Senior Information Security Analyst
Listed on 2026-07-06
-
IT/Tech
Information Security, Cybersecurity, IT Business Analyst, Data Security
Title: Senior Information Security Analyst
Location: Beaverton, OR | Open to Remote, US
Duration: 7 months contract
WHO ARE WE LOOKING FOR?We're looking for a Senior Information Security Analyst to join the Information Risk Management (IRM) team within Corporate Information Security (CIS). This role will deliver against an information security and cybersecurity assessment plan integrated into a broader enterprise risk management program supported by executive management.
You will leverage your knowledge of security policies, standards, controls, and industry best practices to perform risk assessments of Nike systems and systems managed for Nike by vendors. Our ideal candidate has superb communication skills, strong analytical and problem‑solving ability, intellectual curiosity, and experience translating complex security risks for both technical and non‑technical audiences.
WHAT YOU WILL WORK ON?This role works with the Information Risk Management team to identify, assess, and elevate visibility to information security risks across Nike's technology landscape.
Key responsibilities include:
- Perform formal risk assessments on partner and vendor connections, evaluating vendor processes at the point of engagement with Nike.
- Ensure sufficient validation of data sharing arrangements and agreements to protect Nike's sensitive information.
- Confirm business objectives align with the type and volume of data used, maintaining a "need to know/use" mindset.
- Review third-party SOC reports and vendor security documentation as part of assessment activities.
- Help establish risk and remediation ownership for identified vendor-related risks and document findings in the Risk Register.
- Assess moderately complex platforms and systems against Nike security and configuration standards.
- Evaluate and process exceptions to information security policies and standards.
- Perform compliance control validation testing to determine the operating effectiveness of IT controls for scoped systems.
- Consult with technology units on IT general controls (ITGCs) and compliance matters.
- Champion information security policies, standards, controls, and processes so compliance requirements are addressed as part of business-as-usual operations.
- Identify, document, and elevate visibility to information risk where business direction creates potential exposure to employee, athlete, and product sensitive data streams.
- Identify and profile Nike systems and processes that require risk assessments; scope specific assessments accordingly.
- Perform detailed analysis of threats and vulnerabilities across information security domains including network security, asset security, security engineering, identity and access management, security operations, and software development security.
- Review key system configurations and complex IT infrastructures (e.g., cloud services).
- Communicate effectively through risk reports, presentations, and stakeholder interactions to drive remediation of identified risks.
- Support vendor risk management metrics, reporting, and master data stewardship to improve accuracy, timeliness, and completeness.
- Provide analysis and insights into data supporting the effectiveness of technical and process-based cybersecurity controls.
- Collaborate on process improvements for data retrieval, analysis, and risk assessment intake.
- Contribute to IRM team projects and strategic initiatives as assigned, including documentation in Service Now (SNOW) and Box.
- Support the risk analysis intake process and participate in daily standups and weekly process meetings.
- Execute targeted internal and external (vendor) risk assessments in support of IRM strategy, following established team processes and enablers.
- Be proactive in anticipating next steps in the risk assessment process and take action accordingly.
- Collaborate with team members on assessment approach, scoping, documentation, and issue presentation activities.
- Serve as an information security and CIS ambassador to Nike lines of business and management.
- Provide…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).