IT Security Analyst II
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Work Model: Work Model: Youâll work in a hybrid model, onsite at your designated Regal Rexnord location at least 3 days per week (Monday-Thursday), with flexibility to work remotely up to 2 days, including Friday., IT Security Compliance and Governance
- Support day-to-day operation of the IT security compliance program, including control documentation, evidence collection, audit readiness, and remediation tracking.
- Assist with control mappings and compliance activities across applicable frameworks, standards, laws, and contractual requirements such as NIST, CMMC, SOC 2, data protection requirements, and internal policies.
- Partner with security, IT, privacy, legal, and business stakeholders to interpret compliance requirements and translate them into actionable control activities.
- Maintain compliance records, control narratives, risk registers, policies, procedures, and supporting documentation.
- Track compliance gaps, audit findings, exceptions, risks, and remediation plans to ensure timely closure and appropriate escalation.
AI Security and Responsible AI Governance
- Research and keep apprised for latest updates in AI trends and AI Security.
- Support security and governance reviews for AI-enabled tools, platforms, models, and use cases to help ensure responsible, compliant, and secure adoption.
- Assist in maintaining AI security documentation, including inventories, risk assessments, control evidence, usage guidelines, data handling requirements, and approval records.
- Evaluate AI-related risks such as sensitive data exposure, unauthorized use, third-party AI dependencies, model access controls, prompt and output handling, and operational misuse.
- Collaborate with security, privacy, legal, data, product, and technology teams to assess AI use cases against internal policies and emerging AI governance expectations.
- Monitor AI security and governance findings and coordinate remediation activities with accountable owners.
Third-Party Risk Management
- Support the third-party risk management lifecycle, including vendor intake, inherent risk reviews, due diligence questionnaires, security assessments, reassessments, and offboarding activities.
- Review supplier security documentation, certifications, audit reports, data protection materials, and responses to security questionnaires to identify risks and control gaps.
- Assist with vendor risk scoring, issue tracking, exception documentation, and remediation follow-up to ensure third-party risks are appropriately managed.
- Partner with Procurement, Legal, Privacy, Security, IT, and business owners to support contract reviews, data protection requirements, and security obligations.
- Pay special attention to third-party AI tools and services, including reviewing AI-related data handling, access controls, sub processors, model usage, and compliance requirements.
Risk Reporting, Process Improvement, and Stakeholder Support
- Prepare clear, accurate reports, dashboards, and summaries that communicate compliance status, AI security risks, third-party risk posture, remediation progress, and key trends.
- Support internal and external audits by coordinating evidence requests, validating control implementation, and tracking follow-up actions.
- Contribute to continuous improvement of GRC processes, security workflows, vendor review procedures, AI governance practices, and reporting standards.
- Assist with security awareness, policy communications, and guidance for business teams related to compliance, AI security, and third-party risk expectations.
- Maintain awareness of cybersecurity, compliance, AI governance, privacy, and third-party risk trends and recommend practical improvements to the program.
Requirements
We are seeking a motivated and detail-oriented IT Security Analyst II to support the organizationâs AI governance, IT compliance and security, and third-party risk management programs. This mid-level role will help translate security, privacy, regulatory, contractual, and AI governance requirements into practical controls including risk assessments, evidence collection and remediation plans. The analyst will partner with IT infrastructure, PMO, Legal, Privacy, Procurement, business stakeholders, and third-party vendors to strengthen the organizationâs security posture, improve audit readiness, and support responsible and secure adoption of AI-enabled technologies., * Associateâs Degree (or equivalent experience) with 3-4 years of relevant experience in cybersecurity, IT audit, IT security compliance, governance, risk management, third-party risk management, privacy, or a related function required.
- Bachelorâs Degree preferred.
- Working knowledge of cybersecurity governance, compliance, and risk management concepts, including security control frameworks and audit readiness practices.
- Familiarity with one or more frameworks or standards such as NIST, ISO 27001, SOC 2, CIS Controls, PCI DSS, or similar control environments. NIST 800-171 or CMMC knowledge is a plus.
- Exposure to AI security, responsible AI governance, data protection, model or tool risk assessments, or emerging AI regulatory requirements preferred.
- Experience supporting third-party risk assessments, vendor security reviews, security questionnaires, contract security reviews, or supplier remediation tracking preferred.
- Ability to collect, organize, validate, and document audit evidence and compliance artifacts with strong attention to detail.
- Strong analytical, problem-solving, written communication, and stakeholder-management skills.
- Ability to work collaboratively across technical and non-technical teams and communicate risk in clear, business-oriented language.
- Relevant certifications such as Security+, CySA+, CISA, CRISC, CGRC, CISSP Associate, ISO 27001, or other security, audit, risk, or compliance certifications preferred.
NOT OFFERING SPONSORSHIP:
Candidates must be eligible to work in the United States without requiring company sponsorship to obtain or keep U.S. work authorization.
Benefits & conditions
- Medical, Dental, Vision and Prescription Drug Coverage
- Spending accounts (HSA, Health Care FSA and Dependent Care FSA)
- Paid Time Off and Holidays
- 401k Retirement Plan with Matching Employer Contributions
- Life and Accidental Death & Dismemberment (AD&D) Insurance
- Paid Leaves
- Tuition Assistance
About the company
Regal Rexnord is a publicly held global industrial manufacturer with 30,000 associates around the world who help create a better tomorrow by providing sustainable solutions that power, transmit and control motion. The Companyâs electric motors and air moving subsystems provide the power to create motion. A portfolio of highly engineered power transmission components and subsystems efficiently transmits motion to power industrial applications. The Companyâs automation offering, comprised of controls, actuators, drives, and precision motors, controls motion in applications ranging from factory automation to precision control in surgical tools.
The Companyâs end markets benefit from meaningful secular demand tailwinds, and include factory automation, food & beverage, aerospace, medical, data center, warehouse, alternative energy, residential and commercial buildings, general industrial, construction, metals and mining, and agriculture.
Regal Rexnord is comprised of three operating segments: Industrial Powertrain Solutions, Power Efficiency Solutions, and Automation & Motion Control. Regal Rexnord has offices and manufacturing, sales and service facilities worldwide. For more information, including a copy of our Sustainability Report, visit RegalRexnord.com.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Industries Outside of AI Are Hiring The Most AI Experts?
Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production
Dev Digest 166: Sycophancy, Zip bombs and AI Native Development
Trustworthy AI Starts at Deployment: 5 Checks Before You Ship