| Location | West Lafayette, IN |
Req Id: 43207
Job Title: Lead IT Security Risk Analyst
City: REMOTE
Job Description:
Job Summary
The IT Security Risk Analyst is a recognized subject matter expert under limited oversight from their supervisor that provides information security risk assessment and compliance consulting services that contribute to a comprehensive information security risk management program. As a primary responsibility, this position provides Purdue IT International Organization for Standardization (ISO) related certification and Business Continuity/Disaster Recovery (BC/DR) subject matter expertise (SME) to the university. This involves a combination of leading, coordinating, and executing programs associated with SME.
The position also leads the execution of security and compliance (e.g., HIPAA, FERPA, GLBA, PCI, and other relevant regulations or standards) risk assessments as required by the University and as requested to improve information security posture. This position provides consulting on appropriate administrative, technical, and physical security controls for implementation to address security and compliance requirements. This position includes analyzing and interpreting information to document findings that are presented to management and technical staff. The position provides awareness training of security policies, tools, methodologies, and best practices. This position will monitor developments regarding laws and regulations, especially those associated with areas of SME, that could impact the organization and recommend measurable changes where necessary.
Join a team that safeguards Purdue's data, reputation, and mission by maintaining standards of security, regulatory compliance, and risk management.
About Us
Purdue Information Technology is the central information technology organization serving students, faculty and staff at Purdue University in West Lafayette, Purdue Fort Wayne and Purdue Northwest. Purdue IT is responsible for major operational systems, the campus wired network and one of the world's largest wireless networks. It also supports dozens of student computing labs as well as tens of thousands of desktop computers in classrooms, research laboratories and offices, and numerous petabytes of storage for business, educational and personal use across the Purdue University system.
In addition to supporting major academic systems, such as the Brightspace course management system, Purdue IT tests, implements and develops innovative learning and classroom technologies, along with big data analytics systems to make prime use of University data to improve learning and Purdue's operations through data-backed methodologies.
Purdue IT also supports an advanced research cyberinfrastructure across campus that includes multiple shared, TOP500-class supercomputing clusters for intensive computational needs; a state-of-the-art, multi-tiered research data storage array; and high-speed networks linking campus labs and computing resources and connecting the campus to national resources.
Take your #nextgiantleap with us.
What Were Looking For
Education and Experience Required:
A Bachelors degree in relevant field, including Business, Computer Science, Engineering, Computer/Information Technology, or Information Security
Equivalent combination of education and/or experience may be accepted
At least six (6) years of progressive technical information security and/or IT compliance experience
Experience:
in performing information security risk and compliance assessments
working with structured management systems or regulatory frameworks (e.g., ISO, NIST)
participating in complex security initiatives in a large organization with varied teams and stakeholders
contributing to and presenting security awareness information
Preferred
Skills Required:
Additional Information:
Who We Are
Purdue is a community built on collaboration, with global perspectives, Boilermaker pride and endless opportunity to live, learn and grow. Join us and contribute to our culture.
Apply now
Posting Start Date: 7/30/26