> Markdown version of [/jobs/ext/1293563-security-analyst](https://www.wearedevelopers.com/jobs/ext/1293563-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst - **Company:** Blackbaud, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $102,000.0 - $133,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cyber Security, Octave, PCI Data Security Standards, Information Technology, Servicenow - **Published:** July 16, 2026 - **Apply:** https://www.workingnomads.com/job/go/1732200/ ## About the Role * 8+ year's experience in Information Technology and/or Security * 3+ year's experience in leading audit/ assessment projects * 3+ year's experience in risk management frameworks (i.e., NIST CSF) * 2+ year's experience in quantitative risk management frameworks (FAIR, OCTAVE, etc.) * Experience in corporate GRC solutions (Archer, ServiceNow, etc.) * Experience in financial services, or other highly regulated industries (i.e. SOX, SOC, PCI DSS) * Experience working in an agile team * Demonstrated understanding of cyber risks and implementing mitigation plans * Possesses effective communication and presentation skills * Ability to handle multiple priorities and high stress situation * Industry Certifications like: CISSP, CRISC, CISM/CISA, AWS certification(s), Azure certification(s) Stay up to date on everything Blackbaud, follow us on Linkedin, Twitter, Instagram, Facebook and YouTube ## Description The Cyber Security Governance, Risk, and Compliance (GRC) team is looking for a Principal Security Analyst to be a key member of a critical security program responsible for security risk and compliance activities across the entire enterprise. The role will require working with various company stakeholders to build and mature the processes of preparing for how Blackbaud identifies, documents, and assesses risk across the organization and determine the strength of our control framework and implementation., * Articulate security risk through the development of Key Risk Indicators (KRIs) and report to multiple stakeholder groups, including the Executive Leadership Team (ELT) and Board of Directors. * Develop, assess, and implement cybersecurity controls and procedures required to protect the confidentiality, integrity, and availability of Blackbaud data. * Lead and coordinate internal and external security, compliance, and regulatory assessments, including customer audits, independent attestations, certification audits, and third party reviews. Serve as the primary liaison with assessors and stakeholders to ensure successful completion of assessment activities and remediation efforts. * Act as a key stakeholder in corporate governance forums and committees by serving as an active advocate for cybersecurity practices, risk management, and policy compliance. * Partner with control owners to continuously monitor control implementations, assess effectiveness, and track noncompliance issues through resolution. * Enhance change management processes to socialize, communicate, and educate stakeholders on policy, standard, and procedure updates. * Identify opportunities to strengthen and mature the organization's governance, risk, and compliance programs through continuous improvement initiatives and industry best practices. ## Related Videos - [Perfect Pitch: Unveiling the Mathematical Symphony Behind a Guitar Tuner](https://www.wearedevelopers.com/videos/1095-perfect-pitch-unveiling-the-mathematical-symphony-behind-a-guitar-tuner) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)