Sr. IT Security Risk & Compliance Analyst - Remote - 140476

Remote in San Diego, CA, US • Posted 23 hours ago • Updated 10 hours ago
Full Time
On-site
USD $130,000.00 - 170,000.00 per year
Fitment

Dice Job Match Score™

⏳ Almost there, hang tight...

Job Details

Skills

  • Payroll
  • Filing
  • Durable Skills
  • Continuous Improvement
  • Decision-making
  • HIPAA
  • PCI DSS
  • Communication
  • Operations Research
  • Risk Management
  • Legal
  • Electronic Discovery
  • Training
  • Information Security
  • Evaluation
  • Encryption
  • IT Security
  • Network Design
  • Computer Hardware
  • Network Security
  • Incident Management
  • Digital Forensics
  • Reporting
  • Risk Assessment
  • Cloud Computing
  • Business Process
  • Security Controls
  • Access Control
  • Management
  • Corrective And Preventive Action
  • Auditing
  • Documentation
  • Regulatory Compliance
  • Health Care
  • Higher Education
  • ISACA
  • CISM
  • CISA
  • CISSP
  • Recruiting
  • Budget
  • Public Health
  • Biomedicine
  • Research
  • Law
  • Screening
  • Forms
  • Unified Communications

Summary

Payroll Title:
IT SCRTY ANL 4 TX Department:
INFORMATION SERVICES Hiring Pay Scale
$130,000 - $170,000 / Year Worksite:
Towne Centre Drive Appointment Type:
Career Appointment Percent:
100% Union:
TX Contract Total Openings:
1 Work Schedule:
Days, 8 hrs/day, Monday-Friday

#140476 Sr. IT Security Risk & Compliance Analyst - Remote
Filing Deadline: Thu 7/23/2026
Apply Now

UC San Diego values and welcomes people from all backgrounds. If you are interested in being part of our team, possess the needed licensure and certifications, and feel that you have most of the qualifications and/or transferable skills for a job opening, we strongly encourage you to apply.

Reassignment Applicants : Eligible Reassignment clients should contact their Disability Counselor for assistance.

This is a UC San Diego Internal Recruitment open to UCSD and UCSD Health System Staff Only

DESCRIPTION

The Senior IT Security Risk and Compliance Analyst performs advanced information security risk assessment, governance, compliance, policy, and assurance activities across UC San Diego Health. Supports the development, implementation, and continuous improvement of information security risk management and compliance programs by identifying, assessing, and documenting security risks, threats, vulnerabilities, and control deficiencies affecting technologies, applications, systems, vendors/3rd-parties, business processes, research environments, and information assets. Provides risk-based recommendations to strengthen the organization's overall security posture and support informed decision-making.

Conducts complex security risk assessments, compliance reviews, and control evaluations; assesses control design and effectiveness, reviews supporting evidence, evaluates residual risk, and supports remediation planning. Activities include assessment of third-party providers, cloud services, new technologies, and other initiatives that introduce information security risk. Ensures alignment with University policy, industry standards, contractual obligations, and applicable regulatory requirements, including HIPAA, PCI DSS, FERPA, and related requirements.

Contributes to the development, maintenance, and communication of information security policies, standards, procedures, and related governance activities. Supports audit readiness, compliance monitoring, assurance activities, and risk treatment processes through evaluation of security controls, compensating controls, exception requests, corrective actions, and risk acceptance decisions. Develops and maintains documentation supporting risk assessments, compliance reviews, governance processes, audit requests, remediation activities, and regulatory requirements.

Serves as a trusted advisor to technical and business stakeholders regarding information security risks, compliance obligations, governance requirements, and remediation strategies. Communicates findings, recommendations, and risk determinations to stakeholders at multiple organizational levels and helps prioritize mitigation efforts based on risk to patient care, clinical operations, research activities, regulatory obligations, institutional objectives, and operational resiliency. Contributes to the maturity and effectiveness of the organization's information security, risk management, governance, and compliance programs.

May support investigations, legal requests, eDiscovery activities, and other matters requiring a high degree of professionalism, discretion, and confidentiality.

MINIMUM QUALIFICATIONS
  • Nine (9) years of related experience, education/training, OR a Bachelor's degree in a related area plus five (5) years of related experience/training. Related experience includes advanced information security risk assessment, compliance, governance, security assurance, control evaluation, or technical security activities within complex organizational environments.
  • Advanced interpersonal skills sufficient to work effectively with both technical and non-technical personnel at various levels in the organization.
  • Advanced experience using IT security systems and tools.
  • Knowledge of department processes and procedures.
  • Demonstrated skills applying security controls to computer software and hardware.
  • Demonstrated skill at administering complex security controls and configurations to computer hardware, software and networks.
  • Advanced knowledge of data encryption technologies and experience selecting and applying appropriate data encryption technologies.
  • Advanced knowledge of IT security.
  • Broad knowledge of other areas of IT.
  • Demonstrated knowledge of secure hardware, software and network design techniques.
  • Demonstrated skill at analyzing and preventing security incidents of high complexity.
  • In-depth knowledge of computer hardware, software and network security issues and approaches.
  • Advanced experience in incident response and digital forensics including reporting.
PREFERRED QUALIFICATIONS
  • Advanced experience conducting and documenting security risk assessments, control evaluations, security reviews, or security assurance activities across applications, systems, cloud services, vendors, research environments, or business processes.
  • Demonstrated ability to evaluate technical, administrative, and operational security controls and determine residual risk, control gaps, and risk-based recommendations.
  • Knowledge of evidence-based assessment techniques, including review of technical artifacts, configuration documentation, vulnerability data, remediation records, access control evidence, vendor documentation, and stakeholder attestations.
  • Experience documenting and managing risk exceptions, compensating controls, corrective action plans, risk acceptance decisions, and related governance activities.
  • Knowledge of vulnerability governance practices, including risk-based prioritization, remediation tracking, exception management, corrective action validation, and residual risk documentation.
  • Experience supporting audit readiness, compliance reviews, accreditation activities, regulatory inquiries, or other assurance-related processes through preparation, review, or validation of supporting documentation and evidence.
  • Knowledge of security and compliance frameworks, regulatory requirements, and industry practices relevant to healthcare, higher education, research, and regulated environments.
  • Experience working in healthcare, academic medical centers, research environments, higher education, or similarly regulated organizations.
  • Security-related certification such as CISSP, CRISC, CISM, CISA, HCISPP, or equivalent; CISSP strongly preferred.
SPECIAL CONDITIONS
  • Must be able to work various hours and locations based on business needs.
  • Employment is subject to a criminal background check and pre-employment physical.
Pay Transparency Act

Annual Full Pay Range: Unclassified - No data available (will be prorated if the appointment percentage is less than 100%)

Hourly Equivalent: Unclassified - No data available

Factors in determining the appropriate compensation for a role include experience, skills, knowledge, abilities, education, licensure and certifications, and other business and organizational needs. The Hiring Pay Scale referenced in the job posting is the budgeted salary or hourly range that the University reasonably expects to pay for this position. The Annual Full Pay Range may be broader than what the University anticipates to pay for this position, based on internal equity, budget, and collective bargaining agreements (when applicable).

Apply Now

If employed by the University of California, you will be required to comply with our Policy on Vaccination Programs, which may be amended or revised from time to time. Federal, state, or local public health directives may impose additional requirements. If applicable, life-support certifications (BLS, NRP, ACLS, etc.) must include hands-on practice and in-person skills assessment; online-only certification is not acceptable.

UC San Diego Health is the only academic health system in the San Diego region, providing leading-edge care in patient care, biomedical research, education, and community service. Our facilities include two university hospitals, a National Cancer Institute-designated Comprehensive Cancer Center, Shiley Eye Institute, Sulpizio Cardiovascular Center, the only Burn Center in the county, and dozens of outpatient clinics. We invite you to join our team!

Applications/Resumes are accepted for current job openings only. For full consideration on any job, applications must be received prior to the initial closing date. If a job has an extended deadline, applications/resumes will be considered during the extension period; however, a job may be filled before the extended date is reached.

To foster the best possible working and learning environment, UC San Diego strives to cultivate a rich and diverse environment, inclusive and supportive of all students, faculty, staff and visitors. For more information, please visit UC San Diego Principles of Community .

The University of California is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, or other protected status under state or federal law.

For the University of California's Anti-Discrimination Policy, please visit:

UC San Diego is a smoke and tobacco free environment. Please visit smokefree.ucsd.edu for more information.

UC San Diego Health maintains a marijuana and drug free environment. Employees may be subject to drug screening.

Misconduct Disclosure Requirement: As a condition of employment, the final candidate who accepts an offer of employment will be required to disclose if they have been subject to any final administrative or judicial decisions within the last seven years determining that they committed any misconduct; or have filed an appeal of a finding of substantiated misconduct with a previous employer.

a. "Misconduct" means any violation of the policies governing employee conduct at the applicant's previous place of employment, including, but not limited to, violations of policies prohibiting sexual harassment, sexual assault, or other forms of harassment, or discrimination, as defined by the employer. For reference, below are UC's policies addressing some forms of misconduct:
  • UC Sexual Violence and Sexual Harassment Policy
  • UC Anti-Discrimination Policy
  • Abusive Conduct in the Workplace
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 80184016
  • Position Id: b97f3ca9fb90555194b2dbb1fe9a5854
  • Posted 23 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

San Diego, California

Today

Full-time

USD 110,982.00 - 155,376.00 per year

San Diego, California

Today

Full-time

USD 125,000.00 - 175,000.00 per year

San Marcos, California

Today

Full-time

USD 6,492.00 - 6,890.00 per month

San Diego, California

Today

Full-time

USD 125,000.00 - 165,000.00 per year

Search all similar jobs