going beyond self-attestation to validate design and operational effectiveness
  • Establish mandatory control effectiveness standards requiring vendors to demonstrate effective design and operational execution for high-impact controls prior to contractual engagement or network integration
  • Develop and operationalize TPRM metrics and executive reporting, including third-party blind metrics and integration into Executive TPRM Council reporting
  • Expand factory risk assessment program scope and contribute to assurance activities for Nike's highest-risk indirect and direct third parties
  • Plan and execute joint response planning tabletop exercises with key direct and indirect suppliers to validate incident readiness and coordination capabilities

Vendor Lifecycle Governance
  • Close vendor onboarding gaps by designing and enforcing standardized, enterprise-wide onboarding controls to ensure no vendor obtains network access or data-sharing capability until a thorough risk assessment is completed
  • Build and steward a centralized vendor inventory capturing all active vendors, associated services, and data-sharing agreements, with inventory updates embedded into the global onboarding workflow
  • Design and enforce a standardized, enterprise-wide vendor offboarding process to ensure all vendor access and data-sharing channels are terminated promptly and consistently at contract end
  • Partner with Procurement, Legal, Privacy, and Technology to align vendor lifecycle controls across domains and drive measurable compliance with TPRM onboarding and offboarding requirements
Enterprise Risk Leadership & Cross-Functional Influence
  • Serve as a recognized subject matter expert in information risk and cybersecurity across Nike, representing IRM and CIS with credibility and authority in forums, partner team engagements, and ad-hoc consultations
  • Embed with cross-functional partners, including Procurement, Legal, Privacy, Engineering, and Nike Business teams, to provide ongoing security risk guidance, ensuring these teams view information security as a strategic partner invested in their success
  • Identify emerging risks, capability gaps, and opportunities for enterprise-wide improvement that others have not yet surfaced, and drive action by building the case, gaining stakeholder alignment, and advancing solutions
  • Initiate and lead cross-team programs and initiatives that extend beyond IRM, such as enterprise data governance alignment, cross-domain risk standardization, or shared assurance frameworks, taking them from concept through operationalization with minimal oversight
  • When assigned to lead or support broader organizational initiatives, operate with full autonomy: set direction, engage stakeholders, build roadmaps, and drive execution end-to-end
  • Maintain and elevate the reputation of IRM and CIS by consistently demonstrating deep understanding of business context, delivering pragmatic risk guidance, and building trust as someone who gives direct, honest assessments of risk

Vendor Information Risk Assessments
  • Perform and lead formal risk assessments on partner and vendor connections, evaluating vendor processes at the point of engagement with Nike
  • Ensure sufficient validation of data sharing arrangements and agreements to protect Nike's sensitive information
  • Confirm business objectives align with the type and volume of data used, maintaining a "need to know/use" mindset
  • Review third-party SOC reports, security baseline documentation, and vendor security evidence as part of assessment activities
  • Establish risk and remediation ownership for identified vendor-related risks and document findings in the Risk Register
  • Serve as a senior escalation point for complex vendor risk decisions and exception recommendations

Security Controls Baseline Assessments
  • Lead assessments of complex platforms and systems against Nike security and configuration standards
  • Evaluate and process exceptions to information security policies and standards, providing principal-level recommendations on risk acceptance and compensating controls
  • Perform compliance control validation testing to determine the operating effectiveness of IT controls for scoped systems
  • Consult with technology units on IT general controls (ITGCs) and compliance matters
  • Champion information security policies, standards, controls, and processes so compliance requirements are addressed as part of business-as-usual operations

Internal Risk Assessments
  • Identify, document, and elevate visibility to information risk where business direction creates potential exposure to employee, athlete, and product sensitive data streams
  • Identify and profile Nike systems and processes that require risk assessments; scope and lead specific assessments accordingly
  • Perform detailed analysis of threats and vulnerabilities across information security domains including network security, asset security, security engineering, identity and access management, security operations, and software development security
  • Review key system configurations and complex IT infrastructures (e.g., cloud services, SaaS platforms, hybrid environments)
  • Communicate effectively through risk reports, presentations, and stakeholder interactions to drive remediation of identified risks

Data Analysis, Reporting, and Strategic Initiatives
  • Own vendor risk management metrics, reporting, and master data stewardship to improve accuracy, timeliness, and completeness
  • Provide analysis and insights into data supporting the effectiveness of technical and process-based cybersecurity controls
  • Lead process improvements for data retrieval, analysis, and risk assessment intake
  • Contribute to and lead IRM team projects and strategic initiatives, including documentation in ServiceNow (SNOW), Aravo, Jira, and Box
  • Support the risk analysis intake process and participate in daily standups and weekly process meetings
  • Mentor and coach Senior and Analyst-level team members on assessment methodology, stakeholder engagement, and risk communication
  • Influence information security strategy through risk-informed insights and expertise that drive the strategic direction of CIS in alignment with Nike's overall strategic vision

General Responsibilities
  • Execute and lead targeted internal and external (vendor) risk assessments in support of IRM strategy, following established team processes and enablers while continuously improving them
  • Be proactive in anticipating next steps in the risk assessment process and act accordingly
  • Collaborate with team members on assessment approach, scoping, documentation, and issue presentation activities; provide quality review and guidance on team deliverables
  • Serve as a principal-level information security and CIS representative to Nike lines of business and management, acting as the team's voice in cross-functional forums, building enduring relationships with partner teams, and ensuring IRM is sought out as a trusted advisor rather than engaged only as a checkpoint
  • Provide enforcement of security policies, standards, and procedures by working cross-functionally with Compliance and Governance functions
  • Stay current on information security technologies, trends, standards, best practices, and emerging threats and vulnerabilities

WHO YOU WILL WORK WITH

This role reports to the Director of Information Risk Management within Corporate Information Security (CIS). You will build strong partnerships with the IRM team, CIS leadership, Nike business and technology process owners, and various governance and legal functions (e.g., Audit, Privacy, and Legal). You will work cross-functionally across Nike at World Headquarters and globally, with particularly close collaboration with Procurement, Privacy, and Technology partners on third-party risk initiatives. You will regularly engage executive stakeholders through TPRM Council reporting and high-risk vendor escalation activities.

WHAT YOU BRING
  • Bachelor's degree in Business Information Management, Computer Science, or a related field; will accept any suitable combination of education, experience, and training
  • 8+ years of experience in information security, risk management, GRC, third-party risk management, or a related field, with demonstrated progression in scope, complexity, and influence
  • 3+ years of experience performing vendor/third-party risk assessments and leading internal information security risk assessments in a large enterprise environment
  • Deep knowledge of information security principles and practices, best practice security architectures, general procedures, and guidelines
  • Deep knowledge of information security frameworks and best practices (e.g., NIST, ISO 27000, COBIT, COSO)
  • Experience designing or operationalizing third-party risk management programs, including vendor tiering, tiered assurance models, vendor lifecycle governance, and TPRM metrics/reporting
  • Experience assessing systems against security standards and performing control validation or baseline assessments
  • Experience reviewing third-party SOC reports, security baseline documentation, and vendor assurance evidence
  • Experience partnering with Procurement, Legal, and Privacy on vendor risk and contractual security requirements
  • A general understanding of technology use, trends, and risks as they apply in a business context and environment
  • Exceptional analytical and problem-solving skills with proven ability to identify solutions for complex problems in enterprise environments
  • Superb communication skills (written and verbal) with comfort and experience presenting to executive audiences and proven persuasion skills
  • The ability to appropriately communicate complex security risks to non-technical staff and influence remediation at scale
  • Demonstrated experience serving as a recognized security subject matter expert beyond your immediate team; proactively consulted by partner functions and trusted to represent security's perspective in cross-functional settings
  • Track record of identifying organizational gaps or opportunities and independently initiating cross-team programs or initiatives that drove measurable improvement, not solely executing against a predefined roadmap</

About NIKE, Inc

Nike is a sporting goods company that designs, develops, and markets footwear, apparel, equipment, and accessory products. The company offers various categories of shoes including running, training, basketball, soccer, sport-inspired urban shoes, and kids' shoes. It also provides shoes for aquatic activities, baseball, football, cheerleading, golf, lacrosse, outdoor activities, skateboarding, tennis, volleyball, walking, wrestling, and various athletic and recreational uses. In addition, the company offers sports-inspired lifestyle apparel, athletic bags, and accessory items. Further, it provides a line of performance equipment including bags, socks, sports balls, eyewear, timepieces, electronic devices, bats, gloves, protective equipment, golf clubs, and various equipment designed for sports activities under the NIKE brand name, as well as markets apparel with licensed college and professional team and league logos. Additionally, it offers licenses to produce and sell NIKE brand swimwear, children's apparel, training equipment, eyewear, electronic devices, and golf accessories. The company also markets its products under the brand names of Converse, Chuck Taylor, All Star, One Star, Umbro, Jack Purcell, Cole Haan, Bragano, and Hurley. It sells its products to retail accounts through stores, independent distributors, and licensees, as well as through its Website, nikestore.com. As of May 31, 2009, Nike, Inc. operated 338 retail stores in the United States and 336 retail stores internationally. The company was founded in 1964 and is headquartered in Beaverton, Oregon.

Nike Careers

Join the dynamic world of Nike, Inc., a global leader in sports apparel and innovation, where your career can flourish in an environment that fosters diversity, leadership, and growth. At Nike, we believe in bringing out the best in our team members through continuous professional development and a culture that celebrates creativity and innovation. Work You’ll Do Become a part of Nike’s mission to inspire and innovate towards a better world. Engage in work that intersects with cutting-edge technology, market-leading strategies, and sustainable practices that define the future of the sports industry. Lead with us at the forefront of the global marketplace, where your skills in leadership, teamwork, and innovation can shine. Nike offers a unique position in the industry, combining deep industry expertise with a relentless pursuit of excellence. Collaborate with a diverse team of professionals who are pioneers in their fields. Nike, Inc. employs over 75,000 passionate and talented individuals worldwide, all dedicated to moving the world of sports forward. Introducing Nike’s Professional Growth and Development Opportunities We are committed to fostering an inclusive environment where every team member can succeed. Nike offers a variety of job opportunities, from in-store retail positions to corporate roles in design, marketing, and technology. Do Innovative Work Join us and contribute to our mission of bringing inspiration and innovation to every athlete* in the world. (*If you have a body, you are an athlete.) Deliver targeted solutions and drive innovation through your unique perspective and skills. At Nike, Inc., your work directly contributes to our global impact. Be Part of a Great Team Engage in meaningful work that connects with consumers and impacts millions worldwide. Our team benefits from unparalleled capabilities, a commitment to diversity training, and a culture that encourages professional growth and networking. Future-Proof Your Career Advance your career with Nike’s comprehensive benefits and support systems. We provide extensive training, development programs, and leadership courses to help you reach your full potential. Explore Discover how Nike is leading in sustainable innovation and pushing the boundaries of what’s possible in the sports industry. The Nike Employment Experience Our combined efforts in innovation, culture, and leadership make Nike, Inc. not just a place to work, but a place to grow a rewarding career. Clients and employees alike look to Nike for new strategies and impactful solutions in a rapidly evolving industry. Stay Connected Join Our Team Search for open positions that match your skills and interests. We are always on the lookout for curious, driven, creative, and solution-oriented team players. SEARCH NIKE JOBS Keep Up to Date Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. READ CAREERS BLOG Job Alert Emails Customize your subscription to receive job alerts, the latest news, and insider tips tailored to your preferences. Explore the exciting and rewarding opportunities that await at Nike, Inc.
Learn more about NIKE, Inc
Size
73,300 employees
Market Cap
$184.6 billion
Industry
Net Income
$2.8 billion
Founded
1964
5 Year Trend
+6.3%
Revenue
$38.2 billion
NASDAQ

Similar Jobs

More Jobs at NIKE, Inc

More Information Technology Jobs

  • Reynolds & Reynolds
    Director of Engineering
    Reynolds & Reynolds
    North Andover, MA 01845 (Essex County)
  • Program Manager
    $225K — $275K *
    Edgewater Federal Solutions, Inc.
    La Canada Flintridge, CA 91011 (Los Angeles County)
  • Full Stack Python Developer
    $126K — $128K *
    Edgewater Federal Solutions, Inc.
    Washington, DC 20011 (District Of Columbia County)
  • Service Desk Technical Lead
    $175K — $225K *
    Edgewater Federal Solutions, Inc.
    La Canada Flintridge, CA 91011 (Los Angeles County)
  • Flexsteel Industries
    ServiceNow Architect
    $156K — $195K *
    Flexsteel Industries
    Washington, DC 20011 (District Of Columbia County)

Find similar Principal Information Security Analyst - Information Risk Management jobs: