Jobs and Careers
NI

Senior Information Security Analyst

Nike
United StatescontractVerifiedPosted 2 Jul 2026

About the role

Title: Senior Information Security Analyst

Location: Beaverton, OR | Open to Remote, US

Duration: 7 months contract

NIKE, Inc. does more than outfit the world's best athletes. It is a place to explore potential, obliterate boundaries and push out the edges of what can be. The company looks for people who can grow, think, dream and create. Its culture thrives by embracing diversity and rewarding imagination. The brand seeks achievers, leaders and visionaries. At Nike, it’s about each person bringing skills and passion to a challenging and constantly evolving game.

NIKE is a technology company. From our flagship website and five-star mobile apps to developing products, managing big data and providing leading edge engineering and systems support, our teams at NIKE Global Technology exist to revolutionize the future at the confluence of tech and sport. We invest and develop advances in technology and employ the most creative people in the world, and then give them the support to constantly innovate, iterate and serve consumers more directly and personally. Our teams are innovative, diverse, multidisciplinary and collaborative, taking technology into the future and bringing the world with it.

WHO ARE WE LOOKING FOR?

We're looking for a Senior Information Security Analyst to join the Information Risk Management (IRM) team within Corporate Information Security (CIS). This role will deliver against an information security and cybersecurity assessment plan integrated into a broader enterprise risk management program supported by executive management.

You will leverage your knowledge of security policies, standards, controls, and industry best practices to perform risk assessments of Nike systems and systems managed for Nike by vendors. Our ideal candidate has superb communication skills, strong analytical and problem-solving ability, intellectual curiosity, and experience translating complex security risks for both technical and non-technical audiences.

WHAT YOU WILL WORK ON?

This role works with the Information Risk Management team to identify, assess, and elevate visibility to information security risks across Nike's technology landscape. Key responsibilities include:

Vendor Information Risk Assessments

  • Perform formal risk assessments on partner and vendor connections, evaluating vendor processes at the point of engagement with Nike.
  • Ensure sufficient validation of data sharing arrangements and agreements to protect Nike's sensitive information.
  • Confirm business objectives align with the type and volume of data used, maintaining a "need to know/use" mindset.
  • Review third-party SOC reports and vendor security documentation as part of assessment activities.
  • Help establish risk and remediation ownership for identified vendor-related risks and document findings in the Risk Register.

Security Controls Baseline Assessments

  • Assess moderately complex platforms and systems against Nike security and configuration standards.
  • Evaluate and process exceptions to information security policies and standards.
  • Perform compliance control validation testing to determine the operating effectiveness of IT controls for scoped systems.
  • Consult with technology units on IT general controls (ITGCs) and compliance matters.
  • Champion information security policies, standards, controls, and processes so compliance requirements are addressed as part of business-as-usual operations.

Internal Risk Assessments

  • Identify, document, and elevate visibility to information risk where business direction creates potential exposure to employee, athlete, and product sensitive data streams.
  • Identify and profile Nike systems and processes that require risk assessments; scope specific assessments accordingly.
  • Perform detailed analysis of threats and vulnerabilities across information security domains including network security, asset security, security engineering, identity and access management, security operations, and software development security.
  • Review key system configurations and complex IT infrastructures (e.g., cloud services).
  • Communicate effectively through risk reports, presentations, and stakeholder interactions to drive remediation of identified risks.

Data Analysis and Other Projects

  • Support vendor risk management metrics, reporting, and master data stewardship to improve accuracy, timeliness, and completeness.
  • Provide analysis and insights into data supporting the effectiveness of technical and process-based cybersecurity controls.
  • Collaborate on process improvements for data retrieval, analysis, and risk assessment intake.
  • Contribute to IRM team projects and strategic initiatives as assigned, including documentation in Serv

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Nike

View company profile →