Senior Third-Party Risk Management Analyst
New
J
JobgetherCybersecurity risk
Based in United StatesFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years of professional experience in cybersecurity, third-party risk management, risk management, audit, compliance, or a closely related discipline.
- Required Skills
- AWSGCPAzure
Requirements
- 5+ years of professional experience in cybersecurity, third-party risk management, risk management, audit, compliance, or a closely related discipline.
- Strong knowledge of regulatory and compliance requirements, including PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST.
- Experience evaluating legacy environments and cloud technologies, including AWS, GCP, and Azure.
- Understanding of APIs, application security, encryption, endpoint security, and network security concepts.
- Familiarity with SIEM, intrusion detection systems, log management, vulnerability management, and threat intelligence.
- Ability to assess vendor controls, map controls to security frameworks, identify gaps, and communicate risk to technical and non-technical stakeholders.
- Experience supporting SOC 2 Type II and PCI DSS audits is highly valuable.
- Familiarity with eGRC or ITGRC platforms such as Jira Service Management GRC, Archer, OneTrust, or LogicGate is preferred.
- Professional certifications such as CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP are desirable.
- Able to manage multiple vendor assessments and compliance activities simultaneously and collaborate across stakeholder teams.
- Able to work remotely and independently while maintaining collaboration and accountability.
Responsibilities
- Maintain the inventory of third-party providers, applications, and services from onboarding through termination.
- Lead vendor cybersecurity assessments with cybersecurity, legal, procurement, and business stakeholders.
- Evaluate vendor maturity against frameworks and requirements including NIST CSF, CIS, CMMC, GDPR, PCI DSS, and SOC 2.
- Review vendor service-level agreements, RPO/RTO commitments, breach notification requirements, cybersecurity insurance, and other risk-related obligations.
- Document assessment findings, recommendations, remediation plans, exceptions, and compensating controls, and track risks through resolution.
- Support internal and external audits by providing evidence and validating third-party controls.
- Maintain audit-ready policies, standards, procedures, risk treatment plans, and supporting documentation.
- Coordinate client vulnerability notifications with Threat & Vulnerability Management teams.
- Advise clients and internal stakeholders on risk impact, remediation expectations, and cybersecurity practices.
- Support control selection, cybersecurity metrics, vendor resilience planning, and continuous improvement of the information security management system.
View Full Description & ApplyYou'll be redirected to the employer's site