CISS Risk Analyst

OptechUs

Auburn Hills (MI)

On-site

USD 70,000 - 95,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

OptechUs is seeking a candidate in Auburn Hills, Michigan, to assess supplier controls and ensure effectiveness in mitigating outsourcing risks. This role requires evaluating risk management processes and performing independent reviews at suppliers.

Qualified candidates should have information security experience with a focus on third-party risk management, relevant compliance knowledge, and strong documentation skills. Necessary tools include MS Office, Archer, and Hiperos.

Qualifications

  • Information security experience, preferably related to third-party risk management.
  • Familiarity with regulatory standards like GLBA, HIPAA, COBIT, and FFIEC.
  • Ability to create and maintain documentation such as processes and flowcharts.

Responsibilities

  • Evaluate supplier controls to mitigate outsourcing risks.
  • Conduct reviews and inspections at supplier sites.
  • Automate risk scoring using tools like Archer and MS Office.

Skills

Information security experience
Third-party risk management
Compliance knowledge
Process writing

Tools

MS Office
Archer
Hiperos

Job description

Job Description

Assess the controls at our suppliers to ensure they are adequate to mitigate the risk of outsourcing to that supplier.

  • Interpret independent reviews of the supplier, conduct minimal on‑site reviews and testing at the supplier, and use tools such as MS Office, Archer, and Hiperos to automate and communicate the scoring of inherent and residual risks involved in supplier relationships.
Qualifications
  • Information security experience, preferably third‑party risk management and compliance.
  • Familiarity with SOC 1 (SSAE 16) and SOC 2 (AT 101) reports.
  • Ability to write processes, procedures, and flowcharts.
  • Knowledge of regulatory and industry standards such as GLBA, HIPAA, COBIT, and FFIEC.
Preferred Skills and Competencies
  • Knowledge of FS‑ISAC Shared Assessments, penetration test results, and PCI DSS.
  • Experience performing on‑site third‑party reviews.
  • CISA, CISSP, CRISC, or other security certifications.
  • Archer (eGRC) or Hiperos (Supplier Management) experience.
  • Knowledge of Visual Basic and macro coding for MS Office applications.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Risk Business Analyst
Risk Business Analyst

System One • Merrifield (VA)

Hybrid
USD 83,000 - 124,000
CISSPCyber Security Analyst
CISSPCyber Security Analyst

TECHOAUTH SOLUTIONS LLC • Rancho Cucamonga (CA)

Hybrid
USD 90,000 - 120,000
(On-site) Information Security Vendor Management Analyst
(On-site) Information Security Vendor Management Analyst

Centreville Bank • Warwick (RI)

On-site
USD 70,000 - 90,000
Information Security Risk Analyst
Information Security Risk Analyst

Compunnel, Inc. • San Francisco (CA)

On-site
USD 90,000 - 120,000
Information Security and Compliance Manager
Information Security and Compliance Manager

Transhield, Inc. • Elkhart (IN)

On-site
USD 120,000 - 180,000
Senior IT Security Analyst
Senior IT Security Analyst

TridentCare • United States

On-site
USD 110,000 - 150,000
Cyber Security Analyst
Cyber Security Analyst

Infobahn Softworld Inc • Oakland (CA)

Hybrid
USD 85,000 - 120,000
TS/SCI Security Control Assessor
TS/SCI Security Control Assessor

Insight Global • Denver (CO)

On-site
USD 95,000 - 135,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Information Security Vendor Management Analyst
Information Security Vendor Management Analyst

Centreville Bank • West Warwick (RI)

On-site
USD 75,000 - 100,000