Role: This role supports the Information Security Director and the Governance, Risk and Compliance (GRC) function in maintaining a strong control environment, advancing risk and compliance activities, and building foundational security skills. The intern gains hands-on exposure to vendor risk management, policy governance, audit and exam support, and business continuity while helping the team operate efficiently.
Job Type: Part time, on-site at our administrative office in St. Paul, MN. Interns will work 15–20 hours per week during the academic year. Weekly hours are determined by departmental needs, with flexibility provided to accommodate academic schedules.
Major Duties and Responsibilities
- Assist with vendor risk management activities, including intake, due diligence, collection of SOC 2 reports, and tracking of vendor tier classifications
- Support the review and organization of security policies, standards, and procedures, including formatting, version control, and redline preparation
- Help gather and organize audit and examiner artifacts for internal audits, NCUA exams, and third-party assessments
- Maintain risk registers, control libraries, and compliance trackers to keep records current and accurate
- Support business continuity management (BCM) activities, including department intake, business impact analysis data entry, and plan documentation
- Assist with control testing and evidence collection to validate that security controls are operating as intended
- Research regulatory requirements and industry frameworks (e.g., NIST CSF, GLBA, FFIEC) and summarize findings for the team
- Track open risk and remediation items and follow up with owners on status
- Support routine GRC operations such as tracking security awareness metrics and maintaining shared documentation
Other Duties
- Participate in business continuity, incident management, and recovery planning and exercise efforts
- Comply with applicable laws and regulations, including but not limited to the Bank Secrecy Act, the Patriot Act, and the Office of Foreign Assets Control
- Exhibit Blaze’s Core Values: Better Lives, Thoughtfully Compassionate, Minnesota’s Best, and Give Back
- Perform other duties as assigned to support effective department operation
Job Requirements
Experience/Education/Certifications/Licenses
- Minimum High School degree or equivalent
- Currently pursuing an Associate’s or Bachelor’s degree in Information Security, Information Technology, Business, Risk Management, or a related field; recent graduates also considered
- Coursework, projects, or prior experience related to information security, risk, compliance, or IT is preferred
- Interest in pursuing security or compliance certifications (e.g., CompTIA Security+, ISACA CRISC, or similar) is a plus
Demonstrated Knowledge
- Familiarity with basic information security, risk, and compliance concepts
- General awareness of data privacy and financial regulations such as GLBA, GDPR, CCPA and CPRA is a plus
- Proficiency with Microsoft Office (Word, Excel, PowerPoint, Outlook); exposure to collaboration and GRC tools is a plus
- Strong attention to detail; high level of honesty and integrity
- Ability to handle multiple tasks simultaneously, take initiative and be proactive
- Willingness to learn, ask questions, and follow documented processes
Communication Skills
Ability to communicate clearly and professionally with staff across the organization; willingness to document processes and develop written materials that draw from information in the field, whether working independently or as part of a team
Physical Requirements
Ability to sit and stand; answer calls; operate a computer; interact with internal staff and the public on the phone; travel to designated offices; lift up to 20 lbs.
Diversity creates a healthier atmosphere, and we encourage diverse applicant depth and breadth. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law.
We are committed to providing salary information for all open positions. Compensation for this position is $21.00/hour.