Hiring.Camp

IT Risk & Information Security Analyst

Main Princeton

·

Yesterday

Salary
$105k – $120k
Location
Princeton, NJ, US
Type
Full-time
Department
IT
Education
Bachelor
Closing date
Today
Source
iCIMS

Description

Overview

University Services at Princeton University is seeking an IT Risk & Information Security Analyst to help strengthen the security, privacy, resilience, and continuity of the systems and data that support a broad portfolio of campus services. This role leads and coordinates IT risk management, information security, data privacy, mission continuity, disaster recovery, incident response, and security awareness efforts across University Services. Reporting to the Senior Director of Information Technology for University Services, with a dotted line to the University Chief Information Security Officer, the analyst will work closely with University Services Information Technology (USIT); the Office of Information Technology (OIT), including the Information Security Office (ISO); departmental leaders; and operational partners to reduce risk and protect critical services.

 

The analyst will serve the IT risk and information security needs of the University Services Office of the Vice President, University Services Administration, and the seven operating departments within University Services. This is a highly collaborative role for someone who can bridge policy, risk, technical controls, operational realities, and user education. The successful candidate will bring sound judgment, practical security and privacy knowledge, strong communication skills, and the ability to turn risk findings into clear, actionable improvements.

 

A cover letter is required for full consideration. A full job description will be furnished prior to interview.  

Responsibilities

• Lead system and data security initiatives, including security architecture reviews, access audits, vulnerability management, remediation tracking and coordination, evidence collection, monitoring, reporting, and continuous risk reduction efforts to protect University Services systems and data and support compliance with university security standards and policies. • Support compliance with applicable regulations, standards, and University policies, including FERPA, GDPR, CCPA, PCI, and privacy-aware handling of sensitive and regulated data.• Conduct IT risk assessments, privacy reviews, and business impact analyses to identify threats, evaluate operational impacts, prioritize mitigation, and strengthen resilience.• Partner with USIT, ISO, OIT, and departmental teams on data classification, responsible data handling, retention, access management, endpoint protection, and secure system operations.• Perform or coordinate system and application security testing, vulnerability scanning, remediation follow-up, and related reporting using appropriate tools, dashboards, and automation.• Develop, maintain, and test mission continuity and disaster recovery plans for critical University Services functions, systems, applications, and data.• Serve as the primary University Services point of contact for security incidents, coordinating response, escalation, remediation, communication, post-incident review, and improvement activities.• Design and deliver security and data privacy awareness training for staff, translating policies, threats, and best practices into practical guidance for diverse audiences.• Prepare concise reports, metrics, briefings, and recommendations that help leaders understand risk, track progress, and make informed decisions.• Works on special projects as assigned.

Qualifications

ESSENTIAL QUALIFICATIONS• Bachelor's degree in Information Technology, Cybersecurity, or a related field.• 5+ years of relevant professional, hands-on experience in an IT risk management and/or information security role.• Experience with security incident response and management.• Familiarity with regulatory requirements and compliance standards.• Knowledge of data classification and management practices.• Knowledge of data privacy principles, privacy-aware data handling practices, and requirements related to sensitive and regulated data.• Proficiency in security testing tools and methodologies (e.g. vulnerability scanning, penetration testing, static and/or dynamic code analysis, etc.).• Experience using tools, automation technologies, dashboards, reporting platforms, or workflow systems to improve security operations, risk tracking, audit readiness, and remediation tracking, coordination, and follow-through.• Strong knowledge of security and privacy frameworks and best practices.• Ability to work collaboratively with cross-functional teams.• Strong communication and interpersonal skills.• Ability to foster and maintain positive and professional working relationships; ability to effectively handle interpersonal interactions at all levels and respond appropriately to conflicts and problems.• Ability to work with complex confidential information and/or issues using discretion and judgement.• Excellent written/oral communication skills in order to present findings to all levels of management.• Possess organizational skills to handle several projects simultaneously, accommodate shifting priorities, and meet deadlines. • Ability and drive to stay current with and report on the rapidly evolving risk and information security landscape.

 

PREFERRED QUALIFICATIONS• Relevant and active certifications such as CISSP, CISM, CISA, or Security+.• Professional experience in a higher education environment.• Experience with the Family Educational Rights and Privacy Act (FERPA)• Experience with the Payment Card Industry Data Security Standards (PCI DSS)• Experience with privacy, data governance, data classification, or responsible data use initiatives in a complex organization.• Experience developing scripts, integrations, reports, or automated workflows that reduce manual effort and improve risk, security, compliance, or privacy processes.• Experience training, developing, and improving others’ understanding of risk and information security.

 

________________________________

 

Princeton University is an Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity or expression, national origin, disability status, protected veteran status, or any other characteristic protected by law.

 

The University considers factors such as (but not limited to) scope and responsibilities of the position, candidate's qualifications, work experience, education/training, key skills, market, collective bargaining agreements as applicable, and organizational considerations when extending an offer. The posted salary range represents the University's good faith and reasonable estimate for a full-time position; salaries for part-time positions are pro-rated accordingly.

 

If the salary range on the posted position shows an hourly rate, this is the baseline; the actual hourly rate may be higher, depending on the position and factors listed above.

 

The University also offers a comprehensive benefit program to eligible employees. Please see this link for more information.

Standard Weekly Hours

36.25

Eligible for Overtime

No

Benefits Eligible

Yes

Probationary Period

180 days

Essential Services Personnel (see policy for detail)

No

Physical Capacity Exam Required

No

Valid Driver’s License Required

No

Experience Level

Mid-Senior Level

#LI-JJ1

Salary Range

$105,000 to $120,000

Skills

CybersecurityPenetration TestingRisk ManagementComplianceGDPRCISSP

Similar Jobs

30

Senior Specialist, IT Risk Management and Controls (Bangkok Based – Relocation Provided)

Agoda · Bangkok +1 · Onsite

Yesterday

IT Risk & Information Security Analyst

Hub Princeton · Princeton, NJ, US

Yesterday

Senior Manager, Operational Risk / IT Risk and Compliance

Rbc · 180 WELLINGTON ST W:TORONTO, Canada

3 days ago

IT Risk Analyst / Cybersecurity DevOps Engineer

Chevron · Makati City Chevron 6750 Office, Philippines

6 days ago

IT Risk Manager, IT Risk

Amazon

1 week ago

Senior IT Risk Analyst

Freseniusmedicalcare · PHL Shared Services Philippines - BGC Office · Hybrid

1 week ago

IT Risk Expert (1st line)

Rabobank · Utrecht Croeselaan 18, Netherlands · Hybrid

1 week ago

Cyber/IT Risk Supervising Examiner

Rb · New York, NY, United States of America · Onsite

1 week ago

IT Risk & Controls Analyst

Open Positions · UK - 135 Bishopsgate - London, United Kingdom

1 week ago

IT Risk Manager

Rabobank · Sydney - Darling Park, Australia · Hybrid

1 week ago

Consultant Senior Tech Risk & IT M&A (H/F)

MAZARS · Levallois-Perret, IDF, France · Hybrid

1 week ago

IT – Risk & Governance Specialist

Teamsystem · MILANO_P.ZZA LUIGI EINAUDI, Italy

2 weeks ago

Director, Cybersecurity and IT Risk Management

SourceAmerica · Vienna, VA

2 weeks ago

IT Risk Analyst

Ing · Manila (One Ayala Tower 2), Philippines

2 weeks ago

IN_Manager_ IT Risk– GCC–Advisory- Bangalore

Pwc · Bengaluru Millenia, India

2 weeks ago

Manager - IT Risk and Governance

Prudential · EIB | Kuala Lumpur - Menara Prudential 22/F (TRX), Malaysia

2 weeks ago

Senior IT Risk Analyst

Global Payments · GSC Vertis North, Philippines · Hybrid

2 weeks ago

IT Risk & Compliance Analyst 2

Symcor · 1 Robert Speck Pkwy, Mississauga, ON L4Z 2G5, Canada

2 weeks ago

IN-Specialist 3– IT Risk– GCC - Advisory- Bangalore

Pwc · Bengaluru Millenia, India

2 weeks ago

IT Risk Analyst

Hiwin · Huntley, IL

3 weeks ago

Team Lead-IT Risk

Ameriprise Financial · 11073 Ameriprise India - Noida - Embassy Oxygen Business Park +1 · Hybrid

3 weeks ago

PCI Compliance & IT Risk Management People Leader

Global Payments · GSC Vertis North, Philippines · Hybrid

3 weeks ago

Staff Engineer, ServiceNow IT Risk & Compliance

TJX · USA Home Office Framingham MA 770 Cochituate Rd, United States of America +2

3 weeks ago

IT Security Manager - Third-Party IT Risk Manager

Wk · USA - Riverwoods, IL, United States of America +4 · Hybrid

4 weeks ago

IT Risk and Security Compliance Specialist

Respond.io · Kuala Lumpur, MY

1 month ago

Manager - IT Risk Assurance

Pwc · Ho Chi Minh City, Vietnam +1

1 month ago

Associate - IT Risk Services

Pwc · Hanoi, Vietnam +1

1 month ago

IT Risk & Compliance Engineer (DevOps/Agile)

Ing · Katowice (Zabrska 19), Poland +1 · Hybrid

1 month ago

IT Risk & Compliance Engineer (DevOps/Agile)

Ing · Katowice (Zabrska 19), Poland +1 · Hybrid

1 month ago

Senior Analyst, IT Risk Analytics & Reporting (Global Security)

Rbc · 16 YORK ST:TORONTO, Canada

1 month ago