Hiring.Camp

Lead Security Analyst

Ovative

·

Jul 31, 2026

Salary
$90k – $132k
Location
Minneapolis, United States of America · Chicago
Type
Full-time
Department
Security
Seniority
Lead
Experience
2+ years
Source
Workday

Description

About Ovative Group:

Ovative Group is an independent, full-funnel media, measurement, and creative firm. Leveraging our deep industry expertise, we help brands like Best Buy, Domino's, American Eagle, The Home Depot, Post, Disney, Tumi, Michael Kors, Boost Mobile, and UnitedHealth Group transform their media and measurement programs. The result? Profitable growth that speaks for itself.

 

At Ovative, we don't just track data, we redefine success. How do we do it? Our proprietary MarTech platform, EMRge helps businesses transform marketing into a driver of sustainable growth. Powered by Enterprise Marketing Return (EMR), our differentiated approach to holistic media buying, planning, and measurement, EMRge is the first MarTech platform to measure businesses holistically. We're all about raising the bar every day, and it shows. Our work has been recognized by organizations like Digiday, Google, Inc. 5000, USA Today, and Search Engine Land.

About the Role
Ovative Group is seeking a Security Analyst to join our growing Information Security team. Reporting to the Head of Information Security and Privacy, this role
owns the operational core of our governance, risk, and compliance program — client security questionnaires, vendor assessments, and SOC 2 operations — and builds out new capabilities in AI governance and enablement. The ideal candidate is a strong writer, highly organized, comfortable engaging both technical and non-technical stakeholders, and genuinely excited about helping a company adopt AI quickly and safely.

Responsibilities
Governance, Risk, and Compliance

  • Own client security questionnaires end to end; build and maintain a reusable answer library to make each response faster and more consistent
  • Conduct vendor security assessments for new vendors and renewals; maintain ongoing vendor risk tracking
  • Run SOC 2 compliance operations, including evidence collection, control monitoring, and audit support
  • Maintain the risk register: track remediation owners and progress, and prepare quarterly risk reviews
  • Drive the policy lifecycle: annual reviews, redline recommendations, and exception tracking
  • Support review of client contractual security obligations in partnership with our contracts administration team
  • Support data privacy compliance operations (CCPA, GDPR, etc.), including data inventory and mapping, subprocessor tracking, and data subject request support

AI Governance and Enablement

  • Operate the AI tool and vendor intake process: triage requests, run security and risk reviews, and document decisions
  • Conduct AI risk assessments using our risk methodology — threat modeling, control analysis, and risk scenarios — and help mature it into a repeatable framework
  • Build and maintain our AI inventory of approved tools, agents, and connectors; monitor for unapproved AI use
  • Maintain AI usage policies and standards, and manage the exception process
  • Support access reviews for AI agents and connectors, including what data non-human identities can reach
  • Deliver secure-AI enablement: training, office hours, and onboarding users to approved tools
  • Track the evolving AI regulatory and framework landscape (EU AI Act, NIST AI RMF, OWASP GenAI Security) and the AI governance sections appearing in client questionnaires

Security Awareness and Training

  • Manage the security awareness training program, including content updates, completion tracking, and new-hire onboarding
  • Run phishing simulation campaigns, reporting, and follow-up coaching
  • Own security communications and the intake channel for employee security questions

Identity and Access Governance

  • Coordinate and execute periodic user access reviews and validate offboarding completion
  • Review third-party application and OAuth grants across M365 and Google environments

Reporting and Security Operations Support

  • Build and maintain security metrics and dashboards covering operational trends, compliance posture, and training completion; support leadership reporting
  • Produce periodic threat intelligence digests for the team
  • Depending on experience and interest, support security alert triage, incident documentation, and tabletop exercise coordination
  • Support business continuity and disaster recovery plan maintenance and test coordination

Skills and Qualifications

  • Two-year or four-year degree in information security, information technology, business, or related field; or 3+ years of equivalent experience
  • 2–5 years of experience in a security analyst, GRC, IT audit, compliance, or similar role title and level will be commensurate with experience
  • Working knowledge of security and compliance frameworks such as SOC 2, NIST CSF, or ISO 27001
  • Experience responding to security questionnaires, conducting vendor assessments, or supporting audits
  • Familiarity with data privacy regulations (CCPA, GDPR, etc.)
  • Hands-on experience using generative AI tools, and a strong interest in AI governance and safe adoption
  • Excellent written communication — much of this work is turning technical reality into clear, accurate answers
  • Strong organization and attention to detail, with the ability to manage many parallel workstreams
  • Ability to work effectively with technical and non-technical stakeholders across the business

Preferred Qualifications

  • Certifications such as Security+, CISA, CRISC, or CIPP
  • Experience with compliance automation platforms (Vanta, Drata, or similar)
  • Familiarity with AI governance frameworks (NIST AI RMF, ISO/IEC 42001, OWASP GenAI Security)
  • Exposure to security operations tooling (SIEM, EDR) and alert triage
  • Experience with M365 and Google Workspace administration or security configuration
  • Basic scripting skills (Python or similar) for reporting and automation
  • Experience working with personal information or other regulated data
     

Pay Transparency
At Ovative, we offer a transparent view into three core components of your total
compensation package: Base Salary, Annual Bonus, and Benefits. The salary range for this position below is inclusive of an annual bonus. Actual offers are made with consideration for relevant experience and anticipated impact. Additional benefits information is provided below.

For our senior security analyst positions, our compensation ranges from $90,000 to $132,000, which is inclusive of a 20% bonus.

Benefits of Working at Ovative Group: 

We provide strong, competitive, holistic benefits that understand the importance of your life inside and out of work.  

Culture:  

Culture matters and we’ve been recognized as a Top Workplace for ten years running because of it. We demand trust and transparency from each other. We believe in doing the hard and complicated work others put off. We’re open in communication and floor plan. We’re flat – our interns sit next to VPs, our analysts work closely with senior leaders, and our CEO interacts with every single person daily. Put together, these elements help foster an environment where smart people can support each other in performing to their highest potential.  

Ovative is committed to fostering an inclusive environment where everyone can participate and thrive. We do not tolerate discrimination of any kind, including on the basis of race, sexual orientation, gender identity, or gender expression. Our policies reflect this commitment—for example, our medical leave benefits are inclusive of same-sex partners, ensuring equitable care and support for all families. 

Compensation and Insurance:  

We strive to hire and retain the best talent. Paying fair, competitive compensation, with a large bonus incentive, and phenomenal health insurance is an important part of this mix.  

We’re rewarded fairly and when the company performs well, we all benefit.  

  

Tangible amenities we enjoy:  

  • Access to all office spaces in MSP, NYC, and CHI  

  • Frequent, paid travel to our Minneapolis headquarters for company events, team events, and in-person collaboration with teams

  • Generous paid vacation policy  

  • 401k match program  

  • Top-notch health insurance options, inclusive of same sex partners 

  • Family formation benefits including reimbursement options for fertility, pregnancy, and parenting needs 

  • Monthly stipend for your mobile phone and data plan  

  • Sabbatical program  

  • Charitable giving via our time and a financial match program  

  • Shenanigan’s Day  

  

Working at Ovative won’t be easy, but if you like getting your hands dirty, driving results, and being surrounded by the best talent, it’ll be the most rewarding job you’ll ever have. If you think you can make us better, we want to hear from you!  

Skills

PythonSIEMSOCOAuthEMRComplianceSOC 2GDPRISO 27001

Similar Jobs

30

Lead Security Analyst

Lennar·Miami FL, US +1

2mo ago

Lead Security Analyst

2K·Austin, Texas

2mo ago

Lead Security Analyst

i3D.net·Rotterdam HQ·Hybrid

4mo ago

Lead Security Analyst

outsidecapital·ZA

4mo ago

Lead Security Analyst

Morningstar·Mumbai, India·Hybrid, Onsite

1y+ ago

Lead Security Metrics Analyst

Mastercard·O'Fallon, Missouri

3d ago

Lead Cyber Security Analyst

Hyland·Hyderabad, TG·Hybrid, Onsite

5d ago

Citi Security and Investigative Services - Intelligence Lead Analyst

citibank·New York, NY

1w ago

Citi Security and Investigative Services - Intelligence Lead Analyst

Citi Bank·388 GREENWICH STREET - TRADING, US·Hybrid

1w ago

Team Lead - Principal Security Detection & Response Analyst Team Lead, German Speaking

LevelBlue LLC·UK

1w ago

Lead Analyst, Information Security

Lowe's·Lowe's Charlotte Technology Hub 3505, US +1·Onsite

1w ago

Senior Network and Security Analyst / Lead

Lalamove·Hong Kong SAR·Onsite

2w ago

Lead Analyst, Third Party Security

Circle·U.S. - California, US·Remote

2w ago

Lead Analyst, Information Security (Risk and Governance)

Rxo·USNC-Charlot15, US·Onsite

2w ago

IT Vulnerability Management Lead / Senior Security Analyst

August Schell·Bethesda, MD·Hybrid, Onsite

3w ago

Enterprise Security Partner (Multiple Levels) - Senior Analyst / Lead / Senior Lead

Salesforce·New York - New York, US +2·Onsite

3w ago

Lead, Network Security Analyst

Pru·Wash, NJ

3w ago

Lead Information Security Analyst, ITC

Nike·INDIA TECHNOLOGY CENTER·Remote

3w ago

Team Lead - Principal Security Detection & Response Analyst Team Lead

LevelBlue LLC·Poland

1mo ago

Lead Analyst, Security Strategy & Assurance

Outsystems·PT - Remote, Portugal·Remote

1mo ago

Lead Analyst, Digital Security

AIA Careers·MY-Putrajaya, Malaysia

1mo ago

Lead Security Analyst (DLP/DSPM)

Gartner·Irving - 6011 Connection, US +1

1mo ago

Lead Cyber Security Analyst

Staples Canada·Framingham, MA·Onsite

1mo ago

Team Lead - Security Analyst

Outsystems·IN - Remote, India·Remote

2mo ago

Lead Cyber Security Analyst

Uw·Seattle, Non-Campus·Remote

2mo ago

Lead Product Analyst - Security Platform

WISE·London, UK

2mo ago

Lead Analyst, Cyber Security Compliance

Vst·Sierra Office, US

2mo ago

Lead Analyst, Cyber Security Compliance

Vst·Sierra Office, US

2mo ago

Lead Analyst, Cyber Security Compliance

VST·Sierra Office, US

2mo ago

Lead Information Security Analyst (Individual Contributor)

Applied Materials·Bengaluru, KA

2mo ago