Get more replies from employers
Send a job-specific resume in minutes.
FM is seeking a Senior Information Security Analyst specializing in Third-Party Risk Management (TPRM). You will lead end-to-end risk assessments of external vendors, SaaS platforms, and cloud solutions, focusing on data handling, storage, and integration with internal systems.
You will partner with business, technology, and procurement teams to identify risks and implement practical mitigation strategies, guiding risk governance and alignment with regulatory expectations.
Establishednearly twocenturies ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineeringexpertiseare solely dedicated to property risk management and the resilience of its policyholder-owners. These owners, who share the belief that the majority of property loss is preventable, represent many of the world’s largest organizations, including one of every four Fortune 500 companies. They work with FM to better understand the hazards that canimpacttheir business continuity to make cost-effective risk management decisions, combining property loss prevention with insurance protection.
This position requires on-site work one day per week at our Corporate Headquarters and flexibility to be on-site when needed based on the demands of the business.
Relocation is not offered for this position.
FM is seeking a Senior Information Security Analyst with deepexpertisein Third-Party Risk Management (TPRM), you will play a critical role in protecting FM by assessing how external vendors, SaaS platforms, and cloud solutions interact with our systems and data. This high-impact rolewhere yourexpertiseincyber risk, vendor security, and cloud architecturewillhelp shape business decisions, strengthen our security posture, and support innovation in a secure way. This includes reviewing both the vendor’s security control environment and the specific solution being implemented, with a focus on data handling, storage, and integration with internal systems.
You will partner closely with business, technology, and procurement teams to identifyrisks and recommend practical, business-aligned mitigation strategies.
You will leadend-to-end cybersecurity risk assessmentsof third-party vendors and solutions—going beyond standard due diligence to evaluate real-world risk across systems, data, and integrations.