Vuori is re-defining what athletic apparel looks like: built to move and sweat in but designed with a casual aesthetic to transition into everyday life. We draw inspiration from an active coastal California lifestyle; an integration of fitness, creative expression, and life. Our high energy fast-paced retail environment is reflected in the clothes we make. We aim to inspire others to take on all aspects of their lives with clarity, enthusiasm, and purpose…while having a lot of fun along the way. We are proud to be an outlet for opportunity and for personal growth and success.
Senior Information Security Analyst
Location
United States
Posted
50 days ago
Salary
$117K - $151K / year
Seniority
Senior
Job Description
Senior Information Security Analyst
Vuori, Inc
Role Description The Senior Information Security Analyst is a senior level security professional whose primary responsibility is to design, operate, and continuously mature the organization’s Third‑Party / Vendor Risk Management (TPRM) program. In this role, the analyst serves as an embedded risk partner to the business, driving consistent, high‑quality vendor risk outcomes across the full third‑party lifecycle. While TPRM is the core focus of this role, the analyst is also expected to contribute meaningfully across other Information Security and Privacy domains as needed, including privacy operations, cyber governance, risk and compliance (GRC), and security operations. This role is ideal for a practitioner who enjoys vendor risk but is comfortable flexing across adjacent security functions in a fast-moving environment. What you'll get to do: - Third‑Party / Vendor Risk Management (Primary Focus) - Design, implement, operate, and continuously mature the Third‑Party Risk Management program, evolving it from a reactive, compliance driven function into a proactive, risk-based capability. - Execute and oversee the full third-party risk lifecycle, including onboarding, inherent and residual risk assessments, due diligence, periodic reviews, contract risk review, issue management, remediation tracking, and ongoing monitoring. - Perform deep technical security and risk assessments of third parties, including cloud services, SaaS platforms, infrastructure providers, and technology vendors. - Review and interpret security assurance artifacts such as SOC 2 Type II reports, penetration test reports, CAIQ, SIG, ISO certifications, and other compliance attestations. - Evaluate complex vendor solutions, including API integrations with critical internal systems, cloud native architectures (AWS, Azure, GCP), and AI/ML platforms. - Assess and manage emerging third-party risks, including artificial intelligence risks such as data provenance, model integrity, data leakage, and secure handling of proprietary or regulated data. - Lead end-to-end issue and remediation management, ensuring accountability, effectiveness, and timely closure of identified control gaps. - Develop and maintain TPRM standards, playbooks, governance models, escalation paths, and operating procedures aligned with regulatory expectations and business needs. - Build and deliver meaningful reporting, dashboards, and metrics that provide leadership with clear visibility into third-party risk posture, trends, and decision points. - Privacy & Data Protection (Primary Focus) - Support privacy operations, including Data Subject Requests (DSRs), Data Protection Impact Assessments (DPIAs), and data mapping initiatives. - Partner with Privacy and Legal stakeholders to assess vendor and internal data processing risks and ensure appropriate safeguards are in place. - Contribute to privacy related risk assessments, controls validation, and remediation tracking as needed. - Cyber Governance, Risk & Compliance (Supporting Responsibility) - Support cyber GRC activities, including tracking information security risks, risk exceptions, and remediation plans. - Assist with the implementation and ongoing operation of security and risk management frameworks (e.g., NIST, ISO, SOC 2). - Contribute to audit and assurance activities by providing risk assessments, evidence, and clear articulation of control posture. - Security Operations & Enablement (Supporting Responsibility) - Provide support to information security operations as needed, including incident response activities, impact analysis, and post incident follow‑up. - Contribute to security awareness and training initiatives, helping translate risk themes into actionable guidance for the business. - Assist with cross functional security initiatives during periods of increased demand or emerging risk. - Business Partnership & Advisory - Serve as a trusted risk advisor to vendor relationship owners and senior stakeholders, reducing their operational burden while preserving clear risk ownership and accountability. - Partner closely with Legal, Compliance, Procurement, Technology, and Security teams to synthesize requirements and deliver practical, risk‑appropriate solutions. - Review vendor contracts and summarize risk‑relevant provisions, control obligations, and gaps, partnering with Legal to support risk‑informed contract decisions. - Escalate material risks, delays, or control gaps thoughtfully and early, framing issues in clear business terms and presenting well‑defined options for decision‑making. Qualifications - 7+ years of progressive experience in Information Security, Third‑Party Risk Management, Vendor Risk Management, GRC, or Operational Risk. - Demonstrated experience owning, building, or leading a Third‑Party / Vendor Risk Management program. - Bachelor's degree in information security, Computer Science, Business Administration, or a related field or equivalent practical experience. - Strong experience conducting security risk assessments, assurance reviews, audits, and remediation management. - Deep technical understanding of cloud, SaaS, infrastructure, and AI vendor risk. - Hands on experience reviewing SOC 2, ISO 27001, penetration test reports, CAIQ, SIG, and similar security documentation. - Strong written and verbal communication skills, with the ability to translate technical risk into a clear business context for diverse audiences, including senior leadership. - Proven ability to work autonomously, manage competing priorities, and drive outcomes in a fast paced environment. Benefits - Health Insurance - Savings and Retirement Plan - Employee Assistance Program - Generous Vuori Discount & Industry Perks - Paid Time Off - Wellness & Fitness benefits
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
IT Security Analyst
State of MichiganLocated in the American Midwest, the State of Michigan is home to more than 10 million residents. Part of the Great Lakes region, Michigan has over 11,000 inlan
Review and remediate cyber incidents and vulnerabilities, maintain data confidentiality and integrity, and collaborate with IT security specialists to enhance security operations within the organization.
Senior Cybersecurity, Analyst
PublixHeadquartered in Lakeland, Florida, Publix is a supermarket chain operating more than 1,100 stores across the Southeastern U.S. states of Alabama, Florida, Geor
Assess security posture and implement controls, coordinate IT service updates, analyze systems for data classification, and provide compliance consultation on projects related to various regulations and security standards.
Security & Compliance Analyst
OTGOn the Go has elevated the dining and retail experience for travelers by bringing together world-class hospitality, award-winning dining concepts, and forward-thinking technology. With more than 300 unique dining and retail locations across North America’s busiest airports, we’re fueled by a passion for creating exceptional guest experiences—made possible every day by our incredible Crewmembers. At On the Go, people truly come first. We invest in our teams, and foster growth in an exciting, fast-paced environment where everyone can shine. How we work is just as meaningful as what we accomplish. Our Values—Care, Continuous Improvement, Quality, and Teamwork—guide the way we show up for our guests and for each other. We’re committed to fostering an inclusive, safe, and uplifting workplace where people feel respected, empowered, and encouraged to bring their full selves to work.
Role Description The Security & Compliance Analyst is responsible for the organization’s security posture and compliance obligations, with a primary focus on PCI DSS. This role oversees ongoing compliance efforts, conducts assessments, manages evidence collection, and supports the remediation of compliance gaps across restaurants & marketplaces, e-commerce platforms, and point-of-sale environments. The Security & Compliance Analyst works closely with IT, Engineering, Operations, and third-party business partners to maintain secure environments and achieve successful PCI DSS certification. - Support and maintain the organization’s PCI DSS compliance program across all in-scope systems, networks, and business units. - Conduct internal PCI assessments, gap analyses, and readiness reviews to identify and remediate compliance deficiencies. - Maintain documentation of PCI controls, evidence, and audit artifacts in the company’s Governance, Risk, and Compliance (GRC) platform. - Partner with IT, Security, and Retail Operations to validate technical and procedural controls for compliance. - Coordinate with Qualified Security Assessors (QSAs) during annual assessments, providing documentation and remediation updates. - Monitor system changes, new technologies, and third-party services for PCI scope impact. - Track and report compliance status, risks, and remediation progress to management. - Develop and deliver PCI awareness training for staff and store-level employees handling payment data. - Review and assess vendor compliance with PCI DSS and ensure required Attestations of Compliance (AOC) are maintained. - Stay current on PCI DSS version updates, industry trends, and payment security best practices. - Support broader security and compliance initiatives beyond PCI, including vendor risk management, cloud security controls (AWS), and policy development as the program matures. Qualifications - Bachelor’s degree in Information Security, Information Technology, or related field (or equivalent experience). - 3–5 years of experience in IT security, compliance, or audit, preferably within a retail or financial environment. - Hands-on experience with PCI DSS compliance programs, evidence collection, and remediation management. - Preferred Certifications: PCI Professional (PCIP) or Certified Information Systems Auditor (CISA) preferred; CISSP or equivalent a plus. - Familiarity with network security, encryption, firewalls, vulnerability management, and logging systems. - Familiarity with cloud environments, particularly AWS; experience with services relevant to secure data handling and compliance (e.g., IAM, CloudWatch, Secrets Manager, VPC segmentation) is a plus. - Experience with compliance tracking, documentation, or GRC tools; familiarity with enterprise platforms such as ServiceNow or equivalent is a plus. - Knowledge of POS systems, cardholder data environments, and segmentation practices. - Strong attention to detail and analytical skills. - Excellent written and verbal communication skills. - Ability to work cross-functionally and manage multiple priorities in a fast-paced retail environment. Company Description On the Go has elevated the dining and retail experience for travelers by bringing together world-class hospitality, award-winning dining concepts, and forward-thinking technology. With more than 300 unique dining and retail locations across North America’s busiest airports, we’re fueled by a passion for creating exceptional guest experiences—made possible every day by our incredible Crewmembers. At On the Go, people truly come first. We invest in our teams, and foster growth in an exciting, fast-paced environment where everyone can shine. How we work is just as meaningful as what we accomplish. Our Values—Care, Continuous Improvement, Quality, and Teamwork—guide the way we show up for our guests and for each other. We’re committed to fostering an inclusive, safe, and uplifting workplace where people feel respected, empowered, and encouraged to bring their full selves to work.
Senior Analyst Security - GRC + OT
AccentureAccenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships.
Role Description Explore new possibilities and inspire innovation. You will collaborate and manage the team to perform effectively, engage with multiple teams, and contribute to key decisions. You will provide solutions to challenges for your immediate team and across multiple teams, all while reflecting expertise in Governance Risk Compliance. Join us in shaping a secure and resilient future together. - Design and implement security solutions that align with enterprise policies and risk frameworks. - Govern the use of enterprise security tools, architecture frameworks, and security solutions. - Build and enhance digital identity, platform security, data and artificial intelligence protection, and cloud security solutions. - Develop and maintain security operations centers to detect and respond to cyber threats. - Collaborate with onshore, nearshore, and offshore capabilities to transform security approaches. Qualifications - Expert proficiency in Governance Risk Compliance. - Advanced proficiency in ISO Security Standards. - A minimum of 2 years of experience in relevant related skills. - High School Diploma/GED in relevant field of studies. Requirements - Advanced Operational Technology Security. - Advanced Security Delivery Governance. - Intermediate risk assessment and mitigation. - Intermediate incident response coordination. - Beginner knowledge of cybersecurity frameworks. Company Description Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. - Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. - We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. - Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. - We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.

