Job Description
Job Title:  Security Analyst (IT Risk)
Requisition Number:  12304
Posting Start Date:  9/30/26

Our values start with our people, join a team that values you!

Bring your talents to Ross, our leading off-price retail chain with over 2,200 stores, and a strong track record of success and growth. Our focus has always been bringing our customers a constant stream of high-quality brands and on-trend merchandise at extraordinary savings. All while providing a fun and exciting treasure hunt experience.

As part of our team, you will experience:

  • Success. Our winning team pursues excellence while learning and evolving
  • Career growth. We develop industry leading talent because Ross grows when our people grow<
  • Teamwork. We work together to solve the hard problems and find the right solution
  • Our commitment to Diversity, Equality & Inclusion, and our community. We celebrate the backgrounds, identities, and ideas of those who work and shop with us because our differences make us stronger. We strive to be a positive force in our community.


Our Corporate headquarters are in Dublin, CA, we have 3 buying offices in key markets in New York City, Los Angeles, and Boston, and 8 distribution centers nationwide. With 2025 revenues of $22.8 billion, we are a Fortune 500 company who is committed to providing an inclusive work environment with continuous learning opportunities and development for our teams.

Job Description: 

GENERAL PURPOSE

The Security Risk Analyst is responsible for executing IT risk management processes within Ross. This includes performing risk assessments, tracking mitigation efforts and developing risk metrics and risk reports.  This position is also responsible for executing security risk related projects and programs, such as monitoring DLP events, third-party risk assessments, updating security policies and procedures and executing security awareness programs.

ESSENTIAL FUNCTIONS

•    Performs risk assessments to identify current and future security vulnerabilities.
•    Performs Third Party risk assessment and related contracts agreements to ensure necessary security controls have been included as part of services and capabilities for the protection of organization assets
•    Provides support to IT during product and vendor selection process and provide subject matter expertise on Information security risk and compliance  
•    Maintains related IT Risk Management metrics and reporting. Collaborates with IT Compliance Manager, Secure SDLC Manager, Information Security, and IT groups to gather and analyze metrics. 
•    Maintains risk assessments related tools with the goal of improving efficiency, reducing costs, improving agility and optimizing information technology governance, risk, and controls management processes, while providing an overall view of the organization’s risk profile. 
•    Maintains Information security policies, standards and procedures
•    Maintains information security awareness programs, regularly conducting exercise to educate employees of the information security and best practices.
•    Monitors current and proposed laws, regulations, industry standards, and ethical requirements related to information security and privacy.

ESSENTIAL FUNCTIONS (cont.)

COMPETENCIES

Building Effective Teams
Collaboration
Leading by Example
Communicates Effectively
Ensures Accountability & Execution
Manages Conflict
Business Acumen
Plans, Aligns & Prioritizes
Organizational Agility

QUALIFICATIONS & SPECIAL SKILLS REQUIRED

•    Minimum 3 years of Information Technology Security, at least 1 with large enterprise organizations
•    Strong understanding of security governance, compliance and risk management principles.
•    Working knowledge of UNIX and Windows
•    Firewalls, VPN, PKI, IPS
•    Oracle, MS SQL
•    Virtualization Security
•    Proficient in Microsoft Word, Excel, PowerPoint
•    Excellent analytical, organizational and communication skills
•    Strong Project Management skills

EDUCATION / CERTIFICATIONS

Required
•    Bachelor’s degree or equivalent combination of education and relevant experience

Preferred
•    CISSP (Certified Information Systems Security Professional) Preferred
•    CRISC (Certified in Risk and Information Systems Control (CRISC) Preferred
•    CompTIA Security + Preferred

PHYSICAL REQUIREMENTS

Consistent timeliness and regular attendance
However, this role can perform duties effectively using a combination of in-office and remote work
Job requires ability to work in an office environment, primarily on a computer
Requires sitting, standing, walking, hearing, talking on the telephone, attending in-person meetings, typing, and working with paper/files, etc
This role requires regular in-office presence, including to engage in in-person team interaction, meetings and collaboration, client support, mentoring, coaching, and/or feedback
Vision requirements: Ability to see information in print and/or electronically

SUPERVISORY RESPONSIBILITIES

N/A

DISCLAIMER

This job description is a summary of the primary duties and responsibilities of the job and position. It is not intended to be a comprehensive or all-inclusive listing of duties and responsibilities. Contents are subject to change at management's discretion.

Ross is an equal employment opportunity employer. We consider individuals for employment or promotion according to their skills, abilities and experience. We believe that it is an essential part of the Company's overall commitment to attract, hire and develop a strong, talented and diverse workforce. Ross is committed to complying with all applicable laws prohibiting discrimination based on race, color, religious creed, age, national origin, ancestry, physical, mental or developmental disability, sex (which includes pregnancy, childbirth, breastfeeding and medical conditions related to pregnancy, childbirth or breastfeeding), veteran status, military status, marital or registered domestic partnership status, medical condition (including cancer or genetic characteristics), genetic information, gender, gender identity, gender expression, sexual orientation, as well as any other category protected by federal, state or local laws.

The base pay range for this role $92,400.00 to $148,500.00. The base pay range is dependent on factors including, but not limited to, experience, skills, qualifications, relevant education, certifications, seniority, and location. The range listed is just one component of the total compensation package for employees. Other rewards vary by position and location.