Business Operations Security Analyst
Listed on 2026-06-20
-
IT/Tech
Cybersecurity, Information Security, Data Security, IT Consultant
Job Location
15151 E Alameda Pkwy, Aurora, Colorado , City of Aurora, Colorado
Overview of Position / DepartmentThe Security Analyst will work within the ISO Engagement team and directly with city departments to evaluate information security and privacy risks across business processes and technology platforms. This role engages business leadership to design remediation strategies that support compliance with legal, policy, and security requirements. The position supports CORA and eDiscovery requests and will help shape the City’s data governance program.
PrimaryDuties & Responsibilities
- Evaluate and consult on security and privacy risks for departmental technology and business processes.
- Develop and maintain strong business relationships to support adoption of secure practices.
- Create and deliver security awareness training and educational content.
- Develop reporting, metrics, and quarterly business reviews with the City Attorney Office’s leadership and the CISO.
- Coordinate and support responses to open records requests and eDiscovery holds involving IT systems and records.
- Develop risk mitigation recommendations, security control requirements, and implementation strategies to address identified information security and privacy risks.
- Perform risk assessments on infrastructure, software, and business operations and track remediation activities.
- Collaborate with Security Operations, Program Management, Infrastructure, and Applications teams to support secure technology decisions.
- Translate legal and regulatory technical requirements into business language.
- Support deployment and governance of ISO platforms and co‑manage the IT Risk Management platform.
- Conduct research on emerging technologies and evaluate associated risks.
- Evaluate CAO policies, systems, and processes for security and privacy compliance.
- Assist in emergency response and incident investigations.
- Support development of CAO technology strategies using security‑by‑design principles.
- Participate in data governance program development including data discovery, labeling, and controls.
- Perform other duties as assigned to support IT and ISO program maturation.
Salary range: $37.44 – $46.80 per hour, commensurate with experience. Classified as VHBE (Variable Hour Benefit Eligible), allowing up to 40 hours per week. Eligible for Medical, Dental, and Vision benefits, paid time off, and 11 paid holidays. Additional benefits include the City Employees Retirement Plan, 457b plan, and wellness programs.
Final date to receive applicationsDeadline to submit applications:
June 24th, 2026.
- Education:
Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Computer Science, Public Administration, Business Administration, Legal Studies, or a related field; or an equivalent combination of education, training, and experience. - Experience:
2+ years supporting information security, privacy, data governance, risk management, legal compliance, or related functions, including regulatory compliance or legal practice. - Knowledge: information security, privacy, technology risk management principles; legal and regulatory requirements related to cybersecurity, CORA, and eDiscovery; data governance frameworks; municipal legal systems and CAO operations; security‑by‑design concepts and secure architecture principles;
Microsoft Purview and IT governance tools; industry standards and best practices. - Skills:
developing and delivering training; preparing business reviews and metrics dashboards; technical writing; stakeholder engagement; governance risk compliance platform usage; research and analysis of emerging technology risks. - Abilities: translate complex legal and technical requirements into business-friendly language; conduct comprehensive security and privacy risk assessments; establish and maintain effective working relationships; work independently; exercise sound judgment; manage competing priorities; champion secure practices; support incident response; plan and adapt to changing priorities.
- Public‑sector or municipal organization experience.
- Experience with Colorado Open Records Act…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).