About The Position

This role is a senior individual contributor and program leader within the Information Risk Management (IRM) team, part of Corporate Information Security (CIS). The position is responsible for delivering against an information security and cybersecurity assessment plan integrated into a broader enterprise risk management program. The analyst will leverage expertise in security policies, standards, controls, and industry best practices to conduct and lead risk assessments of Nike systems and vendor-managed systems. A key focus will be driving the strategic advancement of Nike's Third-Party Risk Management (TPRM) program, including establishing risk-profiling methodologies, tiered assurance frameworks, vendor lifecycle controls, and executive reporting capabilities. The ideal candidate is a trusted advisor with strong communication, analytical, and problem-solving skills, capable of translating complex security risks for diverse audiences. This role also involves serving as a recognized subject matter expert across Nike and initiating cross-functional programs for enterprise-wide improvement.

Requirements

  • Bachelor's degree in Business Information Management, Computer Science, or a related field; will accept any suitable combination of education, experience, and training.
  • 8+ years of experience in information security, risk management, GRC, third-party risk management, or a related field, with demonstrated progression in scope, complexity, and influence.
  • 3+ years of experience performing vendor/third-party risk assessments and leading internal information security risk assessments in a large enterprise environment.
  • Deep knowledge of information security principles and practices, best practice security architectures, general procedures, and guidelines.
  • Deep knowledge of information security frameworks and best practices (e.g., NIST, ISO 27000, COBIT, COSO).
  • Experience designing or operationalizing third-party risk management programs, including vendor tiering, tiered assurance models, vendor lifecycle governance, and TPRM metrics/reporting.
  • Experience assessing systems against security standards and performing control validation or baseline assessments.
  • Experience reviewing third-party SOC reports, security baseline documentation, and vendor assurance evidence.
  • Experience partnering with Procurement, Legal, and Privacy on vendor risk and contractual security requirements.
  • A general understanding of technology use, trends, and risks as they apply in a business context and environment.
  • Exceptional analytical and problem-solving skills with proven ability to identify solutions for complex problems in enterprise environments.
  • Superb communication skills (written and verbal) with comfort and experience presenting to executive audiences and proven persuasion skills.
  • The ability to appropriately communicate complex security risks to non-technical staff and influence remediation at scale.
  • Demonstrated experience serving as a recognized security subject matter expert beyond your immediate team; proactively consulted by partner functions and trusted to represent security’s perspective in cross-functional settings.
  • Track record of identifying organizational gaps or opportunities and independently initiating cross-team programs or initiatives that drove measurable improvement, not solely executing against a predefined roadmap.
  • Experience operating with significant autonomy in a matrixed environment, building stakeholder alignment, navigating competing priorities, and delivering outcomes across teams without direct authority.
  • Demonstrated ability to mentor, coach, and quality-review the work of other risk analysts.
  • Experience with ServiceNow, Aravo, Confluence, or Jira preferred.
  • Advanced knowledge of Excel and PowerPoint; experience organizing and analyzing large datasets preferred.
  • CISSP, CISM, CRISC, or relevant GIAC Management Focus Area certifications strongly preferred.
  • Must be trustworthy in keeping sensitive data confidential.
  • Demonstrated desire for continual learning and improvement.

Nice To Haves

  • Experience with ServiceNow, Aravo, Confluence, or Jira preferred.
  • Advanced knowledge of Excel and PowerPoint; experience organizing and analyzing large datasets preferred.
  • CISSP, CISM, CRISC, or relevant GIAC Management Focus Area certifications strongly preferred.

Responsibilities

  • Advance TPRM capability maturity by designing and implementing program rigor beyond control self-assessments, including vendor risk profiling, risk-based controls testing, and tiered assurance requirements.
  • Establish and operationalize a standardized vendor risk-profiling methodology to consistently categorize vendors by inherent risk tier and drive risk-based assessment prioritization.
  • Define and implement tiered assurance requirements so that higher-risk vendors undergo deeper validation while lower-risk vendors follow appropriately scaled processes.
  • Introduce targeted validation of high-impact controls for critical suppliers, going beyond self-attestation to validate design and operational effectiveness.
  • Establish mandatory control effectiveness standards requiring vendors to demonstrate effective design and operational execution for high-impact controls prior to contractual engagement or network integration.
  • Develop and operationalize TPRM metrics and executive reporting, including third-party blind metrics and integration into Executive TPRM Council reporting.
  • Expand factory risk assessment program scope and contribute to assurance activities for Nike's highest-risk indirect and direct third parties.
  • Plan and execute joint response planning tabletop exercises with key direct and indirect suppliers to validate incident readiness and coordination capabilities.
  • Close vendor onboarding gaps by designing and enforcing standardized, enterprise-wide onboarding controls.
  • Build and steward a centralized vendor inventory capturing all active vendors, associated services, and data-sharing agreements.
  • Design and enforce a standardized, enterprise-wide vendor offboarding process to ensure all vendor access and data-sharing channels are terminated promptly and consistently at contract end.
  • Partner with Procurement, Legal, Privacy, and Technology to align vendor lifecycle controls across domains and drive measurable compliance with TPRM onboarding and offboarding requirements.
  • Serve as a recognized subject matter expert in information risk and cybersecurity across Nike, representing IRM and CIS in various forums and engagements.
  • Embed with cross-functional partners, including Procurement, Legal, Privacy, Engineering, and Nike Business teams, to provide ongoing security risk guidance.
  • Identify emerging risks, capability gaps, and opportunities for enterprise-wide improvement and drive action.
  • Initiate and lead cross-team programs and initiatives that extend beyond IRM, such as enterprise data governance alignment or cross-domain risk standardization.
  • Perform and lead formal risk assessments on partner and vendor connections, evaluating vendor processes at the point of engagement with Nike.
  • Ensure sufficient validation of data sharing arrangements and agreements to protect Nike's sensitive information.
  • Confirm business objectives align with the type and volume of data used, maintaining a "need to know/use" mindset.
  • Review third-party SOC reports, security baseline documentation, and vendor security evidence as part of assessment activities.
  • Establish risk and remediation ownership for identified vendor-related risks and document findings in the Risk Register.
  • Serve as a senior escalation point for complex vendor risk decisions and exception recommendations.
  • Lead assessments of complex platforms and systems against Nike security and configuration standards.
  • Evaluate and process exceptions to information security policies and standards, providing principal-level recommendations on risk acceptance and compensating controls.
  • Perform compliance control validation testing to determine the operating effectiveness of IT controls for scoped systems.
  • Consult with technology units on IT general controls (ITGCs) and compliance matters.
  • Champion information security policies, standards, controls, and processes so compliance requirements are addressed as part of business-as-usual operations.
  • Identify, document, and elevate visibility to information risk where business direction creates potential exposure to employee, athlete, and product sensitive data streams.
  • Identify and profile Nike systems and processes that require risk assessments; scope and lead specific assessments accordingly.
  • Perform detailed analysis of threats and vulnerabilities across information security domains.
  • Review key system configurations and complex IT infrastructures.
  • Communicate effectively through risk reports, presentations, and stakeholder interactions to drive remediation of identified risks.
  • Own vendor risk management metrics, reporting, and master data stewardship to improve accuracy, timeliness, and completeness.
  • Provide analysis and insights into data supporting the effectiveness of technical and process-based cybersecurity controls.
  • Lead process improvements for data retrieval, analysis, and risk assessment intake.
  • Contribute to and lead IRM team projects and strategic initiatives.
  • Support the risk analysis intake process and participate in daily standups and weekly process meetings.
  • Mentor and coach Senior and Analyst-level team members on assessment methodology, stakeholder engagement, and risk communication.
  • Influence information security strategy through risk-informed insights and expertise.
  • Execute and lead targeted internal and external (vendor) risk assessments in support of IRM strategy, following established team processes and enablers while continuously improving them.
  • Be proactive in anticipating next steps in the risk assessment process and act accordingly.
  • Collaborate with team members on assessment approach, scoping, documentation, and issue presentation activities; provide quality review and guidance on team deliverables.
  • Serve as a principal-level information security and CIS representative to Nike lines of business and management, acting as the team’s voice in cross-functional forums, building enduring relationships with partner teams, and ensuring IRM is sought out as a trusted advisor rather than engaged only as a checkpoint.
  • Provide enforcement of security policies, standards, and procedures by working cross-functionally with Compliance and Governance functions.
  • Stay current on information security technologies, trends, standards, best practices, and emerging threats and vulnerabilities.

Benefits

  • Information about benefits can be found here.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service