Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Information Security Analyst - Information Risk Management

$149.1k - $313.9k
Full-time

Nike

Open to remote work except in South Dakota, Vermont and West Virginia.The annual base salary for this position ranges from $149,100.00 in our lowest geographic market to $313,900.00 in our highest geographic market. Actual salary will vary based on a candidate's location, qualifications, skills and experience.

Information about benefits can be found here.

WHO WE ARE LOOKING FOR

We're looking for a Principal Information Security Analyst to join the Information Risk Management (IRM) team within Corporate Information Security (CIS). This role is a senior individual contributor and program leader who will deliver against an information security and cybersecurity assessment plan integrated into a broader enterprise risk management program supported by executive management.

You will leverage deep expertise in security policies, standards, controls, and industry best practices to perform and lead risk assessments of Nike systems and systems managed for Nike by vendors. You will also drive strategic advancement of Nike's Third-Party Risk Management (TPRM) program—establishing risk-profiling methodologies, tiered assurance frameworks, vendor lifecycle controls, and executive reporting capabilities that protect Nike's most sensitive data across a complex global vendor ecosystem.

Our ideal candidate is a trusted advisor with superb communication skills, exceptional analytical and problem-solving ability, intellectual curiosity, and proven experience translating complex security risks for both technical and non-technical audiences—including executive leadership, procurement, legal, privacy, and technology partners. You thrive in cross-functional environments, influence without authority, and bring a principal-level perspective to program design, not just execution.

Beyond assessment execution and program delivery, this role carries a broader organizational mandate. You will serve as a recognized subject matter expert in information risk and cybersecurity not only within CIS, but across Nike. Partner teams including Procurement, Legal, Privacy, Engineering, and the broader Nike Business will look to you as a trusted, accessible authority on information risk. You will also identify, initiate, and lead cross-functional programs that extend beyond IRM’s immediate scope, efforts such as enterprise-wide data governance alignment or cross-team risk standardization, bringing structure and momentum to problems that span organizational boundaries.

WHAT YOU WILL WORK ON

This role works with the Information Risk Management team to identify, assess, elevate visibility to, and remediate information security risks across Nike's technology landscape. As a Principal-level contributor, you will lead high-complexity assessments, shape team methodology, mentor analysts, and own key TPRM program initiatives.

Key responsibilities include:

Third-Party Risk Management Program Leadership

  • Advance TPRM capability maturity by designing and implementing program rigor beyond control self-assessments, including vendor risk profiling, risk-based controls testing, and tiered assurance requirements
  • Establish and operationalize a standardized vendor risk-profiling methodology (e.g., data sensitivity, criticality, regulatory impact) to consistently categorize vendors by inherent risk tier and drive risk-based assessment prioritization
  • Define and implement tiered assurance requirements so that higher-risk vendors undergo deeper validation (evidence reviews, control testing, security baseline documentation) while lower-risk vendors follow appropriately scaled processes
  • Introduce targeted validation of high-impact controls (e.g., access management, data protection, availability) for critical suppliers, going beyond self-attestation to validate design and operational effectiveness
  • Establish mandatory control effectiveness standards requiring vendors to demonstrate effective design and operational execution for high-impact controls prior to contractual engagement or network integration
  • Develop and operationalize TPRM metrics and executive reporting , including third-party blind metrics and integration into Executive TPRM Council reporting
  • Expand factory risk assessment program scope and contribute to assurance activities for Nike's highest-risk indirect and direct third parties
  • Plan and execute joint response planning tabletop exercises with key direct and indirect suppliers to validate incident readiness and coordination capabilities

Vendor Lifecycle Governance

  • Close vendor onboarding gaps by designing and enforcing standardized, enterprise-wide onboarding controls to ensure no vendor obtains network access or data-sharing capability until a thorough risk assessment is completed
  • Build and steward a centralized vendor inventory capturing all active vendors, associated services, and data-sharing agreements, with inventory updates embedded into the global onboarding workflow
  • Design and enforce a standardized, enterprise-wide vendor offboarding process to ensure all vendor access and data-sharing channels are terminated promptly and consistently at contract end
  • Partner with Procurement, Legal, Privacy, and Technology to align vendor lifecycle controls across domains and drive measurable compliance with TPRM onboarding and offboarding requirements

Enterprise Risk Leadership & Cross-Functional Inf luence

  • Serve as a recognized subject matter expert in information risk and cybersecurity across Nike, representing IRM and CIS with credibility and authority in forums, partner team engagements, and ad-hoc consultations
  • Embed with cross-functional partners, including Procurement, Legal, Privacy, Engineering, and Nike Business teams, to provide ongoing security risk guidance, ensuring these teams view information security as a strategic partner invested in their success
  • Identify emerging risks, capability gaps, and opportunities for enterprise-wide improvement that others have not yet surfaced, and drive action by building the case, gaining stakeholder alignment, and advancing solutions
  • Initiate and lead cross-team programs and initiatives that extend beyond IRM, such as enterprise data governance alignment, cross-domain risk standardization, or shared assurance frameworks, taking them from concept through operationalization with minimal oversight
  • When assigned to lead or support broader organizational initiatives, operate with full autonomy: set direction, engage stakeholders, build roadmaps, and drive execution end-to-end
  • Maintain and elevate the reputation of IRM and CIS by consistently demonstrating deep understanding of business context, delivering pragmatic risk guidance, and building trust as someone who gives direct, honest assessments of risk

Vendor Information Risk Assessments

  • Perform and lead formal risk assessments on partner and vendor connections, evaluating vendor processes at the point of engagement with Nike
  • Ensure sufficient validation of data sharing arrangements and agreements to protect Nike's sensitive information
  • Confirm business objectives align with the type and volume of data used, maintaining a "need to know/use" mindset
  • Review third-party SOC reports, security baseline documentation, and vendor security evidence as part of assessment activities
  • Establish risk and remediation ownership for identified vendor-related risks and document findings in the Risk Register
  • Serve as a senior escalation point for complex vendor risk decisions and exception recommendations

Security Controls Baseline Assessments

  • Lead assessments of complex platforms and systems against Nike security and configuration standards
  • Evaluate and process exceptions to information security policies and standards, providing principal-level recommendations on risk acceptance and compensating controls
  • Perform compliance control validation testing to determine the operating effectiveness of IT controls for scoped systems
  • Consult with technology units on IT general controls (ITGCs) and compliance matters
  • Champion information security policies, standards, controls, and processes so compliance requirements are addressed as part of business-as-usual operations

Internal Risk Assessments

  • Identify, document, and elevate visibility to information risk where business direction creates potential exposure to employee, athlete, and product sensitive data streams
  • Identify and profile Nike systems and processes that require risk assessments; scope and lead specific assessments accordingly
  • Perform detailed analysis of threats and vulnerabilities across information security domains including network security, asset security, security engineering, identity and access management, security operations, and software development security
  • Review key system configurations and complex IT infrastructures (e.g., cloud services, SaaS platforms, hybrid environments)
  • Communicate effectively through risk reports, presentations, and stakeholder interactions to drive remediation of identified risks

Data Analysis, Reporting, and Strategic Initiatives

  • Own vendor risk management metrics, reporting, and master data stewardship to improve accuracy, timeliness, and completeness
  • Provide analysis and insights into data supporting the effectiveness of technical and process-based cybersecurity controls
  • Lead process improvements for data retrieval, analysis, and risk assessment intake
  • Contribute to and lead IRM team projects and strategic initiatives, including documentation in ServiceNow (SNOW), Aravo, Jira, and Box
  • Support the risk analysis intake process and participate in daily standups and weekly process meetings
  • Mentor and coach Senior and Analyst-level team members on assessment methodology, stakeholder engagement, and risk communication
  • Influence information security strategy through risk-informed insights and expertise that drive the strategic direction of CIS in alignment with Nike's overall strategic vision

General Responsibilitie s

  • Execute and lead targeted internal and external (vendor) risk assessments in support of IRM strategy, following established team processes and enablers while continuously improving them
  • Be proactive in anticipating next steps in the risk assessment process and act accordingly
  • Collaborate with team members on assessment approach, scoping, documentation, and issue presentation activities; provide quality review and guidance on team deliverables
  • Serve as a principal-level information security and CIS representative to Nike lines of business and management, acting as the team’s voice in cross-functional forums, building enduring relationships with partner teams, and ensuring IRM is sought out as a trusted advisor rather than engaged only as a checkpoint
  • Provide enforcement of security policies, standards, and procedures by working cross-functionally with Compliance and Governance functions
  • Stay current on information security technologies, trends, standards, best practices, and emerging threats and vulnerabilities

WHO YOU WILL WORK WIT H

This role reports to the Director of Information Risk Management within Corporate Information Security (CIS). You will build strong partnerships with the IRM team, CIS leadership, Nike business and technology process owners, and various governance and legal functions (e.g., Audit, Privacy, and Legal). You will work cross-functionally across Nike at World Headquarters and globally, with particularly close collaboration with Procurement , Privacy , and Technology partners on third-party risk initiatives. You will regularly engage executive stakeholders through TPRM Council reporting and high-risk vendor escalation activities.

WHAT YOU BRIN G

  • Bachelor's degree in Business Information Management, Computer Science, or a related field; will accept any suitable combination of education, experience, and training
  • 8+ years of experience in information security, risk management, GRC, third-party risk management, or a related field, with demonstrated progression in scope, complexity, and influence
  • 3+ years of experience performing vendor/third-party risk assessments and leading internal information security risk assessments in a large enterprise environment
  • Deep knowledge of information security principles and practices, best practice security architectures, general procedures, and guidelines
  • Deep knowledge of information security frameworks and best practices (e.g., NIST, ISO 27000, COBIT, COSO)
  • Experience designing or operationalizing third-party risk management programs , including vendor tiering, tiered assurance models, vendor lifecycle governance, and TPRM metrics/reporting
  • Experience assessing systems against security standards and performing control validation or baseline assessments
  • Experience reviewing third-party SOC reports, security baseline documentation, and vendor assurance evidence
  • Experience partnering with Procurement, Legal, and Privacy on vendor risk and contractual security requirements
  • A general understanding of technology use, trends, and risks as they apply in a business context and environment
  • Exceptional analytical and problem-solving skills with proven ability to identify solutions for complex problems in enterprise environments
  • Superb communication skills (written and verbal) with comfort and experience presenting to executive audiences and proven persuasion skills
  • The ability to appropriately communicate complex security risks to non-technical staff and influence remediation at scale
  • Demonstrated experience serving as a recognized security subject matter expert beyond your immediate team; proactively consulted by partner functions and trusted to represent security’s perspective in cross-functional settings
  • Track record of identifying organizational gaps or opportunities and independently initiating cross-team programs or initiatives that drove measurable improvement, not solely executing against a predefined roadmap
  • Experience operating with significant autonomy in a matrixed environment, building stakeholder alignment, navigating competing priorities, and delivering outcomes across teams without direct authority
  • Demonstrated ability to mentor, coach, and quality-review the work of other risk analysts
  • Experience with ServiceNow, Aravo, Confluence, or Jira preferred
  • Advanced knowledge of Excel and PowerPoint; experience organizing and analyzing large datasets preferred
  • CISSP, CISM, CRISC, or relevant GIAC Management Focus Area certifications strongly preferred
  • Must be trustworthy in keeping sensitive data confidential
  • Demonstrated desire for continual learning and improvement
  • Occasional travel - ability to travel approximately 5% of the time

POSITION LOCATION

This role is based in the United States , with preference for Nike World Headquarters (Beaverton, Oregon) or another U.S.-based location. U.S.-based placement supports close collaboration with executive stakeholders, Procurement, Legal, Privacy, and World Headquarters technology partners on enterprise TPRM program initiatives that require real-time cross-functional engagement and U.S. regulatory context.

We offer a number of accommodations to complete our interview process including screen readers, sign language interpreters, accessible and single location for in-person interviews, closed captioning, and other reasonable modifications as needed. If you discover, as you navigate our application process, that you need assistance or an accommodation due to a disability, please complete the Candidate Accommodation Request Form.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Principal Information Security Analyst - Information Risk Management in Remote vacancy
  • $120.38k - $192.6k

     ...GlanceThis position will develop and conduct information security risk assessments on parties external to...  ...acceptable tolerances. The Sr. Analyst will provide direction and guidance to...  ...Lincoln’s information security risk management requirements for the services to be provided... 
    Suggested
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Lincoln Financial Group

    Radnor, PA
    1 day ago
  • $140k - $160k

     ...Delta Solutions & Strategies is seeking a Senior Information Security Analyst to support United States Space Force Space Systems Command (SSC...  ...position will provide cybersecurity, information assurance, Risk Management Framework, system authorization, security compliance,... 
    Suggested
    Full time
    Contract work
    For contractors
    Work experience placement
    Work at office

    The Delta Solutions

    Remote
    12 hours ago
  • $107.74k - $140.3k

     ...Job Qualifications: Information Security Management, RMF, System Security Job Description: Check out this...  ...Required: None Job Family: Cyber and IT Risk Management Certifications: None...  ...individuals with disabilities to perform the principal (essential) functions of this job.... 
    Principal
    Temporary work
    Work at office
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Honolulu, HI
    43 minutes ago
  • $110.5k - $149.5k

    Information Security Analyst Principal This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Information Security...  ...security architecture, infrastructure, risk management, compliance, and secure... 
    Principal
    Full time
    Temporary work
    Remote work
    Monday to Friday
    Flexible hours

    Jobgether

    New York, NY
    3 days ago
  • Security Administration and Operations This team is tasked with providing...  ...and security configuration management to the enterprise. Security...  ...policies. Provide support to Risk management and IT Security...  ...call rotation Coordinate with Information Security team to ensure solution... 
    Suggested
    Remote job
    Weekend work
    Afternoon shift

    E-Solutions

    Mc Lean, VA
    3 days ago
  • $88.3k - $162.43k

    Overview Job ID 37879163 Category Information Technology Organization Info Technology Solutions Department IT Risk Management Dept Location Remote/Hybrid Salary $88,302 - $...  ...No Position Information The Information Security Analyst is responsible for the implementation of... 
    Full time
    Part time
    Work at office
    Local area
    Remote work
    Work visa

    University-of-California,-Riversid

    Riverside, CA
    1 day ago
  •  ...improve the lives and ensure the security of all Americans—from...  ...Scope: We are seeking an Information Security Analyst who is responsible for...  ..., Configuration and Change Management Plans, Incident Response Plans...  ...more. Interpret security risk assessment, review security... 
    Work experience placement
    Remote work

    eSimplicity

    Maryland, MD
    24 days ago
  • Lead Information Security Analyst In Cybersecurity Supporting Identity And Access Management (Iam) Wells Fargo is seeking a Lead Information Security Analyst in Cybersecurity supporting...  ...of information security compliance policy, risk management, and remediation Direct... 
    Work experience placement
    Work at office
    Remote work

    Minnesota Jobs

    Chandler, AZ
    1 day ago
  • $80k - $100k

    Description:: Under the direction of the Director, Information Security, the Information Security Compliance Analyst supports the execution, administration, and...  ...'s cybersecurity compliance, governance, and risk management programs. This role is responsible for... 
    Full time
    Remote work

    ImageTrend

    Eagan, MN
    19 days ago
  •  ...SummaryThe Cyber Threat Analytics Analyst is responsible for...  ...behavior, suspicious activity, and security anomalies across the enterprise. This role is part Information Security team focused on bringing...  ...Response, and Vulnerability Management teams to improve detection... 
    Local area
    Remote work
    Flexible hours
    2 days per week
    3 days per week
    1 day per week

    Lam Research Corporation

    Tualatin, OR
    3 days ago
  • $110.97k - $135.63k

     ...us transform healthcare? Bring your true colors to blue. What we needThe Senior Information Risk Analyst is a risk management professional, a versatile technical risk and information security expert, and a highly valued partner within the Information Risk Management (IRM... 
    Full time
    Contract work
    Remote work
    Shift work

    Blue Cross and Blue Shield Association

    Boston, MA
    9 hours ago
  •  ...are one of the largest asset managers in Asia and number one among...  ...business functions. Information Risk Governance (“IRG”) provides...  ...oversight to information and cyber security risk by maintaining and improving...  ...Operations Center (SOC) Analyst is responsible for monitoring... 
    Work at office
    Work from home
    Flexible hours
    2 days per week

    SUMITOMO MITSUI TRUST BANK, LIMITED

    New York, NY
    20 days ago
  • $94.49k - $131.16k

     ...Let’s see what we can achieve. Together.SummaryThe Senior Information Security Analyst is responsible for identifying, investigating, and addressing...  ...processes. Additionally, this role involves directly managing relationships with our security operations vendors and providing... 
    Full time
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Relocation package

    DLA Piper

    Chicago, IL
    4 days ago
  • $121k - $132k

    Position: Senior Information Security Analyst Location: Parsippany, NJJob Id:...  ...assessment and mitigation of information risk and the remediation of identified...  ...network, systems and software applications. Manages continuous monitoring of all... 
    Full time
    Work at office
    Local area
    Remote work
    Monday to Thursday
    Flexible hours

    Marotta

    Parsippany, NJ
    1 day ago
  • $91.19k - $136.78k

     ...effectiveness of the organization's security controls, detection...  ...investments, and reduce cyber risk. Reporting to the Cybersecurity Manager, the Security Analyst will work closely with IT teams...  ...project related tasks. Train information owners in the implementation of... 
    Full time
    Work at office
    Work from home

    Point32Health

    Canton, MA
    12 hours ago
  • $99k - $225k

    Information Security AnalystThe Opportunity: When our country’s cybersecurity is on the line, simply...  ...of those policies, and areas of risks. You’ll evaluate how policies stack up...  ...assessments or performing supply chain risk management analysisExperience in services for the... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Alexandria, VA
    1 day ago
  • Company DescriptionArtech Information Systems is the #12 Largest IT Staffing...  ...market intelligence has secured long-term partnerships with...  ...consoles, both local and remote • Manage customer accounts and...  ...knowledge sharing with other analysts and develop customer solutions... 
    Work experience placement
    Local area
    Remote work
    All shifts
    Shift work

    Artech

    Plano, TX
    12 hours ago
  • $76k - $127k

     ...Ready to join us?Your RoleWe’re hiring Information Security Analysts to join our team, blending traditional...  ...track key performance indicators and risk metrics for senior leadership while partnering...  ...You can prioritize your workload and manage multiple security projects at the same... 
    Work at office
    Remote work
    Flexible hours

    Hudl

    Lincoln, NE
    3 days ago
  • Job Title: Information Security Analyst I or IIWork Place Flexibility: Hybrid Legal Entity: Entergy Services...  ...Analyst I-II will report to the Manager, CSOC and will manage day-to-day tasks...  ...of the various threats and risks related to utility workforce, energy... 
    Work experience placement
    Work at office
    Local area
    Relocation
    Visa sponsorship
    Work visa

    Entergy

    Little Rock, AR
    3 days ago
  • $98.23k - $123.77k

    Role: Information Security Analyst (VTM/Vulnerability Management)Location: Dallas, TX (Must be local to Dallas and able to come onsite to the Dallas office twice...  ...vulnerability management program, compliance initiatives, and risk management activities. This role plays a critical... 
    Full time
    For contractors
    Work at office
    Local area
    Work from home
    Flexible hours

    Blue Yonder

    Dallas, TX
    1 day ago
  •  ...Healthcare. We are hiring a full-time talented Information Security Analyst who is technical, dedicated to...  ..., strong initiative, and able to manage projects autonomously. The Information...  ...remediation with system owners based on risk and priority.Audit user access and permissions... 
    Full time
    Contract work
    Internship
    Work from home

    Medpace

    Cincinnati, OH
    12 hours ago
  • $169.95k - $179.3k

     ...McKesson Corporation POSITION: Senior Information Security Analyst LOCATION: 6555 State Highway 161,...  ...: Lead the delivery and lifecycle management of enterprise security data products,...  ...to identify and remediate security risks, track progress, and ensure alignment... 
    Remote work

    MCKESSON

    Irving, TX
    1 day ago
  • $114k - $139k

     ...USAdministration - Enterprise Information Security /Full-Time /RemoteAs a GRC Security Analyst, you will serve as a fully qualified...  ...in maintaining our Governance, Risk, and Compliance (GRC) posture....  ...comprehensive reports for management, clients, and regulatory authorities... 
    Full time
    Temporary work
    Work experience placement
    Remote work

    Clear Capital

    Reno, NV
    2 days ago
  • $112.2k - $120k

     ...Job Title:  Senior Information Security Analyst Status: Exempt Reports to: Manager - Information Security Investigations Department: IT - Info Sec Analysis...  ...vulnerability management, threat detection, and risk mitigation. You have a proven ability to partner... 
    Immediate start
    Remote work

    Golden 1 Talent Acquisition Team

    United States
    3 days ago
  •  ...your career. Zantech is looking for a talented Project Manager - Team Lead / Information Security Analyst - SME to provide Continuous Process Improvement (CPI), Focused Development and Automation services, Risk Management Operations Support, Continuous Monitoring and... 
    Full time
    Contract work
    Remote work

    Zantech

    Camp Springs, MD
    22 days ago
  • $91.7k - $163.7k

     ...Manager Of Technical Project And Program ManagementOptum is a global...  ...tracking progress across critical security and enterprise programs....  ...executive reporting, dashboards, and risk metrics while leveraging...  ...emerging technology trends to inform solution design and strategic... 
    Minimum wage
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work

    UnitedHealth Group

    Eden Prairie, MN
    3 days ago
  • $95k - $120k

     ...Great Gray is looking to add a Senior Information Security Analyst on our Information Security Team. The role will support IT governance, risk assessment, and security compliance functions...  ...IT governance, enterprise risk management, and compliance with regulations and control... 
    Work experience placement
    Local area
    Remote work
    Visa sponsorship

    Great Gray Group.

    Brooklyn, NY
    18 hours ago
  • $95k - $115k

     ...InformationSecurity Analystto join our Information Security team. This role is the operational backbone...  ...running smoothly. You will primarily manage the security ticket queue, troubleshoot...  ...AND BENEFITS: Pay range: Security Analyst/Level I: $95,000.00 - $115,000.00/per year... 
    Permanent employment
    Temporary work
    Work at office
    Remote work
    Monday to Friday
    Weekend work

    SPACE EXPLORATION TECHNOLOGIES CORP

    Brooklyn, NY
    43 minutes ago
  • Wells Fargo is seeking a Lead Information Security Analyst to join the BISO organization.We are back in...  ...professional who can identify meaningful risks, turn complex data into actionable...  ...Security, Identity & Access Management (IAM), and AI Security. You will analyze... 
    Full time
    Work experience placement
    Work at office
    Remote work
    Visa sponsorship
    3 days per week

    Wells Fargo

    Chandler, AZ
    4 days ago
  •  ...provides Specialty Revenue Cycle Management solutions for healthcare...  ...years. Position Summary The Security Analyst is responsible for assisting...  ...expertise in all areas of information security. They will work closely...  ...issues; recommending risk-reduction solutions. Solid understanding... 
    Work experience placement
    Flexible hours

    EnableComp

    Raleigh, NC
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Information Security Analyst - Information Risk Management. Be the first to apply!