IT Security Analyst II
Grafton, OH - USA
Job Summary
Position: IT Security Analyst II
Location: Grafton Wisconsin
Remote Type: Hybrid
Reports To: Senior Manager Cybersecurity Compliance Data Privacy & AI Governance
We areseekinga motivated and detail-oriented IT Security Analyst II to support the organizationsAIgovernanceIT compliance andsecurity and third-party risk management programs. This mid-level role will help translate security privacy regulatory contractual andAI governancerequirements into practical controlsincludingrisk assessmentsevidencecollectionand remediation plans. The analyst will partnerwith ITinfrastructure PMO Legal Privacy Procurement business stakeholders and third-party vendors to strengthen the organizations security posture improve audit readiness and support responsible and secure adoption of AI-enabled technologies.
Key Responsibilities
IT Security Complianceand Governance
Support day-to-dayoperationof the IT security compliance program including control documentation evidence collection audit readiness and remediation tracking.
Assistwith control mappings and compliance activities across applicable frameworks standards laws and contractual requirements such as NISTCMMC SOC 2 data protection requirements and internal policies.
Partner with security IT privacy legal and business stakeholders to interpret compliance requirements and translate them into actionable control activities.
Maintain compliance records control narratives risk registers policies procedures and supporting documentation.
Track compliance gaps audit findings exceptions risks and remediation plans to ensuretimelyclosure andappropriate escalation.
AI Security and Responsible AI Governance
Research and keep apprised for latest updatesinAI trends and AI Security.
Support security and governance reviews for AI-enabled tools platforms models and use cases to help ensure responsible compliant and secure adoption.
AssistinmaintainingAI security documentation including inventories risk assessments control evidence usage guidelines data handling requirements andapprovalrecords.
Evaluate AI-related risks such as sensitive data exposure unauthorized use third-party AI dependencies model access controls prompt and output handling and operational misuse.
Collaborate with security privacy legal data product and technology teams to assess AI use cases against internal policies and emerging AI governance expectations.
Monitor AI security and governance findings and coordinate remediation activities with accountable owners.
Third-Party Risk Management
Support the third-party risk management lifecycle including vendor intake inherent risk reviews due diligence questionnaires security assessments reassessments and offboarding activities.
Review supplier security documentation certifications audit reports data protection materials and responses to security questionnaires toidentifyrisks and control gaps.
Assist with vendor risk scoring issue tracking exception documentation and remediation follow-up to ensure third-party risks are appropriately managed.
Partner with Procurement Legal Privacy Security IT and business owners to support contract reviews data protection requirements and security obligations.
Pay special attention to third-party AI tools and services including reviewing AI-related data handling access controlssub processors model usage and compliance requirements.
Risk Reporting Process Improvement and Stakeholder Support
Prepare clearaccuratereports dashboards and summaries that communicate compliance status AI security risks third-party risk posture remediation progress and key trends.
Support internal and external audits by coordinating evidence requestsvalidatingcontrol implementation and tracking follow-up actions.
Contribute to continuous improvement of GRC processes security workflows vendor review procedures AI governance practices and reporting standards.
Assistwith security awareness policy communications and guidance for business teams related to compliance AI security and third-party risk expectations.
Maintain awareness of cybersecurity compliance AI governance privacy and third-party risk trends and recommend practical improvements to the program.
Qualifications
Associates Degree (or equivalent experience) with 3-4 years of relevant experience in cybersecurity IT audit IT security compliance governance risk management third-party risk management privacy ora relatedfunction required.
Bachelors Degree preferred.
Working knowledge of cybersecurity governance compliance and risk management concepts including security control frameworks and audit readiness practices.
Familiarity with one or more frameworks or standards such as NIST ISO 27001 SOC 2 CIS Controls PCI DSS or similar control environments.NIST 800-171 or CMMC knowledge is a plus.
Exposure to AI security responsible AI governance data protection model or tool risk assessments or emerging AI regulatory requirements preferred.
Experience supporting third-party risk assessments vendor security reviews security questionnaires contract security reviews or supplier remediation tracking preferred.
Ability to collect organizevalidate and document audit evidence and compliance artifacts with strong attention to detail.
Strong analytical problem-solving written communication and stakeholder-management skills.
Ability to work collaboratively across technical and non-technical teams and communicate risk in clear business-oriented language.
Relevant certifications such as SecurityCySA CISA CRISC CGRC CISSP Associate ISO 27001 or other security audit risk or compliance certifications preferred.
NOT OFFERING SPONSORSHIP:
Candidates must be eligible to work in the United States without requiring company sponsorship to obtain or keep U.S. work authorization.
#LI-Hybrid #LI-AB-1
- Medical Dental Vision and Prescription Drug Coverage
- Spending accounts (HSA Health Care FSA and Dependent Care FSA)
- Paid Time Off and Holidays
- 401k Retirement Plan with Matching Employer Contributions
- Life and Accidental Death & Dismemberment (AD&D) Insurance
- Paid Leaves
- Tuition Assistance
About Regal Rexnord
Regal Rexnord is a publicly held global industrial manufacturer with 30000 associates around the world who help create a better tomorrow by providing sustainable solutions that power transmit and control motion. The Companys electric motors and air moving subsystems provide the power to create motion. A portfolio of highly engineered power transmission components and subsystems efficiently transmits motion to power industrial applications. The Companys automation offering comprised of controls actuators drives and precision motors controls motion in applications ranging from factory automation to precision control in surgical tools.
The Companys end markets benefit from meaningful secular demand tailwinds and include factory automation food & beverage aerospace medical data center warehouse alternative energy residential and commercial buildings general industrial construction metals and mining and agriculture.
Regal Rexnord is comprised of three operating segments: Industrial Powertrain Solutions Power Efficiency Solutions and Automation & Motion Control. Regal Rexnord has offices and manufacturing sales and service facilities worldwide. For more information including a copy of our Sustainability Report visit .
Equal Employment Opportunity Statement
Regal Rexnord is an Equal Opportunity and Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race color religion sex/gender sexual orientation gender identity pregnancy age ancestry national origin genetic information marital status citizenship status (unless required by the applicable law or government contract) disability or protected veteran status or any other status or characteristic protected by law. Regal Rexnord is committed to a diverse and inclusive workforce. We are committed to building a team that represents diverse and inclusive backgrounds perspectives and skills. If youd like to view a copy of the companys affirmative action plan for protected veterans/individuals with disabilities or policy statement please email you have a disability and you believe you need a reasonable accommodation in order to search for a job opening or to submit an online application please e-mail
Required Experience:
IC
About Company
Regal Beloit and Rexnord Corporation merged in 2001 to create Regal Rexnord. Find out more about the brands that make up our power transmission portfolio.