JobsRegal Rexnord

IT Security Analyst II

Regal Rexnord · Grafton, WI

Posted Sep 9, 2026 · We last checked this listing on Sep 20, 2026

Apply at Regal Rexnord

Likely interview questions for this role

Written from this job description, not a generic list. Each one notes what the interviewer is really checking.

Behavioral

Tell me about a time you had to chase down evidence for an audit and someone was slow to respond. What did you do?

persistence and diplomacy when driving compliance work across teams that don't report to them

Describe a situation where you had to explain a technical or compliance risk to someone in Legal or Procurement who didn't have a security background.

communication skill translating risk into business language for non-technical stakeholders

Tell me about a vendor risk assessment where you found something concerning. How did you score it and what happened next?

whether they've actually run the third-party risk lifecycle end to end, not just read about it

How do you keep yourself current on AI security and governance developments given how fast that space is moving?

genuine intellectual curiosity and self-directed learning habits versus passive interest

Tell me about a time your attention to detail caught something in documentation that others had missed.

concrete evidence of the detail-orientation the role explicitly requires for evidence and artifact review

Technical

Walk me through how you'd map a control from a framework like NIST or SOC 2 to an actual business process and collect the evidence to prove it's working.

whether the candidate understands control mapping and evidence collection beyond just knowing framework names

How would you evaluate a vendor's SOC 2 report or security questionnaire response to decide if there's a real gap versus just a documentation issue?

ability to read and interpret third-party assurance documents critically rather than checkbox them

What's your process for tracking remediation items so nothing falls through the cracks between when a gap is found and when it's closed?

organizational rigor and familiarity with issue tracking in a GRC context

Have you worked with NIST 800-171 or CMMC requirements before? Walk me through a control area you're familiar with.

actual depth of exposure to the specific frameworks named in the posting versus surface familiarity

Describe how you'd build a simple dashboard or report to show leadership the status of open audit findings and third-party risks.

ability to turn raw compliance data into something decision-makers can actually use

Situational

Say a business unit wants to roll out a new AI tool that connects to your internal data. What questions would you ask before giving it a green light?

practical grasp of AI risk factors like data exposure, access control, and third-party dependency, not just buzzwords

If you found out a business team had already started using a third-party AI tool without going through security review, what would you do first?

judgment on escalation versus collaboration when discovering shadow IT or ungoverned AI use

If two stakeholders disagree on how urgent a compliance gap is, one says it's critical and one says it can wait a quarter, how do you sort that out?

ability to prioritize risk objectively and manage competing stakeholder opinions without just picking a side

Practice this interview out loud.

Offer builds a real interview for this exact role at Regal Rexnord from your resume and this job description, asks the questions one at a time, and tells you what landed. The first one is free.

Practice this out loud

The full job description

As published by Regal Rexnord.

Work Model: Work Model: You’ll work in a hybrid model, onsite at your designated Regal Rexnord location at least 3 days per week (Monday–Thursday), with flexibility to work remotely up to 2 days, including Friday. ____________________ Position: IT Security Analyst II Location: Grafton, Wisconsin Remote Type: Hybrid Reports To: Senior Manager, Cybersecurity Compliance, Data Privacy & AI Governance We are   seeking   a motivated and detail-oriented IT Security Analyst II to support the organization’s   AI   governance,   IT compliance and   security, and third-party risk management programs. This mid-level role will help translate security, privacy, regulatory, contractual, and  AI governance   requirements into practical controls   including   risk assessments,   evidence   collection   and remediation plans. The analyst will partner  with IT   infrastructure, PMO , Legal, Privacy, Procurement, business stakeholders, and third-party vendors to strengthen the organization’s security posture, improve audit readiness, and support responsible and secure adoption of AI-enabled technologies.   Key Responsibilities   IT Security Compliance   and Governance   • Support day-to-day   operation   of the IT security compliance program, including control documentation, evidence collection, audit readiness, and remediation tracking.   • Assist   with control mappings and compliance activities across applicable frameworks, standards, laws, and contractual requirements such as NIST,   CMMC , SOC 2, data protection requirements, and internal policies.   • Partner with security, IT, privacy, legal, and business stakeholders to interpret compliance requirements and translate them into actionable control activities.   • Maintain compliance records, control narratives, risk registers, policies, procedures, and supporting documentation.   • Track compliance gaps, audit findings, exceptions, risks, and remediation plans to ensure   timely   closure and   appropriate escalation .   AI Security and Responsible AI Governance   • Research and keep apprised for latest updates   in   AI trends and AI Security.   • Support security and governance reviews for AI-enabled tools, platforms, models, and use cases to help ensure responsible, compliant, and secure adoption.   • Assist   in   maintaining   AI security documentation, including inventories, risk assessments, control evidence, usage guidelines, data handling requirements, and   approval   records.   • Evaluate AI-related risks such as sensitive data exposure, unauthorized use, third-party AI dependencies, model access controls, prompt and output handling, and operational misuse.   • Collaborate with security, privacy, legal, data, product, and technology teams to assess AI use cases against internal policies and emerging AI governance expectations.   • Monitor AI security and governance findings and coordinate remediation activities with accountable owners.   Third-Party Risk Management   • Support the third-party risk management lifecycle, including vendor intake, inherent risk reviews, due diligence questionnaires, security assessments, reassessments, and offboarding activities.   • Review supplier security documentation, certifications, audit reports, data protection materials, and responses to security questionnaires to   identify   risks and control gaps.   • Assist with vendor risk scoring, issue tracking, exception documentation, and remediation follow-up to ensure third-party risks are appropriately managed.   • Partner with Procurement, Legal, Privacy, Security, IT, and business owners to support contract reviews, data protection requirements, and security obligations.   • Pay special attention to third-party AI tools and services, including reviewing AI-related data handling, access controls,   sub processors , model usage, and compliance requirements.   Risk Reporting, Process Improvement, and Stakeholder Support   • Prepare clear,   accurate   reports, dashboards, and summaries that communicate compliance status, AI security risks, third-party risk posture, remediation progress, and key trends.   • Support internal and external audits by coordinating evidence requests,   validating   control implementation, and tracking follow-up actions.   • Contribute to continuous improvement of GRC processes, security workflows, vendor review procedures, AI governance practices, and reporting standards.   • Assist   with security awareness, policy communications, and guidance for business teams related to compliance, AI security, and third-party risk expectations.   • Maintain awareness of cybersecurity, compliance, AI governance, privacy, and third-party risk trends and recommend practical improvements to the program.   Qualifications   • Associate's Degree (or equivalent experience) with 3-4 years of relevant experience in cybersecurity, IT audit, IT security compliance, governance, risk management, third-party risk management, privacy, or a related function required. • Bachelor's Degree preferred. • Working knowledge of cybersecurity governance, compliance, and risk management concepts, including security control frameworks and audit readiness practices.   • F amiliarity with one or more frameworks or standards such as NIST, ISO 27001, SOC 2, CIS Controls, PCI DSS, or similar control environments.   NIST 800-171 or CMMC knowledge is a plus.   • Exposure to AI security, responsible AI governance, data protection, model or tool risk assessments, or emerging AI regulatory requirements preferred.   • Experience supporting third-party risk assessments, vendor security reviews, security questionnaires, contract security reviews, or supplier remediation tracking preferred.   • Ability to collect, organize,   validate , and document audit evidence and compliance artifacts with strong attention to detail.   • Strong analytical, problem-solving, written communication, and stakeholder-management skills.   • Ability to work collaboratively across technical and non-technical teams and communicate risk in clear, business-oriented language.   • Relevant certifications such as Security+,   CySA +, CISA, CRISC, CGRC, CISSP Associate, ISO 27001, or other security, audit, risk, or compliance certifications preferred.   NOT OFFERING SPONSORSHIP: Candidates must be eligible to work in the United States without requiring company sponsorship to obtain or keep U.S. work authorization.   #LI-Hybrid #LI-AB-1 Benefits • Medical, Dental, Vision and Prescription Drug Coverage • Spending accounts (HSA, Health Care FSA and Dependent Care FSA) • Paid Time Off and Holidays • 401k Retirement Plan with Matching Employer Contributions • Life and Accidental Death & Dismemberment (AD&D) Insurance • Paid Leaves • Tuition Assistance About Regal Rexnord Regal Rexnord is a publicly held global industrial manufacturer with 30,000 associates around the world who help create a better tomorrow by providing sustainable solutions that power, transmit and control motion. The Company’s electric motors and air moving subsystems provide the power to create motion. A portfolio of highly engineered power transmission components and subsystems efficiently transmits motion to power industrial applications. The Company’s automation offering, comprised of controls, actuators, drives, and precision motors, controls motion in applications ranging from factory automation to precision control in surgical tools. The Company’s end markets benefit from meaningful secular demand tailwinds, and include factory automation, food & beverage, aerospace, medical, data center, warehouse, alternative energy, residential and commercial buildings, general industrial, construction, metals and mining, and agriculture. Regal Rexnord is comprised of three operating segments: Industrial Powertrain Solutions, Power Efficiency Solutions, and Automation & Motion Control. Regal Rexnord has offices and manufacturing, sales and service facilities worldwide. For more information, including a copy of our Sustainability Report, visit RegalRexnord.com. Equal Employment Opportunity Statement Regal Rexnord is an Equal Opportunity and Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex/gender, sexual orientation, gender identity, pregnancy, age, ancestry, national origin, genetic information, marital status, citizenship status (unless required by the applicable law or government contract), disability or protected veteran status or any other status or characteristic protected by law. Regal Rexnord is committed to a diverse and inclusive workforce. We are committed to building a team that represents diverse and inclusive backgrounds, perspectives, and skills.  If you’d like to view a copy of the company’s affirmative action plan for protected veterans/individuals with disabilities or policy statement, please email Recruiting@RegalRexnord.com. If you have a disability and you believe you need a reasonable accommodation in order to search for a job opening or to submit an online application, please e-mail Recruiting@RegalRexnord.com. Equal Employment Opportunity Posters Notification to Agencies : Please note that Regal Rexnord Corporation and its affiliates and subsidiaries ("Regal Rexnord") do not accept unsolicited resumes or calls from third-party recruiters or employment agencies. In the absence of a signed Master Service Agreement or similar contract and approval from HR to submit resumes for a specific requisition, Regal Rexnord will not consider or approve payment to any third-parties for hires made.

Apply at Regal Rexnord

Related jobs

Digital Marketing Summer Intern

Regal Rexnord · Milwaukee, WI

Posted Sep 17 · Verified Sep 20

Machinist - 1st Shift Turning

Regal Rexnord · Union Grove, WI

Posted Sep 17 · Verified Sep 20

EHS Summer Intern

Regal Rexnord · Milwaukee, WI

Posted Sep 17 · Verified Sep 20

Machinist - 2nd Shift Turning

Regal Rexnord · Union Grove, WI

Posted Sep 17 · Verified Sep 20

Machinist - 1st Shift Chucking

Regal Rexnord · Union Grove, WI

Posted Sep 17 · Verified Sep 20

Assembler C

Regal Rexnord · Union Grove, WI

Posted Sep 17 · Verified Sep 20