We're looking for a highly motivated, collaborative and technically experienced Third-Party Risk Analyst with ability to understand and apply the Vendor Risk Assessment (VRA) processes. The successful candidate must be reliable, resourceful and have a "can-do" attitude. You will be a key member of our team and play an important role in applying the Vendor Risk Assessment framework. In this role you will be required to demonstrate ability to analyze security risks, think out-of-box and provide pragmatic solutions and recommendations. The Third-Party Risk Analyst will be involved in driving this process forward and measuring Vendor Risk Assessment process compliance.
How You’ll Contribute
- Perform new and recurring third‑party risk assessments. Lead or assist with vendor risk assessment activities.
- Review of third‑party provided audit reports and supporting collateral (e.g., SOC reports, other certifications, or review of third‑party security whitepapers).
- Using platforms and/or ‘SIGs’ / ‘STIGs’ issue and review questionnaires completed by third parties describing their environment and controls.
- Collaborate with the Procurement Team and the other teams such as Security and Privacy.
- Work in a self‑directed, collaborative, and constructive manner with our internal stakeholders.
- Work with vendors to address any remediation activities required following completion of the assessment.
What Skills You’ll Bring
- Minimum of 2–3 years of hands‑on experience in IT Security and/or Governance, Risk, and Compliance (GRC), specifically in managing or evaluating security controls within an organization.
- Recent working experience with at least two of the following compliance programs: ISO 27001, SOC 2 / SOC 1, PCI, SSAE18, HIPAA, FISMA/FedRAMP.
- Ability to understand the intent of compliance requirements to provide effective and meaningful analysis.
- Ability to communicate technical security risks to non‑technical business stakeholders; strong ability to influence or negotiate with stakeholders dealing with competing priorities. Excellent organization and time‑management skills to oversee simultaneously occurring projects, tasks, and deadlines.
- Experience in leveraging or critically thinking about how to integrate AI into work processes, decision‑making, or problem‑solving, including using AI‑powered tools, automating workflows, analyzing AI‑driven insights, or exploring AI's potential impact on the function or industry.
- Bachelor’s degree preferred.
- Prior experience working in the Security and/or Compliance group.
- Relevant professional certifications such as CISSP, CISA, CISM, CIPP, GIAC, PMP.
- Excellent report‑writing skills, ability to prepare compliance reports and associated metrics.
Benefits
- Excellent organization and time‑management skills to oversee simultaneously occurring projects, tasks, and deadlines.
- Effective cross‑functional communication & influence.
- Broad compliance framework expertise.
- Work‑life balance.
- People‑first company.
- Hybrid work policy.
- Working directly with peers in the US.
We are an equal‑opportunity employer. We do not discriminate on the basis of race, color, religion, sex, national origin, age, disability, or any other protected class.