Senior Security Analyst

The Ohio State University
Columbus, OH, United States
26 days ago
Apply on osu.wd1.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$103,000.0 - $134,500.0
Working hours
Regular working hours

Tech stack

Software as a Service Cyber Security Database Theory Identity and Access Management Information Security Management PCI Data Security Standards Software Engineering Cloud Platform System Information Technology 3-tier Architectures CIS Benchmarks Service Stack

Job description

The Senior Security Analyst is a high-impact, specialized position within The Ohio State University’s Office of Technology and Digital Innovation. This role is responsible for designing, managing, and evolving the comprehensive information security and privacy framework across the university and medical center. Operating with a high degree of autonomy, the Senior Security Analyst will apply advanced industry knowledge to solve highly complex problems, develop new risk models, establish precedents that safeguard the university’s academic, research, and administrative environments, and lead technical focus groups to determine the applicability of industry standards to university business., * Own and operate the university’s Information Security and Privacy Control Requirements

(ISPCR), ensuring alignment with institutional goals.

  • Map institutional policies and controls to industry standards and regulatory requirements,

such as NIST SP 800-53, NIST SP 800-171, CIS Benchmarks, HIPAA, FERPA, GLBA,

and PCI-DSS.CIS Controls, ISO/IEC 27001, SOC 2, HIPAA, FERPA, GLBA, PCI DSS,

or similar.

  • Develop, refine, and implement new compliance practices, processes, maturity models,

and key performance metrics to measure framework effectiveness over time.

  • Lead highly complex, large-scope risk assessment initiatives that have a significant and

long-term impact on the university’s risk posture.

  • Scope, execute, and oversee Tier 1, Tier 2, and Tier 3 risk assessments, evaluating critical

campus infrastructure, cloud environments, third-party vendors, and research data

environments.

  • Provide actionable, technically sound mitigation strategies to system owners, researchers,

and technical teams to remediate identified gaps.

  • Provide guidance, mentorship, and technical oversight to less experienced colleagues

across the distributed university IT and security organizations.

  • Convey difficult, highly complex, or sensitive risk information to diverse campus

stakeholders and leadership, from technical system administrators to non-technical

academic leadership.

  • Facilitate productive dialogue and use advanced communication skills to persuade

Requirements

  • Bachelor’s degree in information technology, cyber security, computer science, or a

related field (or equivalent professional experience).

  • Minimum of 6 years of direct experience in information security governance, risk, and

compliance.* Full technology stack knowledge - broad understanding and ability to explain identity

and access management (IAM), server, networking, application development and

database concepts.

Preferred Education & Experience

  • 8 to 12 years of relevant governance, risk, and compliance (GRC) experience, ideally

within a higher education, academic medical center, or highly decentralized corporate

environment.

  • Advanced degree (master’s or equivalent) in a relevant technical or business field.

  • Active professional certifications such as CISA, CRISC, CISM, CISSP, or equivalent

specialized GRC certifications.

  • Deep specialization in NIST SP 800-53 and HIPAA Security/Privacy Rules. Thorough

understanding of how these controls apply to diverse IT environments (on-premises,

cloud, SaaS).

  • Full technology stack experience - provides expert guidance to securely implement IAM,

server, networking, application development and database services.

Benefits & conditions

The salary range for this position is $103,000 -$134,500 and the offer for this position will be based on internal equity and the candidate’s qualifications.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on osu.wd1.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:47 min

Solving the knowledge deficit in large language models

Alejandro Saucedo Alejandro Saucedo +3 · World Congress 2024

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all