Information Security Analyst II

Online Employment System•Chico, CA
•Onsite

About The Position

Under general supervision of the Information Security Officer (ISO), the Information Security Risk Analyst provides functional governance, risk and compliance (GRC) reporting, oversight and user support for critical campus systems, data repositories, business processes, critical vendors, and partner operations that impact information security and compliance. This position is responsible for ongoing cyber risk management assessment and reporting, IT risk assessment and reporting, critical vendor risk monitoring and serves as the point of contact for information security governance and compliance related issues. Additionally, this position is responsible for managing GRC tools, software, risk assessments, and providing necessary training for end users in support of state and/or locally mandated cyber and information security directives.

Requirements

  • Equivalent to a bachelor’s degree in a related field. Relevant education and/or experience which demonstrates acquired and successfully applied knowledge and abilities shown above may be substituted for the required education on a year-for-year basis.
  • Two years of relevant experience.

Nice To Haves

  • Master’s Degree in Cybersecurity, Computer Science, information systems, or other job-related field
  • Experience working in information technology in a higher education setting
  • Experience in Information Security or risk management related position
  • Experience related to compliance frameworks (PCI-DSS, GLBA, HIPAA, and FERPA)
  • Experience with PeopleSoft security
  • Experience using vulnerability management software
  • Experience using GRC tools to track/monitor/report cyber risk
  • Experience performing third-party IT vendor security risk reviews
  • Information Security Certification (CISA, CRISC, CISM, CISSP, CGRC, or comparable cybersecurity, GRC, audit, or compliance certification)

Responsibilities

  • Provides functional governance, risk and compliance (GRC) reporting, oversight and user support for critical campus systems, data repositories, business processes, critical vendors, and partner operations that impact information security and compliance.
  • Responsible for ongoing cyber risk management assessment and reporting.
  • Responsible for IT risk assessment and reporting.
  • Responsible for critical vendor risk monitoring.
  • Serves as the point of contact for information security governance and compliance related issues.
  • Responsible for managing GRC tools, software, risk assessments.
  • Provides necessary training for end users in support of state and/or locally mandated cyber and information security directives.

Benefits

  • Tuition fee waiver (if eligible)
  • Sick leave
  • Vacation
  • Health insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service