Information Security Analyst

University of Wisconsin MadisonMadison, WI
Hybrid

About The Position

The Risk Management and Compliance (RMC) team within the Office of Cybersecurity is looking for an experienced risk analyst to address the internal security review requests from UW-Madison campus partners. This could include new tools, services, platforms or departmental risk reviews to ensure the security of UW-Madison data at all levels – Public to Restricted (ePHI). This position will work collaboratively with our campus partners, UW-Madison service providers, and third-party vendors to assess risk and present these risks to campus stakeholders. Responsibilities include evaluating current system use and data classification as entered by the system owner, collaboration with the Office of Compliance on privacy risks and presentation of overall risk with opportunities to improve security prior to utilization. Information gathered to establish the data flow and scope of these requests will be entered by campus partners in an enterprise risk review tool (OneTrust). A successful individual will have information security expertise as well as project management, business analysis, solution implementation skills, the ability to communicate to technical, non-technical staff and university leadership. This position reports to the Office of Cybersecurity and serves as a campus technical expert and authority on information security risk analysis and compliance matters. As a trusted advisor and partner with UW-Madison campus partners, UW System integration teams, project managers and system owners, this position will focus on the most efficient and impactful way to review risk of existing tools and present opportunities for improving overall security. This position will also have specific responsibility to assist in the establishment and maintenance of an RMC project management tool to improve overall efficiency. Acquiring feedback from campus partners and liaisons is also required to make procedural adjustments to the service this team offers. The candidate selected for this position may perform a combination of on-site and remote work subject to an approved flexible work arrangement (FWA), which is reviewed and approved annually. Remote work requires successful candidates to possess their own high-speed internet and phone to perform the work on a university provided computer. Per University policy, transportation between home and assigned work location is not payable/reimbursable and will be at the expense of the employee. This position will primarily work remotely but may occasionally need to come to campus for scheduled meetings, retreats, or workshops. The Division of Information Technology (DoIT) is an exciting and dynamic work environment grounded in organizational principles that include family and personal life/work balance; an inclusive, respectful, and supportive work environment; professional development opportunities; innovation; and alignment with the campus's teaching, learning, and research missions. DoIT provides core IT infrastructure services to the university, develops and implements services for the university and in some cases, for the Universities of Wisconsin, plays a major role in managing the state-wide higher education network and regional networks.

Requirements

  • Established professional experience conducting risk assessments against recognized standards (NIST, COBIT or ISO) with minimal oversight.
  • Established professional experience working with security requirements within a healthcare, higher ed, or research organization.
  • Working knowledge of NIST, HIPAA, or PCI Data Security standards along with virtual environment, AI and cloud computing services and demonstrate professional certification in Information Security or IT Audits.
  • Experience executing project management skills including setting expectations, design review, threat modeling and risk profiling while working across a large, distributed organization that is representative of diverse IT and business communities.
  • Experience working independently to conduct technical investigations with diverse constituents, providing detailed written reports and presentations .
  • Experience communicating effectively to and accepting feedback from leadership, peers, technical teams and risk assessment customers (all campus levels).

Nice To Haves

  • Experience in assessing vendors as part of procurement and implementation stagess
  • Experience using standard industry applications to create or update current documents to meet compliance reporting requirements (i.e. office productivity software, project management software)
  • Expertise using vulnerability management tools to analyze discovered vulnerabilities against current configurations to determine the organizational risk.
  • Experience serving as both a lead and a contributing team member on projects
  • Knowledge of enterprise project management tools and skills to navigate them (Ie JIRA).

Responsibilities

  • Conducts vulnerability-scanning analysis, tests security controls, documents the results of risk assessments, and designs procedures to prevent future incidents
  • Assists in the design, development, and implementation of security methodology and infrastructure for major systems
  • Liaison with campus IT practitioners to gather needs and feedback for RMC to ensure efficiency
  • Configures, develops, and tests applications and security controls
  • Assist in development and documentation of an RMC project management tool to include processes and workflows

Benefits

  • generous vacation, holidays, and sick leave
  • competitive insurances and savings accounts
  • retirement benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service