> Markdown version of [/jobs/ext/1263017-information-security-risk-analyst-2](https://www.wearedevelopers.com/jobs/ext/1263017-information-security-risk-analyst-2). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Risk Analyst 2 - **Company:** University of Minnesota - **Location:** Rolla, MO, United States - **Salary:** $85,000.0 - $95,000.0 - **Contract:** Permanent contract - **Skills:** Spreadsheets, Cyber Security, Open Web Application Security, PCI Data Security Standards, Control Structures, Data Analytics - **Published:** July 14, 2026 - **Apply:** https://jobs.chronicle.com/apply/38013983/information-security-risk-analyst-2?LinkSource=JobDetails ## About the Role * Bachelor's degree in a related field and 2 years of relevant work experience or a Master's degree. * 1 year experience in information security risk assessment, audit, quality assurance,or similar. * Excellent communication (oral, written, presentation), interpersonal and consultative skills., * Relevant work experience in a technical role, such as enterprise system management, or working within an IT-role in higher education * Knowledge of information security standards (e.g., ISO 27001/27002, NIST 800-171.), rules and regulations related to information security and data confidentiality (e.g., FERPA, GLBA, PCI DSS, HIPAA) * CISSP, CISA, or other security certifications are desirable. * Strong capability to analyze complex, ambiguous situations and synthesize conflicting information into clear, data-driven risk recommendations. * Demonstrated ability to look beyond surface-level technical symptoms to identify underlying root causes of systemic risk. ## Description The University of Minnesota's University Information Security seeks an Information Security Risk Analyst who will improve the information security of the University through information security risk assessments, security standards development, and exception management. The Information Security Risk Analyst will assess the information security posture of collegiate and administrative units by conducting information security risk assessments, including analyzing security controls and processes, interviewing subject matter experts, and helping to shape a risk-based approach to security across the entire University system. Why Join Our Team? As a Risk Analyst at the University of Minnesota, you won't just be checking boxes on a spreadsheet. You will act as a trusted consultant across a massive ecosystem - ranging from cutting-edge research labs and medical clinics to athletics and student services. Your work directly protects the privacy of our 50,000+ students and safeguards groundbreaking academic research., Security Analysis - 80% * Conduct information security assessments utilizing ISO 27001 / 27002, NIST 800-171 or other appropriate information security control structures; develop risk remediation plans, and facilitate risk remediation efforts. * Facilitate the information security risk management program by identifying areas most in need of risk assessment, coordinating risk assessments with other information security risk analysts, and consulting with information security architects. * Monitor and advise on information security needs for systems and processes at the University of Minnesota to ensure the information security controls for the campuses are consistent and appropriate. * Consult with administrative and collegiate units to address policy and process-related information security risks identified through the information security risk and exception management programs. * Collaborate with stakeholders by translating complex technical vulnerabilities and control deficiencies into clear, business-risk language for non-technical academic and administrative leaders. * Assist with development and maintenance of information security policies, standards, guidelines and procedures, based on industry best practices and compliance requirements. * Maintain a strong working knowledge of regulatory frameworks impacting higher education, including GLBA, PCI and FERPA while building knowledge of applicable security standards (SANS, OWASP, NIST). Procedural Support - 20% * Facilitate the exception management process by tracking exceptions to information security policies and standards, evaluating associated risks by working with the other information security staff, and coordinating communication with the risk owner. * Assist with information security reviews of vendors and suppliers., While our salary ranges provide a framework, it is important to note that most of the time, the initial pay may not reach the maximum of the range. This approach ensures that compensation reflects the value and unique contributions of each candidate while maintaining equity within our organization. As part of our commitment to fair and equitable compensation, please be aware that the salary offered to incoming candidates will be based on their individual credentials and experience. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [Launching a marketplace on-time: A lesson in taking shortcuts using spreadsheets!](https://www.wearedevelopers.com/videos/477-launching-a-marketplace-on-time-a-lesson-in-taking-shortcuts-using-spreadsheets) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Data Analyst Salary Austria](https://www.wearedevelopers.com/magazine/275-data-analyst-salary-austria) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)