University of California San Diego

Sr. IT Security Risk & Compliance Analyst - Remote - 140476

US-AnywhereRemote in San Diego, CA
Healthcare
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Nine years of experience in information security risk assessment, compliance, or governance, or a Bachelor's degree and five years of related experience.
  • Strong skills in communication with both technical and non-technical personnel.
  • Proficient with IT security systems and tools.
  • Knowledge of department processes and operational procedures.
  • Experience applying security controls to hardware and software environments.
  • Expertise in administering complex security configurations across networks.
  • In-depth understanding of data encryption technologies.

Responsibilities

  • Conduct advanced information security risk assessments and compliance reviews.
  • Evaluate the design and effectiveness of security controls.
  • Document security risks, threats, and vulnerabilities.
  • Support the alignment of security practices with regulatory requirements, such as HIPAA and PCI DSS.
  • Develop and maintain governance documentation and risk management processes.
  • Communicate risk findings and recommendations to stakeholders at various levels.
  • Support audit readiness and compliance monitoring activities.

Benefits

  • Remote work flexibility with the ability to work various hours and locations based on business needs.
  • Opportunity for professional growth in a supportive academic medical center environment.
  • Access to a collaborative work culture that values the contributions of IT security professionals.
Full Job Description
Payroll Title:
IT SCRTY ANL 4 TX Department:
INFORMATION SERVICES Hiring Pay Scale
$130,000 - $170,000 / Year Worksite:
Towne Centre Drive Appointment Type:
Career Appointment Percent:
100% Union:
TX Contract Total Openings:
1 Work Schedule:
Days, 8 hrs/day, Monday-Friday

#140476 Sr. IT Security Risk & Compliance Analyst - Remote
Filing Deadline: Thu 7/23/2026
Apply Now

DESCRIPTION

The Senior IT Security Risk and Compliance Analyst performs advanced information security risk assessment, governance, compliance, policy, and assurance activities across UC San Diego Health. Supports the development, implementation, and continuous improvement of information security risk management and compliance programs by identifying, assessing, and documenting security risks, threats, vulnerabilities, and control deficiencies affecting technologies, applications, systems, vendors/3rd-parties, business processes, research environments, and information assets. Provides risk-based recommendations to strengthen the organization's overall security posture and support informed decision-making.

Conducts complex security risk assessments, compliance reviews, and control evaluations; assesses control design and effectiveness, reviews supporting evidence, evaluates residual risk, and supports remediation planning. Activities include assessment of third-party providers, cloud services, new technologies, and other initiatives that introduce information security risk. Ensures alignment with University policy, industry standards, contractual obligations, and applicable regulatory requirements, including HIPAA, PCI DSS, FERPA, and related requirements.

Contributes to the development, maintenance, and communication of information security policies, standards, procedures, and related governance activities. Supports audit readiness, compliance monitoring, assurance activities, and risk treatment processes through evaluation of security controls, compensating controls, exception requests, corrective actions, and risk acceptance decisions. Develops and maintains documentation supporting risk assessments, compliance reviews, governance processes, audit requests, remediation activities, and regulatory requirements.

Serves as a trusted advisor to technical and business stakeholders regarding information security risks, compliance obligations, governance requirements, and remediation strategies. Communicates findings, recommendations, and risk determinations to stakeholders at multiple organizational levels and helps prioritize mitigation efforts based on risk to patient care, clinical operations, research activities, regulatory obligations, institutional objectives, and operational resiliency. Contributes to the maturity and effectiveness of the organization's information security, risk management, governance, and compliance programs.

May support investigations, legal requests, eDiscovery activities, and other matters requiring a high degree of professionalism, discretion, and confidentiality.

MINIMUM QUALIFICATIONS
  • Nine (9) years of related experience, education/training, OR a Bachelor's degree in a related area plus five (5) years of related experience/training. Related experience includes advanced information security risk assessment, compliance, governance, security assurance, control evaluation, or technical security activities within complex organizational environments.
  • Advanced interpersonal skills sufficient to work effectively with both technical and non-technical personnel at various levels in the organization.
  • Advanced experience using IT security systems and tools.
  • Knowledge of department processes and procedures.
  • Demonstrated skills applying security controls to computer software and hardware.
  • Demonstrated skill at administering complex security controls and configurations to computer hardware, software and networks.
  • Advanced knowledge of data encryption technologies and experience selecting and applying appropriate data encryption technologies.
  • Advanced knowledge of IT security.
  • Broad knowledge of other areas of IT.
  • Demonstrated knowledge of secure hardware, software and network design techniques.
  • Demonstrated skill at analyzing and preventing security incidents of high complexity.
  • In-depth knowledge of computer hardware, software and network security issues and approaches.
  • Advanced experience in incident response and digital forensics including reporting.
PREFERRED QUALIFICATIONS
  • Advanced experience conducting and documenting security risk assessments, control evaluations, security reviews, or security assurance activities across applications, systems, cloud services, vendors, research environments, or business processes.
  • Demonstrated ability to evaluate technical, administrative, and operational security controls and determine residual risk, control gaps, and risk-based recommendations.
  • Knowledge of evidence-based assessment techniques, including review of technical artifacts, configuration documentation, vulnerability data, remediation records, access control evidence, vendor documentation, and stakeholder attestations.
  • Experience documenting and managing risk exceptions, compensating controls, corrective action plans, risk acceptance decisions, and related governance activities.
  • Knowledge of vulnerability governance practices, including risk-based prioritization, remediation tracking, exception management, corrective action validation, and residual risk documentation.
  • Experience supporting audit readiness, compliance reviews, accreditation activities, regulatory inquiries, or other assurance-related processes through preparation, review, or validation of supporting documentation and evidence.
  • Knowledge of security and compliance frameworks, regulatory requirements, and industry practices relevant to healthcare, higher education, research, and regulated environments.
  • Experience working in healthcare, academic medical centers, research environments, higher education, or similarly regulated organizations.
  • Security-related certification such as CISSP, CRISC, CISM, CISA, HCISPP, or equivalent; CISSP strongly preferred.
SPECIAL CONDITIONS
  • Must be able to work various hours and locations based on business needs.
  • Employment is subject to a criminal background check and pre-employment physical.
Pay Transparency Act

Annual Full Pay Range: Unclassified - No data available (will be prorated if the appointment percentage is less than 100%)

Hourly Equivalent: Unclassified - No data available

Factors in determining the appropriate compensation for a role include experience, skills, knowledge, abilities, education, licensure and certifications, and other business and organizational needs. The Hiring Pay Scale referenced in the job posting is the budgeted salary or hourly range that the University reasonably expects to pay for this position. The Annual Full Pay Range may be broader than what the University anticipates to pay for this position, based on internal equity, budget, and collective bargaining agreements (when applicable).

Apply Now

About University of California San Diego

The University of California San Diego (UC San Diego) is a public research university in San Diego, California. Established in 1960 near the pre-existing Scripps Institution of Oceanography, UC San Diego is the seventh-oldest of the 10 University of California campuses and offers over 200 undergraduate and graduate degree programs, enrolling approximately 38,325 students. UC San Diego is organized into six undergraduate residential colleges (Revelle, John Muir, Thurgood Marshall, Earl Warren, Eleanor Roosevelt, and Sixth College) and five academic divisions (Arts and Humanities, Biological Sciences, Jacobs School of Engineering, Physical Sciences, and Social Sciences). The university operates 19 organized research units (ORUs), including the Center for Energy Research, Qualcomm Institute (a branch of the California Institute for Telecommunications and Information Technology), and the San Diego Supercomputer Center.
Learn more about University of California San Diego
Size
38,325 employees
Industry

Similar Jobs

More Jobs at University of California San Diego

More Healthcare Jobs

Find similar Sr. IT Security Risk & Compliance Analyst - Remote - 140476 jobs: