Ohio State University logo

Senior Security Analyst

Ohio State University

Hybrid
Columbus Campus
Full-time
Senior
6+ yrs
$103k–$135kPosted 8m ago

Real job — pulled straight from Ohio State University’s careers page · Verified September 18, 2026 · No reposts.

Job description

Ohio State University is hiring a Senior Security Analyst — a full-time, based in Columbus Campus role ($103k–$135k). Apply directly on Ohio State University's careers page below.

Senior Security Analyst

Location: Columbus Campus

Remote Type: Hybrid

Time Type: Full time

Job Description

Screen reader users may encounter difficulty with this site. For assistance with applying, please contact hr-accessibleapplication@osu.edu. If you have questions while submitting an application, please review these frequently asked questions.

Current Employees and Students:

If you are currently employed or enrolled as a student at The Ohio State University, please log in to Workday to use the internal application process.

Welcome to The Ohio State University's career site. We invite you to apply to positions of interest. In order to ensure your application is complete, you must complete the following:

  • Ensure you have all necessary documents available when starting the application process. You can review the additional job description section on postings for documents that may be required.

  • Prior to submitting your application, please review and update (if necessary) the information in your candidate profile as it will transfer to your application. 

Job Title:

Senior Security Analyst

Department:

OTDI | Governance and Risk Management

Senior Security Analyst Position Summary

The Senior Security Analyst is a high-impact, specialized position within The Ohio State University’s Office of Technology and Digital Innovation. This role is responsible for designing, managing, and evolving the comprehensive information security and privacy framework across the university and medical center. Operating with a high degree of autonomy, the Senior Security Analyst will apply advanced industry knowledge to solve highly complex problems, develop new risk models, establish precedents that safeguard the university's academic, research, and administrative environments, and lead technical focus groups to determine the applicability of industry standards to university business.

Key Responsibilities

• Own and operate the university’s Information Security and Privacy Control Requirements

(ISPCR), ensuring alignment with institutional goals.

• Map institutional policies and controls to industry standards and regulatory requirements,

such as NIST SP 800-53, NIST SP 800-171, CIS Benchmarks, HIPAA, FERPA, GLBA,

and PCI-DSS.CIS Controls, ISO/IEC 27001, SOC 2, HIPAA, FERPA, GLBA, PCI DSS,

or similar.

• Develop, refine, and implement new compliance practices, processes, maturity models,

and key performance metrics to measure framework effectiveness over time.

• Lead highly complex, large-scope risk assessment initiatives that have a significant and

long-term impact on the university’s risk posture.

• Scope, execute, and oversee Tier 1, Tier 2, and Tier 3 risk assessments, evaluating critical

campus infrastructure, cloud environments, third-party vendors, and research data

environments.

• Provide actionable, technically sound mitigation strategies to system owners, researchers,

and technical teams to remediate identified gaps.

• Provide guidance, mentorship, and technical oversight to less experienced colleagues

across the distributed university IT and security organizations.

• Convey difficult, highly complex, or sensitive risk information to diverse campus

stakeholders and leadership, from technical system administrators to non-technical

academic leadership.

• Facilitate productive dialogue and use advanced communication skills to persuade

others to adopt secure practices and consider alternative risk-treatment options.

Required Education & Experience

• Bachelor’s degree in information technology, cyber security, computer science, or a

related field (or equivalent professional experience).

• Minimum of 6 years of direct experience in information security governance, risk, and

compliance.• Full technology stack knowledge – broad understanding and ability to explain identity

and access management (IAM), server, networking, application development and

database concepts.

Preferred Education & Experience

• 8 to 12 years of relevant governance, risk, and compliance (GRC) experience, ideally

within a higher education, academic medical center, or highly decentralized corporate

environment.

• Advanced degree (master’s or equivalent) in a relevant technical or business field.

• Active professional certifications such as CISA, CRISC, CISM, CISSP, or equivalent

specialized GRC certifications.

• Deep specialization in NIST SP 800-53 and HIPAA Security/Privacy Rules. Thorough

understanding of how these controls apply to diverse IT environments (on-premises,

cloud, SaaS).

• Full technology stack experience – provides expert guidance to securely implement IAM,

server, networking, application development and database services.

Function: Information Technology

Subfunction: Information Security and Risk Management

Career Band: Individual Contributor - Specialized

Proposed Career Level: S4

Additional Information:

The salary range for this position is $103,000 -$134,500 and the offer for this position will be based on internal equity and the candidate's qualifications.

Function: Information Technology

Sub-function: Information Security and Risk Management

Career Band: Individual Contributor - Specialized

Career Level: S4

Location:

Mount Hall (0311)

Position Type:

Regular

Scheduled Hours:

40

Shift:

First Shift

Final candidates are subject to successful completion of a background check. A drug screen or physical may be required during the post offer process.

Thank you for your interest in positions at The Ohio State University and Wexner Medical Center. Once you have applied, the most updated information on the status of your application can be found by visiting the Candidate Home section of this site. Please view your submitted applications by logging in and reviewing your status. For answers to additional questions please review the frequently asked questions.

The university is an equal opportunity employer, including veterans and disability. 

Get Security Analyst jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
TSYS logo

TSYS

New

Information Security Assurance Analyst

Alpharetta, GA
✓ From careers page· 2h ago
New Fire Global logo

Senior Android System Engineer

Remote · Croatia, Remote
✓ From careers page· 3h ago
Vera Whole Health logo

Cyber Security Engineering and Administration Manager

$119k–$179kRemote · US-eligible
✓ From careers page· 3h ago
Future logo

Full-Stack Growth Engineer (Remote)

$200k–$230kRemote · US-eligible
✓ From careers page· 5h ago

Frequently asked questions

What is the salary for Senior Security Analyst at Ohio State University?

The estimated salary range for Senior Security Analyst at Ohio State University is $103,000 - $135,000 USD per year.

What skills are required for Senior Security Analyst at Ohio State University?

The required skills for Senior Security Analyst at Ohio State University include: HIPAA, PCI DSS, ISO 27001, SOC 2, IAM, CISA, CISM, CISSP.

What is the seniority level for Senior Security Analyst at Ohio State University?

Senior Security Analyst at Ohio State University is a Senior level position.

How do I apply for Senior Security Analyst at Ohio State University?

You can view the full description and apply for Senior Security Analyst at Ohio State University on EchoJobs: https://echojobs.io/job/ohio-state-university-senior-security-analyst-twnxh.