Information Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+2 more
Job description
We are seeking a motivated, detail-oriented Information Security Analyst to own and mature Rice Parkās information security governance, risk, and compliance (āGRCā) program. This is a governance and risk management role, not a security operations role: Rice Park engages a third-party managed security services provider (āMSSPā) to handle day-to-day SIEM monitoring, alert triage, and SOC-level response.
This position is the internal owner of that vendor relationship and of Rice Parkās broader InfoSec program - ensuring the MSSP is delivering against its scope, identifying and closing the gaps the vendor does not cover (e.g., access reviews, policy governance, internal risk assessments), and driving Rice Parkās compliance posture across frameworks such as SOC 2 and GLBA, as well as investor and lender due diligence requirements.
The Information Security Analyst will work closely with the head of IT and coordinate across the organization to manage risk, maintain governance documentation, and ensure Rice Park meets its regulatory, contractual, and investor-facing security obligations., Vendor & Security Program Management
- Serve as the primary internal owner of the relationship with Rice Parkās managed security services provider (MSSP), ensuring SLAs are met and proactively identifying coverage gaps
- Coordinate third-party penetration testing engagements, including scoping, scheduling, documentation, and remediation tracking
- Track and drive remediation of findings from the MSSP, internal audits, and vulnerability scans
Governance, Risk & Compliance
- Own and maintain the information security policy and procedure suite, including annual review and approval cycles
- Lead SOC 2, GLBA, and related compliance efforts, including evidence collection, control testing, and remediation of gaps
- Conduct internal and external risk assessments and audits, and maintain the enterprise risk register
- Support the development and execution of Business Impact Analyses (BIA), business continuity planning, and related risk management activities
- Manage investor, lender, and other counterparty information security due diligence requests and questionnaires, on both an ad hoc and annual basis
Access & Control Oversight
- Own the user access review program across systems and applications - an area outside the MSSPās scope - including designing the review cadence and ensuring appropriate controls are documented and enforced
- Serve as the internal escalation point of contact for the MSSP during a security incident, coordinating internal response, documentation, and communication
Awareness & Continuous Improvement
- Maintain and deliver Rice Parkās security awareness training and phishing simulation program
- Collaborate with internal teams across the organization to promote security awareness and ensure adherence to security policies and protocols
- Stay current on cybersecurity trends, regulatory developments, and industry best practices relevant to Rice Parkās risk profile
- Undertake other related duties as assigned to support business operations and evolving organizational needs
Requirements
- Bachelorās degree in Information Technology, Risk Management, Business, Cybersecurity, or a related field (or equivalent experience)
- 2+ years of experience in information security governance, risk, or compliance (GRC); experience managing an MSSP or other outsourced security vendor relationship is a strong plus
- Working knowledge of regulatory and compliance frameworks such as SOC 2, ISO 27001, NIST CSF, and GLBA
- Experience conducting or supporting risk assessments, audits, access reviews, and third-party/vendor due diligence
- Strong policy writing, documentation, and project management skills
- Familiarity with SIEM and security tooling output sufficient to interpret and act on vendor reporting (hands-on SIEM operation is not required - that is handled by our MSSP)
- Strong organizational and communication skills; comfort managing vendors and driving cross-functional accountability
- Ability to handle sensitive information with discretion and professionalism
- Nice to have: exposure to a scripting or programming language (e.g., SQL, Python) for reporting and data analysis
- Nice to have: CISA, CRISC, or a similar governance-oriented certification, * Briefly describe your hands-on experience in information security over the past 2-3 years (e.g., monitoring, incident response, vulnerability management, compliance, etc.).
- Which security tools or platforms have you worked with (e.g., SIEM, EDR, vulnerability scanners), and what was your role in using them?
- Do you have at least 2+ years of mortgage related experience?
Benefits & conditions
Pulled from the full job description
- Health insurance
- 401(k) matching
- Paid time off
- Vision insurance
- Dental insurance
- Life insurance
- Disability insurance, This is a full-time position with competitive compensation (salary & bonus) and a comprehensive benefits package including:
- Medical, Dental, Vision Insurance Options
- Paid Time Off and Paid Holidays
- Company Paid Life Insurance
- Long-Term Disability
- 401(k) with employer match
Work Location: Plymouth, MN (hybrid
Pay: $60,000.00 - $90,000.00 per year
Benefits:
- Dental insurance
- Health insurance
- Vision insurance
About the company
Rice Park Capital Management LP (āRice Parkā) is a fast-growing, Minneapolis-based, alternative investment firm with deep roots in real estate and structured products. Rice Park provides capital, industry expertise, and support to its partners in complex situations through its venture capital, fixed income, and real estate investment verticals. Currently, Rice Park manages three distinct but complimentary strategies in the U.S. real estate and mortgage sectors:
- Ventures Strategies: Investments in early to mid-stage companies operating in the real estate and mortgage sectors where Rice Park can play an active role in creating value for its investors and entrepreneur partners.
- Mortgage Servicing Rights (āMSRā): Investments in performing conventional MSR where Rice Park can leverage its significant investment and operational experience to create reliable, compelling yields for investors.
- Credit Strategies: Investments in residential transition loans (āRTLsā) and other mortgage and real estate assets focused on dislocated, distressed, and mispriced markets where active asset management strategies can generate alpha.
Rice Park is looking for the right individual to join our team!
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role ā technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
The Overflow: Security and Privacy
Data Analyst Salary in the UK