Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Ovative Group

Lead Security Analyst

Ovative Group

. Own client security questionnaires end to end and maintain a reusable answer library .

Posted 9/30/2026full-timeUnited StatesSenior💰 $90,000 - $132,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in security compliance operations, including SOC 2, NIST CSF, and data privacy regulations such as CCPA and GDPR. Proficient in managing vendor security assessments, risk tracking, and AI governance while effectively communicating with both technical and non-technical stakeholders.

Highest-signal resume keywords
SOC 2 Compliance OperationsVendor Security AssessmentsData Privacy ComplianceGenerative AI Tools ExperienceSecurity+ Certification

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security Questionnaires ManagementRisk Register MaintenanceThreat ModelingControl MonitoringAudit SupportPhishing SimulationsSecurity Metrics DevelopmentPython ScriptingIncident DocumentationBusiness Continuity Planning
Soft Skills
Excellent Written CommunicationStrong OrganizationAttention to DetailStakeholder CollaborationAbility to Manage Parallel Workstreams
Tools & Technologies
VantaDrataM365 AdministrationGoogle Workspace SecuritySIEMEDR
Certifications & Qualifications
Security+CISACRISCCIPP
Industry Keywords
NIST AI RMFISO/IEC 42001OWASP GenAI SecurityGDPRCCPA

Tech Stack

Tools & technologies
Python

About the role

Key responsibilities & impact
  • Own client security questionnaires end to end and maintain a reusable answer library
  • Conduct vendor security assessments and maintain vendor risk tracking
  • Run SOC 2 compliance operations, including evidence collection, control monitoring, and audit support
  • Maintain the risk register and prepare quarterly risk reviews
  • Drive policy reviews, redline recommendations, and exception tracking
  • Support review of client contractual security obligations
  • Support data privacy compliance operations, including data inventory, mapping, subprocessor tracking, and data subject requests
  • Operate AI tool and vendor intake, including security and risk reviews and decision documentation
  • Conduct AI risk assessments using threat modeling, control analysis, and risk scenarios
  • Build and maintain an inventory of approved AI tools, agents, and connectors; monitor for unapproved AI use
  • Maintain AI usage policies and standards and manage exceptions
  • Support access reviews for AI agents and connectors
  • Deliver secure-AI training, office hours, and onboarding
  • Track AI regulatory and framework developments and AI governance requirements in client questionnaires
  • Manage security awareness training, content updates, completion tracking, and new-hire onboarding
  • Run phishing simulations, reporting, and follow-up coaching
  • Own security communications and the employee security-question intake channel
  • Coordinate periodic user access reviews and validate offboarding completion
  • Review third-party application and OAuth grants across M365 and Google environments
  • Build security metrics and dashboards and support leadership reporting
  • Produce periodic threat intelligence digests
  • Depending on experience and interest, support security alert triage, incident documentation, and tabletop exercises
  • Support business continuity and disaster recovery plan maintenance and test coordination

Requirements

What you’ll need
  • Two-year or four-year degree in information security, information technology, business, or related field; or 3+ years of equivalent experience
  • 2–5 years of experience in a security analyst, GRC, IT audit, compliance, or similar role; level commensurate with experience
  • Working knowledge of SOC 2, NIST CSF, or ISO 27001
  • Experience responding to security questionnaires, conducting vendor assessments, or supporting audits
  • Familiarity with CCPA, GDPR, and other data privacy regulations
  • Hands-on experience using generative AI tools and strong interest in AI governance and safe adoption
  • Excellent written communication
  • Strong organization and attention to detail; ability to manage many parallel workstreams
  • Ability to work effectively with technical and non-technical stakeholders
  • Applicants must be legally authorized to work in the United States for any employer on a full-time basis, without current or future need for visa sponsorship
  • Preferred: Security+, CISA, CRISC, or CIPP certifications
  • Preferred: Experience with Vanta, Drata, or similar compliance automation platforms
  • Preferred: Familiarity with NIST AI RMF, ISO/IEC 42001, or OWASP GenAI Security
  • Preferred: Exposure to SIEM, EDR, and alert triage
  • Preferred: M365 and Google Workspace administration or security configuration
  • Preferred: Basic Python or similar scripting skills
  • Preferred: Experience with personal information or other regulated data

Benefits

Comp & perks
  • Annual bonus program; stated compensation range includes a 20% bonus
  • Flexible work arrangement with office work on set days and remote work on other days
  • Access to office spaces in Minneapolis, New York City, and Chicago
  • Frequent, paid travel to the Minneapolis headquarters for company and team events and in-person collaboration
  • Generous paid vacation policy
  • 401(k) match program
  • Health insurance options, inclusive of same-sex partners
  • Family formation benefits, including reimbursement options for fertility, pregnancy, and parenting needs
  • Monthly stipend for mobile phone and data plan
  • Sabbatical program
  • Charitable giving through time and financial match program
  • Shenanigan’s Day