Senior Security Analyst
osu.wd1.myworkdayjobs.com
Job at a glance
Screen reader users may encounter difficulty with this site. For assistance with applying, please contact hr-accessibleapplication@osu.edu . If you have questions while submitting an application, please review these frequently asked questions . Current Employees and Students: If you are currently employed or enrolled as a student at The Ohio State University, please l og in to Workday to use the internal application process.
Welcome to The Ohio State University's career site. We invite you to apply to positions of interest. In order to ensure your application is complete, you must complete the following: Ensure you have all necessary documents available when starting the application process. You can review the additional job description section on postings for documents that may be required. Prior to submitting your application, please review and update (if necessary) the information in your candidate profile as it will transfer to your application.
Job Title: Senior Security Analyst Department: OTDI | Governance and Risk Management Senior Security Analyst Position Summary The Senior Security Analyst is a high-impact, specialized position within The Ohio State University’s Office of Technology and Digital Innovation. This role is responsible for designing, managing, and evolving the comprehensive information security and privacy framework across the university and medical center.
Operating with a high degree of autonomy, the Senior Security Analyst will apply advanced industry knowledge to solve highly complex problems, develop new risk models, establish precedents that safeguard the university's academic, research, and administrative environments, and lead technical focus groups to determine the applicability of industry standards to university business. Key Responsibilities • Own and operate the university’s Information Security and Privacy Control Requirements (ISPCR), ensuring alignment with institutional goals.
• Map institutional policies and controls to industry standards and regulatory requirements, such as NIST SP 800-53, NIST SP 800-171, CIS Benchmarks, HIPAA, FERPA, GLBA, and PCI-DSS.CIS Controls, ISO/IEC 27001, SOC 2, HIPAA, FERPA, GLBA, PCI DSS, or similar. • Develop, refine, and implement new compliance practices, processes, maturity models, and key performance metrics to measure framework effectiveness over time.
• Lead highly complex, large-scope risk assessment initiatives that have a significant and long-term impact on the university’s risk posture. • Scope, execute, and oversee Tier 1, Tier 2, and Tier 3 risk assessments, evaluating critical campus infrastructure, cloud environments, third-party vendors, and research data environments. • Provide actionable, technically sound mitigation strategies to system owners, researchers, and technical teams to remediate identified gaps.
• Provide guidance, mentorship, and technical oversight to less experienced colleagues across the distributed university IT and security organizations. • Convey difficult, highly complex, or sensitive risk information to diverse campus stakeholders and leadership, from technical system administrators to non-technical academic leadership. • Facilitate productive dialogue and use advanced communication skills to persuade others to adopt secure practices and consider alternative risk-treatment options.
Required Education & Experience • Bachelor’s degree in information technology, cyber security, computer science, or a related field (or equivalent professional experience). • Minimum of 6 years of direct experience in information security governance, risk, and compliance. • Full technology stack knowledge – broad understanding and ability to explain identity and access management (IAM), server, networking, application development and database concepts.
Preferred Education & Experience • 8 to 12 years of relevant governance, risk, and compliance (GRC) experience, ideally within a higher education, academic medical cente