Overview
Associate Security Analyst Jobs in Eagan, MN at Insight Global
Title: Associate Security Analyst
Company: Insight Global
Location: Eagan, MN
Required Skills & Experience
• Degree, certification, or equivalent practical experience in cybersecurity, information security, IT, risk management, or a related field.
• Basic knowledge of information security, third-party risk, and cloud services.
• Ability to review vendor security evidence, assess sufficiency, and identify follow-up needs.
• Clear written and verbal communication skills.
• Strong organizational skills, attention to detail, and time management.
• Working knowledge of core security concepts such as access management, vulnerability management, incident response, encryption, and network security.
• Proficiency with Microsoft Office applications.
Nice to Have Skills & Experience
• Internship, academic, or early career experience in cybersecurity, governance, risk, compliance, vendor risk management, or reviewing third-party security evidence.
• Exposure to cloud technologies and shared responsibility models.
• Familiarity with SOC 2 and other common vendor assurance documentation, as well as frameworks such as NIST or CIS Controls.
• Understanding of third-party due diligence, contract review support, or procurement-related processes.
• Relevant entry-level certification, such as CompTIA Security+, ISC2 Certified in Cybersecurity, or similar.
Job Description
The Associate Security Analyst – Cloud Vendor Risk Management supports security assessments of third-party cloud vendors within the Digital Security function. This role helps maintain and improve vendor risk management processes, with a strong focus on reviewing vendor security documentation, determining whether submitted evidence is sufficient, and supporting risk-based assessments for both prospective and existing providers. The ideal candidate is detail-oriented, analytical, and comfortable evaluating technical and compliance materials such as SOC 2 reports, ISAE 3402 reports, third-party penetration test reports, network documentation, and architecture diagrams.
Key Responsibilities
• Support the documentation, maintenance, and continuous improvement of Digital Security vendor management processes.
• Review vendor security evidence, with a primary focus on SOC 2 Type 2 reports and related assurance documentation, including ISAE 3402 reports, third-party penetration test reports, network documentation, and architecture diagrams.
• Analyze vendor evidence to assess sufficiency and identify control gaps, exceptions, and follow-up items based on established review criteria and internal standards.
• Document assessment results and communicate findings to security, procurement, legal, and business stakeholders.
• Track evidence requests, remediation items, and review status, and support follow-up with vendors on missing, incomplete, or clarifying documentation.
• Partner with senior analysts and cross-functional teams to support onboarding and ongoing monitoring of cloud vendors.
• Maintain review templates, procedures, and supporting documentation to improve consistency and efficiency.
• Escalate higher-risk issues, insufficient evidence, or unresolved documentation gaps, as appropriate.
• Support reporting, metrics, and audit-ready documentation related to third-party security reviews.
• Maintain awareness of evolving third-party risk and cloud security practices.