Information Security & Third-Party Risk Analyst

Wright-Patt Credit Union

Beavercreek (OH)

On-site

USD 90,000 - 118,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Wright-Patt Credit Union is seeking an Information Security Risk & Compliance Analyst to support the enterprise risk program, including Third-Party Risk Management. You will assess vendor risks, document due diligence, and work with Legal on contractual risk terms, while documenting findings in risk systems and guiding remediation efforts.

The role requires experience with risk methodologies, MITRE/NIST, and SOC reporting; travel is expected to various locations.

Qualifications

  • Bachelor’s degree or equivalent work experience in IT, information security, or risk management.
  • Certification in information security or vendor management (CISSP, CRISC, CTPRP, CRVPM or equivalent) preferred.
  • 3+ years in IT or information security, with at least 2 years in third-party/vendor risk management.
  • Familiarity with MITRE framework, PCI-DSS, and NIST RMF.
  • Ability to interpret SOC reports and cybersecurity controls.

Responsibilities

  • Lead Third-Party Risk Management (TPRM) program activities and risk evaluations.
  • Conduct risk assessments for products/technologies using CIS, NIST, MITRE ATT&CK, and OWASP Top 10.
  • Collaborate with Legal and IT to ensure contracts reflect risk due diligence and SLAs.
  • Document findings and residual risks; escalate as needed.
  • Develop and maintain risk assessment methodologies for emerging tech including AI.
  • Support policy updates and governance reporting; manage risk mitigation progress.
  • Coordinate with business units to understand business impacts of identified risks.

Skills

SOC reports interpretation
Vendor risk management
Information security risk management
Third-party risk management
MITRE framework familiarity
PCI-DSS familiarity
NIST RMF familiarity
Certification: CISSP/CRISC/CTPRP/CRVPM

Education

Bachelor’s degree in IT/security/risk

Job description

Wright-Patt Credit Union is seeking an Information Security Risk & Compliance Analyst to support the enterprise risk program, including Third-Party Risk Management. You will assess vendor risks, document due diligence, and work with Legal on contractual risk terms, while documenting findings in risk systems and guiding remediation efforts.

The role requires experience with risk methodologies, MITRE/NIST, and SOC reporting; travel is expected to various locations.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

InfoSec Risk & Compliance Specialist
InfoSec Risk & Compliance Specialist

Wright-Patt Credit Union Inc. • Beavercreek (OH)

On-site
USD 90,000 - 120,000
Information Security Risk & Compliance Analyst
Information Security Risk & Compliance Analyst

Wright-Patt Credit Union Inc. • Beavercreek (OH)

On-site
USD 90,000 - 120,000
Information Security Risk & Compliance Analyst
Information Security Risk & Compliance Analyst

Wright-Patt Credit Union • Beavercreek (OH)

On-site
USD 90,000 - 118,000
Third Party Cyber Risk Analyst
Third Party Cyber Risk Analyst

Selby Jennings • New York (NY)

On-site
USD 90,000 - 140,000
Senior Manager, Third-Party Risk (Remote)
Senior Manager, Third-Party Risk (Remote)

FourLeaf Federal Credit Union • Bethpage (NY)

Remote
USD 117,000 - 176,000
Security Risk & Compliance Analyst - Hybrid
Security Risk & Compliance Analyst - Hybrid

First Tech Federal Credit Union • Marlborough (MA)

Hybrid
USD 74,000 - 89,000
Medical, dental, and vision coverage
401(k) match
PTO and holidays
+1
Information Security Risk Analyst
Information Security Risk Analyst

Compunnel, Inc. • San Francisco (CA)

On-site
USD 90,000 - 120,000
(On-site) Information Security Vendor Management Analyst
(On-site) Information Security Vendor Management Analyst

Centreville Bank • Warwick (RI)

On-site
USD 70,000 - 90,000
Information Security & Third-Party Risk Analyst
Information Security & Third-Party Risk Analyst

AditiStaffing • Bellevue (WA)

On-site
USD 85,000 - 110,000
Career growth focus on cybersecurity
Confidential handling of information according to EEO guidelines
Third Party Risk Analyst
Third Party Risk Analyst

Addison Group • Chicago (IL)

On-site
USD 70,000 - 90,000