Senior Third-Party Risk Management Analyst

New
J
JobgetherCybersecurity risk
Based in United StatesFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
5+ years of professional experience in cybersecurity, third-party risk management, risk management, audit, compliance, or a closely related discipline.
Required Skills
AWSGCPAzure

Requirements

  • 5+ years of professional experience in cybersecurity, third-party risk management, risk management, audit, compliance, or a closely related discipline.
  • Strong knowledge of regulatory and compliance requirements, including PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST.
  • Experience evaluating legacy environments and cloud technologies, including AWS, GCP, and Azure.
  • Understanding of APIs, application security, encryption, endpoint security, and network security concepts.
  • Familiarity with SIEM, intrusion detection systems, log management, vulnerability management, and threat intelligence.
  • Ability to assess vendor controls, map controls to security frameworks, identify gaps, and communicate risk to technical and non-technical stakeholders.
  • Experience supporting SOC 2 Type II and PCI DSS audits is highly valuable.
  • Familiarity with eGRC or ITGRC platforms such as Jira Service Management GRC, Archer, OneTrust, or LogicGate is preferred.
  • Professional certifications such as CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP are desirable.
  • Able to manage multiple vendor assessments and compliance activities simultaneously and collaborate across stakeholder teams.
  • Able to work remotely and independently while maintaining collaboration and accountability.

Responsibilities

  • Maintain the inventory of third-party providers, applications, and services from onboarding through termination.
  • Lead vendor cybersecurity assessments with cybersecurity, legal, procurement, and business stakeholders.
  • Evaluate vendor maturity against frameworks and requirements including NIST CSF, CIS, CMMC, GDPR, PCI DSS, and SOC 2.
  • Review vendor service-level agreements, RPO/RTO commitments, breach notification requirements, cybersecurity insurance, and other risk-related obligations.
  • Document assessment findings, recommendations, remediation plans, exceptions, and compensating controls, and track risks through resolution.
  • Support internal and external audits by providing evidence and validating third-party controls.
  • Maintain audit-ready policies, standards, procedures, risk treatment plans, and supporting documentation.
  • Coordinate client vulnerability notifications with Threat & Vulnerability Management teams.
  • Advise clients and internal stakeholders on risk impact, remediation expectations, and cybersecurity practices.
  • Support control selection, cybersecurity metrics, vendor resilience planning, and continuous improvement of the information security management system.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now