Turn this role into an interview — a resume and cover letter built around what this employer wants.
Expedient Technology Solutions seeks an Information Security Risk & Compliance Analyst to support the risk programs and third-party vendor assessments. You will conduct risk assessments for products and technologies using recognized frameworks and collaborate with business units, IT, and Enterprise Risk Management.
The role requires 3+ years in IT/security, 2+ years in vendor risk, and familiarity with MITRE, PCI-DSS, and NIST RMF. Travel may be required with a valid driver's license.
The Information Security Risk & Compliance Analyst is responsible for the day-to-day tactical support of WPCU's Information Security Risk program and Third-Party Risk Management (TPRM) program. The position performs risk assessments for products and technologies following industry recognized frameworks such as CIS, NIST, MITRE ATT&CK and OWASP Top 10. This role is required to work closely with business units, Information Technology, and Enterprise Risk Management. They serve as the Information Security Subject Matter Expert (SME) for vendor risk management and will conduct evaluations of new and existing third-party relationships including but not limited to: conducting document due diligence; supporting contract reviews; and identifying risks associated with vendors. They are responsible forensuring all risksidentifiedeither through Information Security Risk Assessments or TPRM program are properly documented in the Issue Management, seeking regular updates towards resolution, and escalating concerns when needed.
1) Third Party Risk Management (TPRM) program (40%)
2) Risk Assessment Methodology (40%)
3) Issue Management (20%)
1) Bachelor's Degree in information technology, information security, or risk management is required. Candidates without a bachelor’s degree will be considered who can demonstrate equivalent work experience or training.
2) One of the following certifications is required: CISSP, CRISC, CTPRP, CRVPM or similar information security or vendor management certification. Candidates without this certification will be considered, however they will be required to obtain certification within the first year of employment.
3) 3+ years of experience in information technology or information security field required. Must include at least 2 years of experience in third-party risk management, vendor risk management, and information security or cybersecurity risk management.
4) Must have familiarity with MITRE framework, PCI-DSS, and NIST RMF.
5) Must demonstrate the ability to interpret SOC reports and cybersecurity controls.
Valid driver's license is required as the position will be required to travel to various locations to complete assessments.