CyberSecurity Senior Analyst

Nelnet ServicingCentennial, CO
Hybrid

About The Position

Nelnet is a diversified and innovative company committed to enriching lives through the power of service. This role leads information security initiatives to minimize risk and maximize compliance. The position involves facilitating risk assessments, managing audit fulfillment and remediation, governing business data, monitoring security controls, leading special security initiatives, and coaching to improve information security awareness and standards. The analyst will plan, coordinate, perform, and report on work assignments based on risk assessments and priorities set by leadership.

Requirements

  • Bachelor’s degree in Information Technology, or related field required.
  • Four to six years risk management or closely related field.
  • Proficient in the NIST SP 800 53 rev 5 and NIST RMF risk management frameworks
  • Experience with Governance, Risk, and Compliance (GRC) tools (Service Now, Archer, SAP, Logic Gate, other)
  • Exposure and working knowledge of Artificial Intelligence toolsets and applying them to cybersecurity risk management use cases
  • Strong research and problem-solving skills, with the ability to independently investigate and resolve complex, time-sensitive issues
  • Excellent oral, written, negotiation and presentations skills
  • Ability to communicate complex concepts
  • Self-directed and able to work independently
  • Demonstrate aptitude for learning new technologies
  • Ability to prioritize and manage multiple concurrent projects, and work within critical timelines
  • Strong leadership, interpersonal, and organizational skills
  • Ability to work within a team environment, skilled at interacting with internal and external personnel.
  • High degree of literacy in information system processes, PC’s, end-user computing controls, website controls, systems development, infrastructure management, and information security software.
  • Candidates must already be authorized to work in the United States without the need for current or future sponsorship.

Nice To Haves

  • Certification in Risk Management, CISA, CISSP, CISM, GSEC, or other information security certifications preferred.

Responsibilities

  • Oversee information security risk management functions by leading initiatives with Information Technology, Corporate Security, Audit Services, Compliance, Operations and Operational Risk leadership and associates.
  • Coordinate with business unit stakeholders to align cybersecurity practices and priorities across diverse shared services functions, ensuring consistent risk posture enterprise-wide.
  • Align with business technology, security, vendor and audit professionals to facilitate risk assessments, respond to audits, examinations, and RFP’s, remediate risks, and improve Nelnet’s risk management program.
  • Work with leadership and associates to resolve issues, recommend cost savings, reduce exposure and implement internal controls to reduce risk.
  • Identify and research improvements in order to reduce risk, improve compliance with related rules and regulations or ensure efficient utilization of company resources.
  • Recommend improvements, develop tactical plans, establish measurable goals, and achieve results.
  • Monitor and validate adherence to information security controls and promote risk awareness.
  • Maintain knowledge of regulatory standards, contracts and best practices.
  • Demonstrate a commitment to teamwork and exhibit a positive professional image.
  • Actively participate as a senior team member contributing to the growth of IT Risk Management and Nelnet.
  • Produce after action reports that provide senior leadership with actionable information.
  • Review, assess and provide feedback of technical cybersecurity requirements for new and existing contracts.
  • Provide audit support activities for SOC (Type 1 or Type 2) engagements, including the systems, applications, and underlying infrastructure within the scope of the examination.
  • Assist with maturation and execution of PCI DSS compliance and testing program.
  • Serve as a cybersecurity subject matter resource across multiple shared services functions, ensuring security considerations are integrated into broader operational, risk and compliance initiatives.
  • Support additional cybersecurity initiatives and projects as they arise, adapting to evolving priorities within Nelnet environment.

Benefits

  • medical
  • dental
  • vision
  • HSA and FSA
  • generous earned time off
  • 401K/student loan repayment
  • life insurance & AD&D insurance
  • employee assistance program
  • employee stock purchase program
  • tuition reimbursement
  • performance-based incentive pay
  • short- and long-term disability
  • a robust wellness program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service