Rice Park Capital Managment LP
Minneapolis / Global
You have blocked notifications
Oops! You have blocked notifications. Click here for more info
You have blocked notifications, please check your browser settings.
You're currently subscribed to job notifications
Subscribe to notifications
You will no longer receive notifications
Minneapolis / Global
POSITION DESCRIPTION: We are seeking a motivated, detail-oriented Information Security Analyst to own and mature Rice Parks information security governance, risk, and compliance (GRC) program. This is a governance and risk management role, not a security operations role: Rice Park engages a third-party managed security services provider (MSSP) to handle day-to-day SIEM monitoring, alert triage, and SOC-level response.This position is the internal owner of that vendor relationship and of Rice Parks broader InfoSec program ensuring the MSSP is delivering against its scope, identifying and closing the gaps the vendor does not cover (e.g., access reviews, policy governance, internal risk assessments), and driving Rice Parks compliance posture across frameworks such as SOC 2 and GLBA, as well as investor and lender due diligence requirements.The Information Security Analyst will work closely with the head of IT and coordinate across the organization to manage risk, maintain governance documentation, and ensure Rice Park meets its regulatory, contractual, and investor-facing security obligations.DUTIES AND RESPONSIBILITIES:Vendor & Security Program ManagementServe as the primary internal owner of the relationship with Rice Parks managed security services provider (MSSP), ensuring SLAs are met and proactively identifying coverage gapsCoordinate third-party penetration testing engagements, including scoping, scheduling, documentation, and remediation trackingTrack and drive remediation of findings from the MSSP, internal audits, and vulnerability scansGovernance, Risk & ComplianceOwn and maintain the information security policy and procedure suite, including annual review and approval cyclesLead SOC 2, GLBA, and related compliance efforts, including evidence collection, control testing, and remediation of gapsConduct internal and external risk assessments and audits, and maintain the enterprise risk registerSupport the development and execution of Business Impact Analyses (BIA), business continuity planning, and related risk management activitiesManage investor, lender, and other counterparty information security due diligence requests and questionnaires, on both an ad hoc and annual basisAccess & Control OversightOwn the user access review program across systems and applications an area outside the MSSPs scope including designing the review cadence and ensuring appropriate controls are documented and enforcedServe as the internal escalation point of contact for the MSSP during a security incident, coordinating internal response, documentation, and communicationAwareness & Continuous ImprovementMaintain and deliver Rice Parks security awareness training and phishing simulation programCollaborate with internal teams across the organization to promote security awareness and ensure adherence to security policies and protocolsStay current on cybersecurity trends, regulatory developments, and industry best practices relevant to Rice Parks risk profileUndertake other related duties as assigned to support business operations and evolving organizational needsQUALIFICATIONS:Bachelors degree in Information Technology, Risk Management, Business, Cybersecurity, or a related field (or equivalent experience)2+ years of experience in information security governance, risk, or compliance (GRC); experience managing an MSSP or other outsourced security vendor relationship is a strong plusWorking knowledge of regulatory and compliance frameworks such as SOC 2, ISO 27001, NIST CSF, and GLBAExperience conducting or supporting risk assessments, audits, access reviews, and third-party/vendor due diligenceStrong policy writing, documentation, and project management skillsFamiliarity with SIEM and security tooling output sufficient to interpret and act on vendor reporting (hands-on SIEM operation is not required that is handled by our MSSP)Strong organizational and communication skills; comfort managing vendors and driving cross-functional accountabilityAbility to handle sensitive information with discretion and professionalismNice to have: exposure to a scripting or programming language (e.g., SQL, Python) for reporting and data analysisNice to have: CISA, CRISC, or a similar governance-oriented certificationPOSITION DETAILS: This is a full-time position with competitive compensation (salary & bonus) and a comprehensive benefits package including:Medical, Dental, Vision Insurance OptionsPaid Time Off and Paid HolidaysCompany Paid Life InsuranceLong-Term Disability401(k) with employer matchWork Location: Plymouth, MN or Charlotte, NC (hybrid)
recblid z54g0zx3jvmzk1cziwvj4njec4h43j
Minneapolis / Global
Minneapolis / Global
Minneapolis / Global
Minneapolis / Global
Lake Elmo / Global
Minneapolis / Global