Cyber & Information Security team is seeking a Third-Party Security Analyst. Reporting to the Director of Cyber & Information Security, the analyst will perform third-party security assessments. You will work with a team of professional Security Analysts leveraging Next-Gen security tools to perform the full lifecycle of third-party reviews from onboarding to real-time monitoring of vendors and suppliers.
Total Experience – 4 to 6 years
Responsibilities, Functions and Duties
- Conduct technical security assessments of third-party vendors, suppliers, and partners by reviewing their security controls, adherence to regulations, compliance, and contracts.
- Analyze third-party security assessment findings and document security risks within the management software for tracking of risk reporting.
- Coordinate with various stakeholders to verify and remediate security risk findings.
- Develop KRIs and KPIs around third-party risk assessments and the remediation of key findings.
- Develop, update, and publish policies and standard operating procedures for third-party risk management.
- Continuously monitor for active vulnerabilities and cyber events against our vendors and suppliers.
- Participate in third-party cyber incident response by reaching out to impacted vendors and tracking remediation.
Requirements
Knowledge and Requirements
- Previous experience performing technical security audits or third-party assessments.
- Understanding of current cyber vulnerabilities & threats.
- Knowledge of security assessments (SOC reports, ISO/NIST, vulnerability and pen testing assessments).
- Fundamental understanding of system and network security principles and technology.
- Ability to interface with a wide audience of technical and non-technical personnel.
- Ability to prioritize and manage workloads and deadlines.
- Excellent written and verbal communication skills.
- Self-starter who is motivated and driven to learn.
Preferred Qualifications
- Prior experience and/or certifications in AWS, Azure, and/or GCP.
- Experience in performing third-party assessments of SaaS providers and vendors operating in cloud environments.
- Any security-focused certifications.
- 3-5 years of cybersecurity-related experience.
Additional Details
- Seniority level: Not Applicable
- Employment type: Full-time
- Job function: Information Technology
- Industries: IT Services and IT Consulting