×
Register Here to Apply for Jobs or Post Jobs. X

Lead Security Analyst

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: Ovative Group
Full Time position
Listed on 2026-08-03
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity
Salary/Wage Range or Industry Benchmark: 90000 - 132000 USD Yearly USD 90000.00 132000.00 YEAR
Job Description & How to Apply Below

About Ovative Group

Ovative Group is an independent, full-funnel media, measurement, and creative firm. Leveraging our deep industry expertise, we help brands like Best Buy, Domino's, American Eagle, The Home Depot, Post, Disney, Tumi, Michael Kors, Boost Mobile, and United Health Group transform their media and measurement programs. The result? Profitable growth that speaks for itself.

About Ovative Group

Ovative Group is an independent, full-funnel media, measurement, and creative firm. Leveraging our deep industry expertise, we help brands like Best Buy, Domino's, American Eagle, The Home Depot, Post, Disney, Tumi, Michael Kors, Boost Mobile, and United Health Group transform their media and measurement programs. The result? Profitable growth that speaks for itself.

At Ovative, we don't just track data, we redefine success. How do we do it? Our proprietary Mar Tech platform, EMRge helps businesses transform marketing into a driver of sustainable growth. Powered by Enterprise Marketing Return (EMR), our differentiated approach to holistic media buying, planning, and measurement, EMRge is the first Mar Tech platform to measure businesses holistically. We're all about raising the bar every day, and it shows.

Our work has been recognized by organizations like Digiday, Google, Inc. 5000, USA Today, and Search Engine Land.

About

The Role

Ovative Group is seeking a Security Analyst to join our growing Information Security team. Reporting to the Head of Information Security and Privacy, this role owns the operational core of our governance, risk, and compliance program — client security questionnaires, vendor assessments, and SOC 2 operations — and builds out new capabilities in AI governance and enablement. The ideal candidate is a strong writer, highly organized, comfortable engaging both technical and non-technical stakeholders, and genuinely excited about helping a company adopt AI quickly and safely.

Responsibilities

Governance, Risk, and Compliance
  • Own client security questionnaires end to end; build and maintain a reusable answer library to make each response faster and more consistent
  • Conduct vendor security assessments for new vendors and renewals; maintain ongoing vendor risk tracking
  • Run SOC 2 compliance operations, including evidence collection, control monitoring, and audit support
  • Maintain the risk register: track remediation owners and progress, and prepare quarterly risk reviews
  • Drive the policy lifecycle: annual reviews, redline recommendations, and exception tracking
  • Support review of client contractual security obligations in partnership with our contracts administration team
  • Support data privacy compliance operations (CCPA, GDPR, etc.), including data inventory and mapping, subprocessor tracking, and data subject request support
AI Governance and Enablement
  • Operate the AI tool and vendor intake process: triage requests, run security and risk reviews, and document decisions
  • Conduct AI risk assessments using our risk methodology — threat modeling, control analysis, and risk scenarios — and help mature it into a repeatable framework
  • Build and maintain our AI inventory of approved tools, agents, and connectors; monitor for unapproved AI use
  • Maintain AI usage policies and standards, and manage the exception process
  • Support access reviews for AI agents and connectors, including what data non-human identities can reach
  • Deliver secure-AI enablement: training, office hours, and onboarding users to approved tools
  • Track the evolving AI regulatory and framework landscape (EU AI Act, NIST AI RMF, OWASP GenAI Security) and the AI governance sections appearing in client questionnaires
Security Awareness and Training
  • Manage the security awareness training program, including content updates, completion tracking, and new-hire onboarding
  • Run phishing simulation campaigns, reporting, and follow-up coaching
  • Own security communications and the intake channel for employee security questions
Identity and Access Governance
  • Coordinate and execute periodic user access reviews and validate offboarding completion
  • Review third-party application and OAuth grants across M365 and Google environments
Reporting and Security Operations…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary