994,162open jobs
59,296companies
165,357added this week
Browse all
Salary
$90k – $132k per year
Location
In office (Minneapolis, Chicago)
Seniority
Staff · 3+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 1, 2026. First seen by Alion on Sep 30, 2026.

Overview
Company
Impact
Profile match
We drive results. Ovative Group is a digital-first media and measurement firm that's transforming the measure of marketing success.

About Ovative Group:

Ovative Group is an independent, full-funnel media, measurement, and creative firm transforming how brands grow. We partner with leading names like American Eagle, Best Buy, Domino’s, The Home Depot, Polaris, and UnitedHealth Group to build smarter media and measurement programs that drive real, profitable growth.

We don’t just track performance-we redefine it. Powered by our proprietary intelligence platform, EMRge, and our holistic metric Enterprise Marketing Return (EMR), we help brands connect revenue, customer, and brand outcomes into one clear picture of success. Our approach to full-funnel strategy, buying, and measurement delivers results that matter-and it’s getting noticed. Our work has been recognized by Digiday, Google, USA Today, Inc. 5000, and Search Engine Land.

About the Role

Ovative Group is seeking a Security Analyst to join our growing Information Security team. Reporting to the Head of Information Security and Privacy, this role

owns the operational core of our governance, risk, and compliance program - client security questionnaires, vendor assessments, and SOC 2 operations - and builds out new capabilities in AI governance and enablement. The ideal candidate is a strong writer, highly organized, comfortable engaging both technical and non-technical stakeholders, and genuinely excited about helping a company adopt AI quickly and safely.

Responsibilities

Governance, Risk, and Compliance

  • Own client security questionnaires end to end; build and maintain a reusable answer library to make each response faster and more consistent
  • Conduct vendor security assessments for new vendors and renewals; maintain ongoing vendor risk tracking
  • Run SOC 2 compliance operations, including evidence collection, control monitoring, and audit support
  • Maintain the risk register: track remediation owners and progress, and prepare quarterly risk reviews
  • Drive the policy lifecycle: annual reviews, redline recommendations, and exception tracking
  • Support review of client contractual security obligations in partnership with our contracts administration team
  • Support data privacy compliance operations (CCPA, GDPR, etc.), including data inventory and mapping, subprocessor tracking, and data subject request support

AI Governance and Enablement

  • Operate the AI tool and vendor intake process: triage requests, run security and risk reviews, and document decisions
  • Conduct AI risk assessments using our risk methodology - threat modeling, control analysis, and risk scenarios - and help mature it into a repeatable framework
  • Build and maintain our AI inventory of approved tools, agents, and connectors; monitor for unapproved AI use
  • Maintain AI usage policies and standards, and manage the exception process
  • Support access reviews for AI agents and connectors, including what data non-human identities can reach
  • Deliver secure-AI enablement: training, office hours, and onboarding users to approved tools
  • Track the evolving AI regulatory and framework landscape (EU AI Act, NIST AI RMF, OWASP GenAI Security) and the AI governance sections appearing in client questionnaires

Security Awareness and Training

  • Manage the security awareness training program, including content updates, completion tracking, and new-hire onboarding
  • Run phishing simulation campaigns, reporting, and follow-up coaching
  • Own security communications and the intake channel for employee security questions

Identity and Access Governance

  • Coordinate and execute periodic user access reviews and validate offboarding completion
  • Review third-party application and OAuth grants across M365 and Google environments

Reporting and Security Operations Support

  • Build and maintain security metrics and dashboards covering operational trends, compliance posture, and training completion; support leadership reporting
  • Produce periodic threat intelligence digests for the team
  • Depending on experience and interest, support security alert triage, incident documentation, and tabletop exercise coordination
  • Support business continuity and disaster recovery plan maintenance and test coordination

Skills and Qualifications

  • Two-year or four-year degree in information security, information technology, business, or related field; or 3+ years of equivalent experience
  • 2-5 years of experience in a security analyst, GRC, IT audit, compliance, or similar role title and level will be commensurate with experience
  • Working knowledge of security and compliance frameworks such as SOC 2, NIST CSF, or ISO 27001
  • Experience responding to security questionnaires, conducting vendor assessments, or supporting audits
  • Familiarity with data privacy regulations (CCPA, GDPR, etc.)
  • Hands-on experience using generative AI tools, and a strong interest in AI governance and safe adoption
  • Excellent written communication - much of this work is turning technical reality into clear, accurate answers
  • Strong organization and attention to detail, with the ability to manage many parallel workstreams
  • Ability to work effectively with technical and non-technical stakeholders across the business

Preferred Qualifications

  • Certifications such as Security+, CISA, CRISC, or CIPP
  • Experience with compliance automation platforms (Vanta, Drata, or similar)
  • Familiarity with AI governance frameworks (NIST AI RMF, ISO/IEC 42001, OWASP GenAI Security)
  • Exposure to security operations tooling (SIEM, EDR) and alert triage
  • Experience with M365 and Google Workspace administration or security configuration
  • Basic scripting skills (Python or similar) for reporting and automation
  • Experience working with personal information or other regulated data

Pay Transparency

At Ovative, we offer a transparent view into three core components of your total

compensation package: Base Salary, Annual Bonus, and Benefits. The salary range for this position below is inclusive of an annual bonus. Actual offers are made with consideration for relevant experience and anticipated impact. Additional benefits information is provided below.

For our senior security analyst positions, our compensation ranges from $90,000 to $132,000, which is inclusive of a 20% bonus.

Working at Ovative Group:

We provide strong, competitive, holistic benefits that understand the importance of your life inside and out of work.

At Ovative, culture isn’t a buzzword-it’s the reason we’ve been named a Top Workplace for ten years running. We lead with trust, transparency, and a commitment to doing the hard work others avoid.

We offer flexibility. You'll work from our Minneapolis, Chicago, or New York office on set days each week, and an option to work remote on others.

Our open floor plan reflects our open communication and flat structure-where interns collaborate with VPs, analysts partner with senior leaders, and our CEO engages with every team member. Together, we create an environment where smart, driven people can do their best work and support one another in the process.

We’re equally committed to inclusion and belonging. Ovative fosters a workplace where everyone can participate and thrive-regardless of ethnicity, gender, sexual orientation, gender identity, or expression or other protected class status. Our benefits and policies reflect that commitment, from inclusive medical leave coverage for same-sex spouses to equitable care and support for all families.

Benefits:

We strive to hire and retain the best talent by offering fair, competitive compensation, a meaningful bonus program, and excellent health coverage. When the company performs well, we all benefit.

Some tangible benefits and amenities we enjoy:

  • Access to all office spaces in MSP, NYC, and CHI
  • Frequent, paid travel to our Minneapolis headquarters for company events, team events, and in-person collaboration with teams
  • Generous paid vacation policy
  • 401k match program
  • Top-notch health insurance options, inclusive of same sex partners
  • Family formation benefits including reimbursement options for fertility, pregnancy, and parenting needs
  • Monthly stipend for your mobile phone and data plan
  • Sabbatical program
  • Charitable giving via our time and a financial match program
  • Shenanigan’s Day

Additional information can be found at Ovative's Career Page.

The details of the benefits are covered by applicable plan documents for group benefits and by company policies where a plan document does not apply.

Working at Ovative won’t be easy-but if you like challenging, hard work, driving results, and being surrounded by the best talent, it has the potential to be the most rewarding job you’ll ever have. If you think you can make us better, we want to hear from you!

EEO & Accessibility:

Ovative is an Equal Opportunity Employer committed to a respectful, inclusive workplace for all. Applicants receive consideration without regard to legally protected characteristics (e.g., color, religion, creed, national origin, sex, pregnancy, childbirth and related conditions, sexual orientation, gender identity/, gender expression, gender identity, age, physical or mental disability, marital/ status, familial status, military or veteran’s status, genetic information, status with regard to public assistance, and any other status protected under applicable law).

We provide reasonable accommodations consistent with the Americans with Disabilities Act and applicable state law to qualified applicants and employees with disability, unless doing so would create an undue hardship.

If you need assistance or accommodation at any stage of the application or interview process due to a disability, please contact us at [email protected].

Application Details and Process:

Applicants must be legally authorized to work in the United States for any employer on a full-time basis, without current or future need for visa sponsorship. Ovative is unable to sponsor or take over sponsorship of an employment visa for this position. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification documentation upon hire.

Open Until Filled or Otherwise Withdrawn:

We encourage interested candidates to apply early. The position will remain open for at least 10 business days from the first day of posting. After this time, if the position has not been filled, the posting will remain open until the position is filled, or until the posting is otherwise closed or withdrawn for business reasons.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
994,162 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Minneapolis
$125k – $150k per year • Equity • Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Minneapolis
Python
PowerShell
DevOps
Ansible
VMWare
Azure
Windows Server
AWS
Cybersecurity
ISO 27001
SOC 2
Active Directory
SIEM
Apply
$210k per year • Hybrid • 10+ years exp • Orlando
DevOps
GCP
Azure
AWS
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
HIPAA
Zero Trust
Apply
≈ $118k – $250k per year (Estimated) • Hybrid • 7+ years exp • Bachelor's Degree • Charlotte
AI/ML
LLM
DevOps
GCP
Azure
Cybersecurity
ISO 27001
NIST CSF
SOC 2
Apply
$160k – $235k per year • In office • TS/SCI • Contractor • 8+ years exp • Bachelor's Degree • Denver
Python
Rust
Elixir
DevOps
GCP
Azure
AWS
Cybersecurity
SIEM
Apply
≈ $152k – $316k per year (Estimated) • In office • Full-Time • New York
AI/ML
AI Agents
LLM
Cybersecurity
SOC 2
Threat Modeling
Apply
≈ $144k – $317k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Los Angeles
Cybersecurity
SOC 2
GDPR
HIPAA
Apply
≈ $155k – $342k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • New York
Cybersecurity
SOC 2
GDPR
HIPAA
Apply
≈ $134k – $296k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Chicago
Cybersecurity
SOC 2
GDPR
HIPAA
Apply
≈ $140k – $310k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Washington
Cybersecurity
SOC 2
GDPR
HIPAA
Apply
≈ $145k – $320k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • San Diego
Cybersecurity
SOC 2
GDPR
HIPAA
Apply
$90k – $132k per year • In office • Full-Time • 6+ years exp • Minneapolis • New York
Marketing
YouTube
Apply
Product Owner, AI 7 days ago
$90k – $132k per year • In office • Full-Time • 5+ years exp • Minneapolis • Chicago • New York
Databases
Databricks
Google BigQuery
BigQuery
AI/ML
Model Context Protocol
Function Calling
AI Agents
Human-in-the-Loop
Tool Use
Mobile
MVP
Cybersecurity
SOC 2
Management
Confluence
Jira
Agile
Scrum
Apply
$90k – $132k per year • In office • Full-Time • 5+ years exp • Minneapolis • Chicago • New York
Apply
Engineering Manager 9 days ago
$90k – $132k per year • In office • Full-Time • 5+ years exp • Minneapolis • Chicago • New York
Databases
Snowflake
Databricks
Google BigQuery
BigQuery
AI/ML
Dagster
dbt
AI Agents
LLM Guardrails
Cybersecurity
SOC 2
Management
Agile
Apply
$90k – $132k per year • In office • Full-Time • 5+ years exp • Minneapolis • Chicago • New York
Apply
Software Engineer 1 day ago
$79k – $131k per year • Remote (United States) • Full-Time • 3+ years exp • Bachelor's Degree • Omaha • Minneapolis
Python
Java
SQL
Java
Spring Boot
Databases
Amazon Redshift
DevOps
CI/CD
AWS
Docker
Kubernetes
AWS Lambda
GitLab
Amazon S3
Amazon EventBridge
API Gateway
Cybersecurity
OWASP
Management
Agile
Apply
$50k – $70k per year • In office • Full-Time • 4+ years exp • High School Diploma • Minneapolis
DevOps
TCP/IP
Apply
$86k – $105k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Minneapolis
Apply
$76k – $102k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Minneapolis • Denver • Columbus
Management
Microsoft Office
Apply
$82k – $109k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Minneapolis
Apply
See all jobs
This is one of many
994,162 more open roles from verified company boards, updated every day.