Principal Information Security Analyst
2 weeks ago
Remote, OR, United States
Nike
Full-time
Free with email or Google
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Free with email or Google
By continuing, you agree to our Terms & Privacy Policy.
Open to remote work except in South Dakota, Vermont and West Virginia.The annual base salary for this position ranges from $149,100.00 in our lowest geographic market to $313,900.00 in our highest geographic market. Actual salary will vary based on a candidate's location, qualifications, skills and experience.
Information about benefits can be found here. WHO WE ARE LOOKING FOR
We're looking for a
Principal Information Security Analyst
to join the Information Risk Management (IRM) team within Corporate Information Security (CIS). This role is a senior individual contributor and program leader who will deliver against an information security and cybersecurity assessment plan integrated into a broader enterprise risk management program supported by executive management. You will leverage deep expertise in security policies, standards, controls, and industry best practices to perform and lead risk assessments of Nike systems and systems managed for Nike by vendors. You will also drive strategic advancement of Nike's Third-Party Risk Management (TPRM) program—establishing risk-profiling methodologies, tiered assurance frameworks, vendor lifecycle controls, and executive reporting capabilities that protect Nike's most sensitive data across a complex global vendor ecosystem. Our ideal candidate is a trusted advisor with superb communication skills, exceptional analytical and problem-solving ability, intellectual curiosity, and proven experience translating complex security risks for both technical and non-technical audiences—including executive leadership, procurement, legal, privacy, and technology partners. You thrive in cross-functional environments, influence without authority, and bring a principal-level perspective to program design, not just execution. Beyond assessment execution and program delivery, this role carries a broader organizational mandate. You will serve as a recognized subject matter expert in information risk and cybersecurity not only within CIS, but across Nike. Partner teams including Procurement, Legal, Privacy, Engineering, and the broader Nike Business will look to you as a trusted, accessible authority on information risk. You will also identify, initiate, and lead cross-functional programs that extend beyond IRM’s immediate scope, efforts such as enterprise-wide data governance alignment or cross-team risk standardization, bringing structure and momentum to problems that span organizational boundaries. WHAT YOU WILL WORK ON
This role works with the Information Risk Management team to identify, assess, elevate visibility to, and remediate information security risks across Nike's technology landscape. As a Principal-level contributor, you will lead high-complexity assessments, shape team methodology, mentor analysts, and own key TPRM program initiatives. Key responsibilities include: Third-Party Risk Management Program Leadership
Advance TPRM capability maturity
by designing and implementing program rigor beyond control self-assessments, including vendor risk profiling, risk-based controls testing, and tiered assurance requirements Establish and operationalize a standardized vendor risk-profiling methodology
(e.g., data sensitivity, criticality, regulatory impact) to consistently categorize vendors by inherent risk tier and drive risk-based assessment prioritization Define and implement tiered assurance requirements
so that higher-risk vendors undergo deeper validation (evidence reviews, control testing, security baseline documentation) while lower-risk vendors follow appropriately scaled processes Introduce targeted validation of high-impact controls
(e.g., access management, data protection, availability) for critical suppliers, going beyond self-attestation to validate design and operational effectiveness Establish mandatory control effectiveness standards
requiring vendors to demonstrate effective design and operational execution for high-impact controls prior to contractual engagement or network integration Develop and operationalize TPRM metrics and executive reporting
, including third-party blind metrics and integration into Executive TPRM Council reporting Expand factory risk assessment program scope
and contribute to assurance activities for Nike's highest-risk indirect and direct third parties Plan and execute joint response planning tabletop exercises
with key direct and indirect suppliers to validate incident readiness and coordination capabilities Vendor Lifecycle Governance
Close vendor onboarding gaps
by designing and enforcing standardized, enterprise-wide onboarding controls to ensure no vendor obtains network access or data-sharing capab
Information about benefits can be found here. WHO WE ARE LOOKING FOR
We're looking for a
Principal Information Security Analyst
to join the Information Risk Management (IRM) team within Corporate Information Security (CIS). This role is a senior individual contributor and program leader who will deliver against an information security and cybersecurity assessment plan integrated into a broader enterprise risk management program supported by executive management. You will leverage deep expertise in security policies, standards, controls, and industry best practices to perform and lead risk assessments of Nike systems and systems managed for Nike by vendors. You will also drive strategic advancement of Nike's Third-Party Risk Management (TPRM) program—establishing risk-profiling methodologies, tiered assurance frameworks, vendor lifecycle controls, and executive reporting capabilities that protect Nike's most sensitive data across a complex global vendor ecosystem. Our ideal candidate is a trusted advisor with superb communication skills, exceptional analytical and problem-solving ability, intellectual curiosity, and proven experience translating complex security risks for both technical and non-technical audiences—including executive leadership, procurement, legal, privacy, and technology partners. You thrive in cross-functional environments, influence without authority, and bring a principal-level perspective to program design, not just execution. Beyond assessment execution and program delivery, this role carries a broader organizational mandate. You will serve as a recognized subject matter expert in information risk and cybersecurity not only within CIS, but across Nike. Partner teams including Procurement, Legal, Privacy, Engineering, and the broader Nike Business will look to you as a trusted, accessible authority on information risk. You will also identify, initiate, and lead cross-functional programs that extend beyond IRM’s immediate scope, efforts such as enterprise-wide data governance alignment or cross-team risk standardization, bringing structure and momentum to problems that span organizational boundaries. WHAT YOU WILL WORK ON
This role works with the Information Risk Management team to identify, assess, elevate visibility to, and remediate information security risks across Nike's technology landscape. As a Principal-level contributor, you will lead high-complexity assessments, shape team methodology, mentor analysts, and own key TPRM program initiatives. Key responsibilities include: Third-Party Risk Management Program Leadership
Advance TPRM capability maturity
by designing and implementing program rigor beyond control self-assessments, including vendor risk profiling, risk-based controls testing, and tiered assurance requirements Establish and operationalize a standardized vendor risk-profiling methodology
(e.g., data sensitivity, criticality, regulatory impact) to consistently categorize vendors by inherent risk tier and drive risk-based assessment prioritization Define and implement tiered assurance requirements
so that higher-risk vendors undergo deeper validation (evidence reviews, control testing, security baseline documentation) while lower-risk vendors follow appropriately scaled processes Introduce targeted validation of high-impact controls
(e.g., access management, data protection, availability) for critical suppliers, going beyond self-attestation to validate design and operational effectiveness Establish mandatory control effectiveness standards
requiring vendors to demonstrate effective design and operational execution for high-impact controls prior to contractual engagement or network integration Develop and operationalize TPRM metrics and executive reporting
, including third-party blind metrics and integration into Executive TPRM Council reporting Expand factory risk assessment program scope
and contribute to assurance activities for Nike's highest-risk indirect and direct third parties Plan and execute joint response planning tabletop exercises
with key direct and indirect suppliers to validate incident readiness and coordination capabilities Vendor Lifecycle Governance
Close vendor onboarding gaps
by designing and enforcing standardized, enterprise-wide onboarding controls to ensure no vendor obtains network access or data-sharing capab