
Cloud Security Risk and Compliance Analyst
- Minneapolis, MN
- $105,400-124,000 per year
- Permanent
- Full-time
- Identify technical security requirements to reduce risk and ensure alignment with enterprise policies and standards.
- Validate that proposed solutions meet the intent of security and compliance requirements.
- Support the development and documentation of security controls by contributing to control design discussions, drafting procedures, and maintaining accurate records aligned with compliance requirements.
- Develop and maintain cloud-focused security guidance integrated with the Enterprise Cloud program.
- Evaluate new cloud technologies for potential security and risk implications.
- Collaborate with stakeholders to embed security and risk principles into product development.
- Analyze security and compliance requirements for cloud-based applications and services.
- Assess risks, vulnerabilities, and threats; support the development of mitigation strategies.
- Communicate security risks and recommendations clearly to technical and non-technical stakeholders.
- Maintain repeatable, documented processes and controls aligned with authoritative requirements.
- Assists with the documentation of risks and treatment plans; monitor remediation efforts with technical and business partners.
- Aggregate and report on thematic security findings; present insights to governance committees.
- Review and validate security controls for effectiveness and risk mitigation.
- Escalate high-impact items through governance channels.
- Provide recommendations to leadership on program improvements.
- Bachelor’s degree in Technology or Business Related Discipline, or equivalent work experience., or equivalent work experience.
- 3+ years of experience in cloud security and/or information security roles.
- 2+ years of experience in technology risk management and/or audit.
- Working knowledge of cloud security and information security principles.
- Strong initiative and collaborative mindset.
- Strong decision-making and problem-solving skills.
- In-depth knowledge of cloud security concepts and architecture.
- Excellent interpersonal, verbal, and written communication skills.
- High attention to detail and documentation quality.
- Experience working in Agile environments.
- Ability to communicate technical concepts to diverse audiences.
- Proven ability to build relationships across technical and non-technical teams.
- Broad technical background including regulatory compliance, security technologies, and controls.
- Understanding of information security architecture and governance.
- Familiarity with IT standards, procedures, and policy development.
- Basic proficiency with BI tools (e.g., Tableau, Power BI).
- Experience with GRC tools (e.g., RSA Archer, ServiceNow).
- Awareness of IT industry trends and emerging technologies.
- Relevant certifications such as:
- CISSP, CISA, CRISC, CCSP, CCSK
- Microsoft Azure certifications (e.g., AZ-900, SC-900)
- AWS certifications (e.g., AWS Certified Cloud Practitioner, AWS Certified Solutions Architect – Associate)