Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Information Security Systems Analyst (Minneapolis, MN)

$96.56k - $124.96k

Dorsey & Whitney

GRC Information Security Systems Analyst (Minneapolis, MN) (#4073)

Join Dorsey’s Information Security team as aGRC Information Security Systems Analystto help safeguard our firm and clients by driving high-impact security initiatives across audits, risk, governance, and compliance. Reporting directly to the Information Security Systems Manager, you’ll lead and support client and pre-contract security assessments, organize and execute internal ISMS audits and management reviews, maintain current policies and controls aligned to ISO 27001 and other leading frameworks, and oversee authorization services and quarterly NetDocuments access reviews. You’ll partner with stakeholders to deliver cybersecurity consulting projects, validate repeatable RBAC and entitlement processes, and ensure our DLP program meets client, ISO, and regulatory requirements to make a tangible difference in the resilience and trust our clients expect.

Key Responsibilities Include:

  • Support Information Security Systems Manager with the maintenance of Information Security documentation, supporting changes in the organization, technology, or threat landscape.

  • Provide Information Security Program reporting related to metrics and dashboards for various Dorsey committees as requested by Information Security Systems Manager.

  • Create and oversee the distribution of Bimonthly Information Security communications released Firm wide.

  • Collaborate with Firm and Information Services process owners and stakeholders, internal and external assessors and auditors to execute and review risk assessments, internal and external surveillance audits resulting in the recertification (e.g., ISO 27001, GDPR). Document audit findings, remediation action plans and audit report responses.

  • Consult with Information Services teams, Dorsey Business Teams and advise on Compliance requirements, and Information Security Standards and Controls.

  • Collaborate with Information Services team stakeholders to implement processes that automate and continuously monitor Compliance-related, Information Security Standard controls, and approved exceptions.

  • Assist GRC and Information Security management with ISMS continuous operation, monitoring, and improvement of the Information Security Management System (ISMS) by organizing and executing annual internal audits and management reviews.

Maintain Compliance-related documentation, including policies, procedures, Statement of Applicability, are current and reflect any changes in the organization, technology, or threat landscape.

  • Complete Client-generated pre- and post-contract security controls and risk review assessment, audits, in support of Dorsey client requests.

  • Review and provide security input into Client RFP Responses. Support Marketing and Business Development teams with RFP response requests as they pertain to Information Security information.

  • Perform Dorsey-requested pre-contract security controls and risk review of technology, software, and services.

  • Maintain Dorsey SIG Questionnaire and ndMax AI chatbot, collaborating with key Information Services stakeholders for its currency.

  • Assist the Information Security Systems Manager with project-based risk assessments, interviewing, collecting data, and documenting risk. May be asked to present risk assessment results to Head of Cybersecurity and CIO for discussion and drive decision-making. Document risk decision in risk register if necessary.

  • Maintain Firm Technology Risk Register, provide reporting and coordinate meetings with Information Services Leadership to discuss open risk items and remediation actions.

  • Support the Information Security Systems Manager in the creation of an annual Firm-wide Annual Security Awareness Training Program, Human Risk Initiative, with Phish Simulation Testing.

  • Support the delivery of a focused 8-week training program for currently hired business professionals, New Hired business professionals training.

  • Support the delivery of multi-month, Firm-wide Phish Simulation Testing.

  • Prepare Human Risk reporting and update Human Risk Calculations and additional training assigned by the Information Security Systems Manager.

  • Execute the project-based enhancement of RBAC, Rights, Permissions, Groups, and Entitlement Definition and Clean-Up for Privileged Accounts (PIM), Service Accounts, and User Accounts, this position will support the ongoing Identity & Authorization Services Compliance Oversight process.

  • Execute post-project oversight process will validate the defined, repeatable process being followed to ensure all user, privileged users, and service accounts maintain security to reduce risk of unauthorized access.

  • Execute oversight process to ensure assurance is validated, repeatable processes are being followed to ensure all human and nonhuman accounts maintain security that reduce risk of unauthorized access and shrink attack surfaces.

  • Perform the quarterly NetDocuments access review as assigned.

  • Support the DLP Program Execution and Oversight to ensure the DLP controls meet Client, ISO, Information Governance, and Regulatory requirements.

  • May perform other duties not listed above.

What we’re looking for:

  • Bachelor's Degree or equivalent in Business, Computer Science or equivalent experience.

  • At least 3-5 years (preferred 5-7 years) of demonstrated experience across three of the following:

  • Implementing or maintaining an Information Security Management System (ISMS) aligned to one or more of the following compliance frameworks:

  • ISO 27001:2013, ISO 27001:2022, SOC2, GDPR, NIST Cybersecurity Framework (CSF), or NIST 800-53.

  • Implementing or maintaining information security policies, standards, controls, guidelines, and procedures in one or more of the following compliance frameworks:

  • ISO 27001:2013, ISO 27001:2022, SOC2, GDPR, NIST Cybersecurity Framework (CSF), or NIST 800-53.

  • Client-request assessment, audit experience and IT/Security technology, software security risk assessment reviews.

  • Similar technology/information security focused experience with minimum of 3 years' experience with at least two of the following:

  • Compliance function.

  • Information security risk and risk frameworks.

  • IT/security governance, and (4) audit.

  • Security awareness training programs.

  • At least 3-5 years (preferred 5-7 years) of experience with:

  • Successful planning, preparing, and delivery of audit (re)certification, authorization of in-scope technology asset compliance environments and boundaries.

  • Performing client security risk assessments, RFP Cybersecurity responses, driving Third-Party Vendor Technology and Service Security Risk Assessments and ongoing Monitoring.

  • Hands-on experience defining, implementing, and maintaining annual information security training program.

  • At least 2-3 years of hands‑on experience driving IAM enhancements using automation and tooling across hybrid AD/Entra environments, including group and role analysis, AD permission cleanup, RBAC design and implementation, least‑privilege enforcement, privileged access reduction, and integration of IAM with HR and IT lifecycle workflows.

  • At least 2–3 years of hands‑on experience executing Data Loss Prevention (DLP) enhancement initiatives, including defining data in scope, implementing data classification and tagging, developing and deploying DLP policies and alerting requirements, performing initial analysis of data flows and risks, and partnering with SOC, IT, and business teams to ensure ongoing compliance and control effectiveness.

  • Excellent written and verbal communication skills; demonstrated experience, communicating and collaborating effectively across business and technology areas.

  • Ability to work independently, excellent organizational and management skills.

  • Ability to manage and prioritize multiple tasks and adapt to needed changes.

  • Knowledge of on-premises and MSFT Azure, M365 Tenant-based technologies and cloud infrastructure platforms (e.g., Microsoft Azure, Microsoft 365, Microsoft AD & Entra, Microsoft Purview, OneDrive, TEAMS, Sentinel, Microsoft Defender, Exchange Online, Exchange On-Prem, Zoom, Jabber, Document Management Systems, SSO, OAuth) and SaaS-based application frameworks to evaluate key information security requirements, controls, risk areas.

Preferred:

  • At least one certification such as CISSP, CISM, and/or CISA.

  • At least 5-7 years' Governance, Risk, and Compliance experiences, listed above.

  • Prior Legal or Professional Services experience.

  • Informed on information security industry standards and best practices.

About Dorsey:

Dorsey & Whitney is a global law firm with over 650 lawyers across 22 offices in the United States, Canada, Europe and Asia. We provide strategic legal counsel to companies worldwide across a diverse range of industries, including banking & financial institutions; development & infrastructure; energy & natural resources; food, beverage & agribusiness; healthcare & life sciences; and technology.

Dorsey offers opportunities for advancement within a collaborative and dynamic environment, with competitive pay and excellent benefits. Our benefits are available to business professionals working 17+ hours/week along with their dependents, including spouses and domestic partners regardless of gender. Dorsey’s benefit package includes: comprehensive medical insurance with coverage for infertility, gender-affirming care, behavioral health, and access to virtual providers; dental insurance; vision insurance; 401(k) retirement savings plan with Firm contribution; basic and optional life insurance; short and long-term disability; paid time off; up to 8 weeks of paid parental leave with up to an additional 6-8 weeks of paid short-term disability for business professionals who give birth; paid holidays; paid volunteer day; discretionary bonuses (if bonus eligible); adoption assistance; healthcare, dependent care, and transportation pre-tax reimbursement accounts; back-up child and elder care program; education and college advising program; virtual tutoring; wellbeing programs and activities; mass transit program (certain offices); travel assistance program; 24/7 employee assistance program with access to five confidential visits with a licensed counselor at no cost. (Some benefits are subject to eligibility criteria.)

One of our greatest strengths is a friendly, cooperative culture that values and appreciates each individual. Dorsey has received external recognition for our welcoming workplace, including:

  • Mansfield Certification Plus (Diversity Lab)

  • Best Law Firms for Women (National Association of Female Executives and Flex-Time Lawyers)

  • 100% rating on the Corporate Equality Index (Human Rights Campaign)

  • Gold Standard Certification (Women in Law Empowerment Forum)

  • Top 100 Adoption-Friendly Workplace (Dave Thomas Foundation for Adoption)

Reasonable Accommodations:

Dorsey is committed to providing disability and religious-based reasonable accommodations, as well as menopause, pregnancy or lactation-related reasonable accommodations. If you require a reasonable accommodation during the application and hiring process, or if you have questions about a workplace reasonable accommodation, please contact us at View phone number on click.appcast.io.

How to Apply:

Dorsey & Whitney LLP accepts online applications. Please go to the “Careers” section of the Dorsey website at and complete Dorsey’s online application form. We are unable to accept application materials by mail or email.

Dorsey & Whitney LLP is an EEO/AAP/Disabled Vets Employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, ancestry, sex, national origin, sexual orientation, gender identity, affectional preference, disability, age, marital status, familial status, status with regard to public assistance, military or veteran status, or any other legally-protected status.

Dorsey & Whitney LLP participates in E-Verify.

The pay range for this position in Minnesota only is an annual salary of $96,560 to $124,960.

This range represents Dorsey’s good faith estimate of likely compensation at the time of posting. Actual pay will be dependent upon a number of factors, including the candidate’s experience, qualifications, skills and location and may fall outside of the range indicated.

Dorsey estimates it will accept applications through June 10, 2026.

Please note that Dorsey is not currently accepting search firm submissions in connection with this opening.

#LI-TC1

#LI-Hybrid

Office Location:

Minneapolis, MN

Vacancy posted 5 hours ago
Similar jobs that could be interesting for youBased on the GRC Information Security Systems Analyst (Minneapolis, MN) in Minneapolis, MN vacancy
  •  ...of our top financial customers is seeking a Senior Information Security Analyst with expertise in ServiceNow GRC. As a Senior Information Security Analyst you will...  ..., - GRC (preferred) ~ Certified Information Systems Security Professional (CISSP) ~ Certified Information... 
    Information System

    Insight Global

    Minneapolis, MN
    3 days ago
  • $110k - $120k

     ...Cloud Security Analyst Senior ECMC Group is a nonprofit...  ...succeed. Headquartered in Minneapolis, ECMC Group and its...  ...to security information events across multiple...  ...attendance in Minneapolis, MN on designated in-office...  ...for cloud-based systems. Conducts regular... 
    Information System
    Full time
    Work at office
    Visa sponsorship
    Work visa
    Flexible hours
    Night shift

    ECMC Group

    Minneapolis, MN
    22 hours ago
  • $96.56k - $124.96k

    Dorsey & Whitney LLP seeks a GRC Information Security Systems Analyst in Minneapolis to oversee compliance and security initiatives. This role demands 3-7 years of experience with information security frameworks such as ISO 27001 and strong skills in risk assessments and... 
    Information System

    Dorsey & Whitney LLP

    Minneapolis, MN
    1 day ago
  • $30 per hour

     ...training and professional development in fields such as information technology, technical/systems consulting, technical support, facilities, finance...  ...and Federal Sales Teams. The Information Security Compliance Analyst is expected to work with the GDI Performance Management... 
    Information System
    Hourly pay
    Temporary work
    Internship
    Flexible hours

    Oracle

    Saint Paul, MN
    3 days ago
  • $90.78k

     ...We are seeking a seasoned Security Governance/Risk professional to...  ...establishing and advising on Information Assurance and security requirements...  .... Advise information system owners on client/project security...  ..., and maintenance of a GRC Minimum Requirements '-... 
    Information System
    Work at office

    MAXIMUS

    Saint Paul, MN
    1 day ago
  • $145.02k

     ...Solutions Architect, RBC Capital Markets, LLC, Minneapolis, MN: Responsible for assessing and...  ...solution. Working with technical systems specialist, business systems specialists...  ...interfaces. Working with Data Architecture, Security Architecture and Infrastructure SME's... 
    Full time
    Work experience placement
    Remote work
    Monday to Friday
    3 days per week

    RBC Capital Markets, LLC

    Minneapolis, MN
    1 day ago
  • $145.02k

     ...project team members like Business Analysts, Quality Engineers, Enterprise system Architects and stakeholders to...  ...degree or foreign equivalent in Information Systems, Computer Science, Electronic...  ...Address: 250 NICOLLET MALL:MINNEAPOLIS City: Minneapolis Country:... 
    Information System
    Full time
    Work experience placement
    Work at office
    Remote work
    Monday to Friday
    3 days per week

    Royal Bank of Canada

    Minneapolis, MN
    more than 2 months ago
  • $91.7k - $163.7k

     ...highly skilled and resourceful offensive security assessment member to join our...  ...Drive cross-team efforts to address systemic risks across the business Conduct...  ...Part 107 drone license Located in Minneapolis/St. Paul, MN *All Telecommuters will be required... 
    Minimum wage
    Full time
    Work experience placement
    Local area
    Remote work

    Optum

    Eden Prairie, MN
    2 days ago
  •  ...Testers / Dynamic Application Security Testing (DAST) San...  ...Irving TX or Chandler AZ or Minneapolis MN (Hybrid 3-5 days onsite) 12+...  ...initiatives and deliverables within Information Security Engineering and...  ...information security applications and systems experience ~3 years of... 
    Information System

    Syntricate Technologies

    Minneapolis, MN
    3 days ago
  • $115k

     ...Operations Overview GovCIO is currently hiring for Senior Information Security Analyst with an active Secret clearance to plan and coordinate IT...  ...programs and policies. Manage and control changes to systems, assessing the security impact of related changes.... 
    Full time
    Currently hiring
    Remote work
    Flexible hours

    GovCIO

    Saint Paul, MN
    1 day ago
  •  ...(09-15-2025 - 02-28-2026) Location: Minneapolis, MN Primary Skills: Angular Job Description...  ...'s Degree in Computer Science Information Systems with 7 years of relevant technical experience...  ...efficient Ensure adherence to security standards and compliance with privacy... 
    Information System
    Contract work
    Immediate start

    Staffing the Universe

    Minneapolis, MN
    3 days ago
  • $70.8k - $131.4k

     ...The Thomson Reuters Information Security and Risk Management (ISRM) organization is seeking a Security Operations Analyst to join our growing global Security Operations Center...  ...activities using case management and ticketing systems   About You You’re a fit for the role... 
    Work at office
    Local area
    Flexible hours
    Shift work
    2 days per week
    3 days per week

    Thomson Reuters

    Eagan, MN
    4 days ago
  •  ...Sr. Systems Analyst We are looking to hire a Sr. Systems Analyst for Minneapolis, MN. The Senior System Analyst will be responsible for executing in depth analysis...  ...~ Bachelor's degree in Computer Science, Information Systems or related field Preferred Skills... 
    Information System

    Echo IT Solutions

    Minneapolis, MN
    3 days ago
  • $120k - $130k

     ...As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance, in particular with our cyber resilience and preparedness. We are looking for a proactive professional with excellent collaboration... 
    Temporary work

    Deluxe Corporation

    Minneapolis, MN
    4 days ago
  • $91.7k - $163.7k

    Senior Physical Red Team Security Analyst (2354040) Optum is a global organization delivering...  ...Drive cross‑team efforts to address systemic risks across the business Conduct...  ...Part 107 drone license Located in Minneapolis/St. Paul, MN Benefits and Compensation Salary... 
    Local area
    Remote work

    UnitedHealth-Grou

    Eden Prairie, MN
    2 days ago
  • $68.4k

     ...Responsibilities include business/systems analysis, requirements...  ...and problem resolution. The analyst communicates with system end-...  ...degree in Computer Science, Information Systems, Healthcare or relevant...  ...Procedures as well as all data security guidelines established within... 
    Information System
    For contractors
    Work experience placement
    Work at office
    Local area
    Remote work

    Highmark Health

    Saint Paul, MN
    22 hours ago
  • $133.2k - $172.37k

     .../Prevention Specialist within Gilead's Minneapolis, MN, you will represent Gilead's products and...  ...and deliver timely disease awareness information, clinical updates, and education on healthcare...  ...customer information in the designated systems, submitting expenses, and managing the... 
    Information System
    Work at office
    Local area
    Worldwide

    Gilead

    Minneapolis, MN
    2 days ago
  •  ...in Industrial Control System (ICS) and Operational...  ...Consultant for Enhanced Information Solutions (EIS), you...  ...Systems Certification (Security+, CISM, CISSP, etc.)...  ...candidate will live in the Minneapolis area and be able to be...  ...on the client site in MN 75% of the time or... 
    Information System
    Live in
    Local area

    Enhanced Information Solutions

    Minneapolis, MN
    3 days ago
  •  ...MS Sql Developer Location: Charlotte NC, Minneapolis MN, Chandler AZ Position Type: Contract US Citizen, Green Card, TN, GC EAD and H4 EAD only No Third-party agencies corp to corp. Job Description: • Must Have: ~8+ years of MS SQL server experience in... 
    Contract work

    Staffing the Universe

    Minneapolis, MN
    13 days ago
  • $34.03 per hour

     ...located at the Marshall Operations Center in Minneapolis, MN. The starting rate of pay for this...  ...of outages to the electric delivery system. Job Responsibilities This list is not...  ...you may redact or remove age-identifying information including but not limited to dates of school... 
    Information System
    Hourly pay
    Full time
    Temporary work
    For contractors

    Xcel Energy

    Minneapolis, MN
    1 day ago
  •  ...Application Developer Location: MINNEAPOLIS, MN Duration: Contract Rate: DOE US Citizen, Green Card, TN, H4EAD, and GC EAD preferred...  ...of multi-threaded application in interfacing with other systems Experience in XML and XSLT transformation Experience... 
    Contract work
    H1b

    Georgia IT Inc

    Minneapolis, MN
    8 days ago
  • $72.4k - $108.6k

     ...have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for...  ...Grumman Defense Systems is seeking an Industrial Security Analyst for our Plymouth, MN location. Roles and Responsibilities: Develops and... 
    Contract work
    Work at office
    Remote work
    Relocation
    Shift work

    Northrop Grumman

    Minneapolis, MN
    3 days ago
  •  ...Job Title: Associate Security Analyst – Cloud Vendor Risk Management We are seeking an Associate...  ...Bachelor’s degree in Cybersecurity, Information Security, IT, Risk Management, or a related...  ...-career experience in cybersecurity, GRC, or vendor risk management... 
    Internship

    Insight Global

    Minneapolis, MN
    2 days ago
  •  ...Sr .Net System Developer Location: Minneapolis, MN Position Type: Fulltime Rate: DOE $/hr. on w2 No Visa...  ....NET web developer) and Certified Secure Programmer • C# • JavaScript...  ...credentials to access some system-level information. • SignalR • Peripheral... 
    Full time
    Visa sponsorship

    Staffing the Universe

    Minneapolis, MN
    2 days ago
  • $78k - $90k

    North Risk Partners, LLC is looking for a Security Analyst II in Plymouth, MN. This role involves operating and improving the security program with responsibilities in detection, investigation, and compliance aligned with industry standards. Candidates should have an associate... 
    Full time

    North Risk Partners, LLC

    Minneapolis, MN
    1 day ago
  • $112.7k - $193.2k

     ...businesses, UnitedHealthcare and Optum, working to build a better health system for all. Here, your contributions matter as they will help...  ...five days a week at our corporate headquarters in Eden Prairie, MN Reside within a commutable distance to Eden Prairie, MN Preferred... 
    Minimum wage
    Full time
    Work experience placement
    Local area
    Flexible hours

    UnitedHealth Group

    Eden Prairie, MN
    2 days ago
  •  ...19s talk about Perks At our North Loop Minneapolis office, we have an awesome office environment...  ...+ Vendor Relations / Operations + Information Technology great people. great services...  ...to verify information and proper system setup u2022 Validate catalog maintenance... 
    Information System
    Work at office
    Local area
    Remote work
    Flexible hours

    Compass Group, North America

    Minneapolis, MN
    4 days ago
  •  ...(***) ***-**** . Title: Security Advisor Duration: 6 Months...  ...Location: St. Paul, MN or Abbott Park (North Chicago...  ..., and backend systems, including building security...  ...based and regulatory-informed cybersecurity requirements...  ...and operational use of GRC toolsets (Governance... 
    Information System
    Permanent employment
    Full time
    Temporary work

    DivIHN Integration

    Saint Paul, MN
    4 days ago
  • $100.8k - $165.6k

     ...$100,800.00 - $165,600.00 Position Summary The Sr. IT Security Specialist is responsible for the development and enforcement...  ...experience in lieu of a degree. Preferred: CISSP (Certified Information Systems Security Professional - ISC2) or CISM (Certified Information... 
    Information System
    Temporary work
    Work experience placement
    Internship
    Worldwide
    Flexible hours

    Bio-Techne

    Minneapolis, MN
    4 days ago
  •  ...talk about Perks! At our North Loop Minneapolis office, we have an awesome office environment...  ...Vendor Relations / Operations Information Technology great people. great services...  ..., and governance across enterprise systems. This role partners with Operations, Implementation... 
    Information System
    Work at office
    Local area
    Remote work
    Flexible hours

    Compass Group, North America

    Minneapolis, MN
    22 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Information Security Systems Analyst (Minneapolis, MN). Be the first to apply!