(On-site) Information Security Vendor Management Analyst

Centreville Bank

Warwick (RI)

On-site

USD 70,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Centreville Bank is seeking a Vendor Management Analyst in Warwick, Rhode Island. This role supports the Third-Party Risk Management (TPRM) program by evaluating vendor risks, reviewing contracts, and maintaining documentation for compliance. Candidates should have a Bachelor's degree and 2–5 years of relevant experience in vendor management or risk assessment. Preferred qualifications include familiarity with FFIEC and GLBA standards. The position offers opportunities for growth in a dynamic banking environment.

Qualifications

  • 2–5 years of experience in vendor management, third-party risk, or a related banking role.
  • Ability to interpret SOC reports and cybersecurity controls.
  • Prior experience in banking or financial services.

Responsibilities

  • Evaluate cybersecurity risks from new and existing vendors.
  • Review contracts for information security and risk-related provisions.
  • Maintain the Vendor Watchlist to track vendor issues.

Skills

Risk management
Analytical skills
Documentation skills
Cybersecurity risk assessment

Education

Bachelor’s degree in Information Security, Business, Risk Management, or related field

Job description

Description

The Vendor Management Analyst is responsible for supporting the Bank’s Third-Party Risk Management (TPRM) Program within the Information Security department. This role evaluates the risk of new and existing third-party relationships, conducts and documents due diligence, supports contract reviews, and manages ongoing monitoring activities to ensure compliance with regulatory guidance (e.g., FFIEC, GLBA, FDIC). The Analyst will work closely with business owners, Risk, Compliance, Project Management, Finance, and senior leadership to ensure vendors meet the Bank’s security, operational, and financial requirements.

Third-Party Risk Assessments
  • Evaluate risks presented by new and existing vendors across cybersecurity, operational, financial, compliance, business continuity, privacy, and reputational domains.
  • Determine required risk tiering and corresponding due diligence requirements.
  • Partner with business units to ensure clear articulation of vendor use cases and criticality.
  • Gather required due diligence artifacts such as SOC 2 reports, independent audits, penetration test summaries, cybersecurity questionnaires, financial statements, insurance certificates, business continuity plans, and regulatory compliance attestations.
  • Review and assess due diligence documents for adequacy, control effectiveness, gaps, and red flags.
  • Document findings, residual risks, and recommendations within the Bank’s vendor management system.
  • Request and follow up on remediation or compensating controls for identified deficiencies.
  • Maintain documentation memorializing new vendor diligence and ongoing monitoring results.
Contract Review Support
  • Review contracts and amendments for required information security and risk-related provisions, including data security requirements, confidentiality, incident reporting, business continuity, right to audit, subcontractor oversight, and termination rights.
  • Collaborate with Legal and Procurement to ensure contract terms align with bank policy.
Issue Tracking & Remediation Oversight
  • Maintain the Bank’s Vendor Watchlist to track issues with vendors, vendor remediation efforts, and follow up on open issues.
  • Document evidence of corrective actions and ensure timely resolution of audit or exam findings.
Program Governance & Reporting
  • Prepare reporting for management, committees, and the Board.
  • Support internal/external audits and regulatory exams.
  • Assist with development and enhancement of TPRM policies and procedures.
  • Train business units and stakeholders on the vendor management process and program.
Requirements
  • Bachelor’s degree in Information Security, Business, Risk Management, or related field.
  • 2–5 years of experience in vendor management, third-party risk, cybersecurity risk, or related banking role.
  • Prior experience in banking or financial services.
  • Ability to interpret SOC reports and cybersecurity controls.
  • Strong analytical and documentation skills.
Preferred Qualifications
  • Understanding of FFIEC, GLBA, and industry best practices.
  • Familiarity with NIST CSF, ISO 27001, SIG/AUP questionnaires.
  • Experience reviewing contracts from a security or risk perspective.
  • Exceptional candidates will have relevant certifications such as CTPRP, CRVPM, or CRISC.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Vendor Management Analyst
Information Security Vendor Management Analyst

Centreville Bank • West Warwick (RI)

On-site
USD 75,000 - 100,000
Third Party Risk Analyst
Third Party Risk Analyst

Addison Group • Chicago (IL)

On-site
USD 70,000 - 90,000
Third Party Risk Sr Analyst
Third Party Risk Sr Analyst

Citizens Bank • Rhode Island

Hybrid
USD 80,000 - 100,000
Third Party Risk Sr Analyst
Third Party Risk Sr Analyst

Citizens • Johnston (RI)

Hybrid
USD 80,000 - 100,000
InfoSec Vendor Risk & Compliance Analyst
InfoSec Vendor Risk & Compliance Analyst

Centreville Bank • West Warwick (RI)

On-site
USD 75,000 - 100,000
Third Party Risk Sr Analyst - Cybersecurity
Third Party Risk Sr Analyst - Cybersecurity

Citizens • Johnston (RI)

Hybrid
USD 95,000 - 123,000
Third Party Risk Sr Analyst - Cybersecurity
Third Party Risk Sr Analyst - Cybersecurity

Citizens Bank • Johnston (RI)

Hybrid
USD 95,000 - 123,000
Supervisor, IT Security Vendor Risk Management
Supervisor, IT Security Vendor Risk Management

Raymond James • Saint Petersburg (FL)

Hybrid
USD 120,000 - 190,000
Benefits package
Hybrid work model
Vendor Risk Manager
Vendor Risk Manager

Aquent • Westlake (TX)

On-site
USD 120,000 - 180,000
Health insurance
Vision insurance
Dental insurance
+2
Risk Analyst – Vendor Management
Risk Analyst – Vendor Management

TechDigital Group • Arizona

Hybrid
USD 60,000 - 80,000