The Ohio State University

Senior Security Analyst

The Ohio State University$103K — $134K *
Education, Government & Non-Profit
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in IT, cyber security, computer science, or related field (or equivalent experience)
  • 6+ years in information security governance, risk, and compliance
  • Broad understanding of IAM, server, networking, application development, and database concepts
  • 8-12 years preferred GRC experience in higher education or similar environments
  • Master’s degree or equivalent in relevant field preferred
  • Relevant certifications like CISA, CRISC, CISM, CISSP encouraged
  • Deep knowledge of NIST SP 800-53 and HIPAA controls in varied IT environments

Responsibilities

  • Own and operate the university’s Information Security and Privacy Control Requirements (ISPCR)
  • Map policies and controls to industry standards and regulations like NIST and HIPAA
  • Develop and implement compliance practices and key performance metrics
  • Lead complex, large-scope risk assessment initiatives affecting university’s risk posture
  • Execute and oversee detailed risk assessments for various environments
  • Provide actionable mitigation strategies to address security gaps
  • Guide and mentor less experienced IT and security colleagues
  • Communicate complex risk information effectively to diverse stakeholders

Benefits

  • Comprehensive information security and privacy framework
  • Autonomy in decision-making and problem-solving
  • Opportunity to lead initiatives with significant impact
  • Mentorship opportunities to develop junior staff
  • Collaboration across a decentralized IT and security organization
Full Job Description

Screen reader users may encounter difficulty with this site. For assistance with applying, please contact . If you have questions while submitting an application, please review these frequently asked questions.

Current Employees and Students:

If you are currently employed or enrolled as a student at The Ohio State University, please log in to to use the internal application process.

Job Title:
Senior Security Analyst

Department:
OTDI | Governance and Risk Management

Senior Security Analyst Position Summary

The Senior Security Analyst is a high-impact, specialized position within The Ohio State University’s Office of Technology and Digital Innovation. This role is responsible for designing, managing, and evolving the comprehensive information security and privacy framework across the university and medical center. Operating with a high degree of autonomy, the Senior Security Analyst will apply advanced industry knowledge to solve highly complex problems, develop new risk models, establish precedents that safeguard the university's academic, research, and administrative environments, and lead technical focus groups to determine the applicability of industry standards to university business.

Key Responsibilities

• Own and operate the university’s Information Security and Privacy Control Requirements

(ISPCR), ensuring alignment with institutional goals.

• Map institutional policies and controls to industry standards and regulatory requirements,

such as NIST SP 800-53, NIST SP 800-171, CIS Benchmarks, HIPAA, FERPA, GLBA,

and PCI-DSS.CIS Controls, ISO/IEC 27001, SOC 2, HIPAA, FERPA, GLBA, PCI DSS,

or similar.

• Develop, refine, and implement new compliance practices, processes, maturity models,

and key performance metrics to measure framework effectiveness over time.

• Lead highly complex, large-scope risk assessment initiatives that have a significant and

long-term impact on the university’s risk posture.

• Scope, execute, and oversee Tier 1, Tier 2, and Tier 3 risk assessments, evaluating critical

campus infrastructure, cloud environments, third-party vendors, and research data

environments.

• Provide actionable, technically sound mitigation strategies to system owners, researchers,

and technical teams to remediate identified gaps.

• Provide guidance, mentorship, and technical oversight to less experienced colleagues

across the distributed university IT and security organizations.

• Convey difficult, highly complex, or sensitive risk information to diverse campus

stakeholders and leadership, from technical system administrators to non-technical

academic leadership.

• Facilitate productive dialogue and use advanced communication skills to persuade

others to adopt secure practices and consider alternative risk-treatment options.

Required Education & Experience

• Bachelor’s degree in information technology, cyber security, computer science, or a

related field (or equivalent professional experience).

• Minimum of 6 years of direct experience in information security governance, risk, and

compliance.• Full technology stack knowledge – broad understanding and ability to explain identity

and access management (IAM), server, networking, application development and

database concepts.

Preferred Education & Experience

• 8 to 12 years of relevant governance, risk, and compliance (GRC) experience, ideally

within a higher education, academic medical center, or highly decentralized corporate

environment.

• Advanced degree (master’s or equivalent) in a relevant technical or business field.

• Active professional certifications such as CISA, CRISC, CISM, CISSP, or equivalent

specialized GRC certifications.

• Deep specialization in NIST SP 800-53 and HIPAA Security/Privacy Rules. Thorough

understanding of how these controls apply to diverse IT environments (on-premises,

cloud, SaaS).

• Full technology stack experience – provides expert guidance to securely implement IAM,

server, networking, application development and database services.

Function: Information Technology

Subfunction: Information Security and Risk Management

Career Band: Individual Contributor - Specialized

Proposed Career Level: S4

Additional Information:

The salary range for this position is $103,000 -$134,500 and the offer for this position will be based on internal equity and the candidate's qualifications.

Function: Information Technology

Sub-function: Information Security and Risk Management

Career Band:   Individual Contributor - Specialized

Career Level: S4

Location:
Mount Hall (0311)

Position Type:
Regular

Scheduled Hours:
40

Shift:
First Shift

About The Ohio State University

The Ohio State University (OSU) is a public research university located in Columbus, Ohio. It was founded in 1870 and is one of the largest universities in the United States, with over 68,000 students enrolled across its main campus and regional campuses. OSU offers a wide range of undergraduate and graduate programs in various fields, including business, engineering, education, law, medicine, and the arts and sciences. The university is known for its strong research programs, particularly in the areas of agriculture, engineering, and medicine. OSU is also home to several museums, including the Wexner Center for the Arts and the Ohio State University Museum of Art.
Learn more about The Ohio State University
Size
45,831 employees
Industry

Similar Jobs

More Jobs at The Ohio State University

More Education, Government & Non-Profit Jobs

  • State Of Delaware
    Director of Accounting
    $130K *
    State Of Delaware
    Dover, DE 19904 (Kent County)
  • Deputy Building Official
    $80K — $150K + gloucester county government offers an excellent benefit package *
    Gloucester County
    Gloucester, VA 23061 (Gloucester County)
  • Deputy Assessor
    $80K — $150K + gloucester county government offers an excellent benefit package *
    Gloucester County
    Gloucester, VA 23061 (Gloucester County)
  • Civil Engineer II
    $80K — $150K + gloucester county government offers an excellent benefit package *
    Gloucester County
    Gloucester, VA 23061 (Gloucester County)
  • Accounting Manager
    $80K — $100K + gloucester county government offers an excellent benefit package *
    Gloucester County
    Gloucester, VA 23061 (Gloucester County)

Find similar Senior Security Analyst jobs: