
Security Analyst (IT Risk)
Dublin, CA · HybridJobSeen 1 day agoSeen in employer's feed 1 day ago
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near Dublin, CA, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
The Security Risk Analyst at Ross Stores executes IT risk management processes, conducts risk assessments, manages third‑party risk, supports vendor selection, maintains metrics, policies, awareness programs, and monitors regulations, collaborating across IT and security teams.
Skills & qualifications
Skills
Qualifications
Full job description
GENERAL PURPOSE
The Security Risk Analyst is responsible for executing IT risk management processes within Ross. This includes performing risk assessments, tracking mitigation efforts and developing risk metrics and risk reports. This position is also responsible for executing security risk related projects and programs, such as monitoring DLP events, third-party risk assessments, updating security policies and procedures and executing security awareness programs.
ESSENTIAL FUNCTIONS
-
Performs risk assessments to identify current and future security vulnerabilities.
-
Performs Third Party risk assessment and related contracts agreements to ensure necessary security controls have been included as part of services and capabilities for the protection of organization assets
-
Provides support to IT during product and vendor selection process and provide subject matter expertise on Information security risk and compliance
-
Maintains related IT Risk Management metrics and reporting. Collaborates with IT Compliance Manager, Secure SDLC Manager, Information Security, and IT groups to gather and analyze metrics.
-
Maintains risk assessments related tools with the goal of improving efficiency, reducing costs, improving agility and optimizing information technology governance, risk, and controls management processes, while providing an overall view of the organization’s risk profile.
-
Maintains Information security policies, standards and procedures
-
Maintains information security awareness programs, regularly conducting exercise to educate employees of the information security and best practices.
-
Monitors current and proposed laws, regulations, industry standards, and ethical requirements related to information security and privacy.
ESSENTIAL FUNCTIONS (cont.)
COMPETENCIES
Building Effective Teams
Collaboration
Leading by Example
Communicates Effectively
Ensures Accountability & Execution
Manages Conflict
Business Acumen
Plans, Aligns & Prioritizes
Organizational Agility
QUALIFICATIONS & SPECIAL SKILLS REQUIRED
-
Minimum 3 years of Information Technology Security, at least 1 with large enterprise organizations
-
Strong understanding of security governance, compliance and risk management principles.
-
Working knowledge of UNIX and Windows
-
Firewalls, VPN, PKI, IPS
-
Oracle, MS SQL
-
Virtualization Security
-
Proficient in Microsoft Word, Excel, PowerPoint
-
Excellent analytical, organizational and communication skills
-
Strong Project Management skills
EDUCATION / CERTIFICATIONS
Required
- Bachelor’s degree or equivalent combination of education and relevant experience
Preferred
-
CISSP (Certified Information Systems Security Professional) Preferred
-
CRISC (Certified in Risk and Information Systems Control (CRISC) Preferred
-
CompTIA Security + Preferred
PHYSICAL REQUIREMENTS
Consistent timeliness and regular attendance
However, this role can perform duties effectively using a combination of in-office and remote work
Job requires ability to work in an office environment, primarily on a computer
Requires sitting, standing, walking, hearing, talking on the telephone, attending in-person meetings, typing, and working with paper/files, etc
This role requires regular in-office presence, including to engage in in-person team interaction, meetings and collaboration, client support, mentoring, coaching, and/or feedback
Vision requirements: Ability to see information in print and/or electronically
SUPERVISORY RESPONSIBILITIES
N/A
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Staff Technical Program Manager, Security + ITDiscord · CA · $248–279K/yrPosted 1w agoPosted 1w ago
Product Security EngineerSalesforce · Bellevue, WA · $117–177K/yrPosted 4 days agoPosted 4 days agoSecurity GRC EngineerCursor · San Francisco, CAPosted 1w agoPosted 1w ago
Security Engineer, Business Continuity & RiskBlock · CA · $180–270K/yrPosted 2 days agoPosted 2 days ago
Product Security Engineer, SeniorSalesforce · Bellevue, WA · $149–224K/yrPosted 4 days agoPosted 4 days ago
You've read the whole posting — now see how you match it.