Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Ovative Group

Lead Security Analyst

Ovative Group

Security Analyst managing governance, risk, and compliance operations. Supporting AI governance and overseeing vendor assessments for operations in a full-funnel media firm.

Posted 8/1/2026full-timeMinneapolis • Illinois, Minnesota • 🇺🇸 United StatesSenior💰 $90,000 - $132,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in security and compliance operations, including SOC 2, NIST CSF, and ISO 27001 frameworks, while effectively managing vendor assessments and data privacy regulations such as CCPA and GDPR. Proficient in utilizing generative AI tools for risk assessments and governance, with strong organizational skills to handle multiple workstreams.

Highest-signal resume keywords
SOC 2 Compliance OperationsVendor Security AssessmentsData Privacy Regulations (CCPA, GDPR)Generative AI Tools ExperienceSecurity Awareness Training Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security AnalystGRCIT AuditCompliance FrameworksRisk AssessmentVendor Risk TrackingControl MonitoringEvidence CollectionThreat ModelingData Inventory and Mapping
Soft Skills
Excellent Written CommunicationStrong OrganizationAttention to DetailStakeholder CollaborationAbility to Manage Parallel Workstreams
Tools & Technologies
AI ToolsSecurity Awareness Training ProgramsRisk Methodology FrameworksAudit Support ToolsContract Management Systems
Industry Keywords
Security QuestionnairesPolicy Lifecycle ManagementRisk Register MaintenanceData Subject Request SupportSubprocessor Tracking

About the role

Key responsibilities & impact
  • Own client security questionnaires end to end; build and maintain a reusable answer library to make each response faster and more consistent
  • Conduct vendor security assessments for new vendors and renewals; maintain ongoing vendor risk tracking
  • Run SOC 2 compliance operations, including evidence collection, control monitoring, and audit support
  • Maintain the risk register: track remediation owners and progress, and prepare quarterly risk reviews
  • Drive the policy lifecycle: annual reviews, redline recommendations, and exception tracking
  • Support review of client contractual security obligations in partnership with our contracts administration team
  • Support data privacy compliance operations (CCPA, GDPR, etc.), including data inventory and mapping, subprocessor tracking, and data subject request support
  • Operate the AI tool and vendor intake process: triage requests, run security and risk reviews, and document decisions
  • Conduct AI risk assessments using our risk methodology — threat modeling, control analysis, and risk scenarios — and help mature it into a repeatable framework
  • Build and maintain our AI inventory of approved tools, agents, and connectors; monitor for unapproved AI use
  • Maintain AI usage policies and standards, and manage the exception process
  • Support access reviews for AI agents and connectors, including what data non-human identities can reach
  • Manage the security awareness training program, including content updates, completion tracking, and new-hire onboarding
  • Coordinate and execute periodic user access reviews and validate offboarding completion

Requirements

What you’ll need
  • 2–5 years of experience in a security analyst, GRC, IT audit, compliance, or similar role
  • Two-year or four-year degree in information security, information technology, business, or related field; or 3+ years of equivalent experience
  • Working knowledge of security and compliance frameworks such as SOC 2, NIST CSF, or ISO 27001
  • Experience responding to security questionnaires, conducting vendor assessments, or supporting audits
  • Familiarity with data privacy regulations (CCPA, GDPR, etc.)
  • Hands-on experience using generative AI tools, and a strong interest in AI governance and safe adoption
  • Excellent written communication
  • Strong organization and attention to detail, with the ability to manage many parallel workstreams
  • Ability to work effectively with technical and non-technical stakeholders across the business

Benefits

Comp & perks
  • Strong, competitive, holistic benefits
  • Health insurance options, inclusive of same sex partners
  • 401k match program
  • Generous paid vacation policy
  • Family formation benefits including reimbursement options for fertility, pregnancy, and parenting needs
  • Monthly stipend for your mobile phone and data plan
  • Corporate events and team collaboration opportunities
  • Sabbatical program
  • Charitable giving via our time and a financial match program