Senior Information Security Risk Analyst

FM

Johnston (RI)

On-site

USD 110,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

FM is seeking a Senior Information Security Analyst specializing in Third-Party Risk Management (TPRM). You will lead end-to-end risk assessments of external vendors, SaaS platforms, and cloud solutions, focusing on data handling, storage, and integration with internal systems.

You will partner with business, technology, and procurement teams to identify risks and implement practical mitigation strategies, guiding risk governance and alignment with regulatory expectations.

Qualifications

  • Minimum 5+ years in cybersecurity, risk, or related fields with TPRM experience.
  • Experience assessing vendor security posture in cloud and enterprise environments.

Responsibilities

  • Lead end-to-end third-party risk assessments and vendor security reviews.
  • Evaluate vendor security programs and governance, including architecture and data flows.
  • Identify risks in data protection, privacy, IAM, and external attack surface.
  • Interpret SOC 1/SOC 2 and ISO 27001 reports to identify gaps and risk.
  • Collaborate with business, technology, procurement and legal teams on risk decisions.
  • Contribute to FM's TPRM framework and align with standards (NIST, ISO 27001, NYDFS).

Skills

Cybersecurity
TPRM
Vendor security
Cloud security
IAM

Job description

Establishednearly twocenturies ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineeringexpertiseare solely dedicated to property risk management and the resilience of its policyholder-owners. These owners, who share the belief that the majority of property loss is preventable, represent many of the world’s largest organizations, including one of every four Fortune 500 companies. They work with FM to better understand the hazards that canimpacttheir business continuity to make cost-effective risk management decisions, combining property loss prevention with insurance protection.

Work Schedule

This position requires on-site work one day per week at our Corporate Headquarters and flexibility to be on-site when needed based on the demands of the business.

Relocation is not offered for this position.

Position Summary

FM is seeking a Senior Information Security Analyst with deepexpertisein Third-Party Risk Management (TPRM), you will play a critical role in protecting FM by assessing how external vendors, SaaS platforms, and cloud solutions interact with our systems and data. This high-impact rolewhere yourexpertiseincyber risk, vendor security, and cloud architecturewillhelp shape business decisions, strengthen our security posture, and support innovation in a secure way. This includes reviewing both the vendor’s security control environment and the specific solution being implemented, with a focus on data handling, storage, and integration with internal systems.

You will partner closely with business, technology, and procurement teams to identifyrisks and recommend practical, business-aligned mitigation strategies.

You will leadend-to-end cybersecurity risk assessmentsof third-party vendors and solutions—going beyond standard due diligence to evaluate real-world risk across systems, data, and integrations.

Key Responsibilities
  • Lead end-to-end third-party solution risk assessments and vendor security reviews across thevendorlifecycle, including due diligence, onboarding, ongoing monitoring, and reassessments.
  • Evaluate vendor security programs, control effectiveness, and governance, along with deep-dive assessment of the specific product being implemented including solution architecture, data flows, and integration points.
  • Identifyand communicate inherent and residual cyber risks related to data protection, privacy, IAM, privileged access, system connectivity, and external attack surface exposure.
  • Review and interpret security documentation, including SOC 1/SOC 2 reports, ISO 27001 certifications, audit reports, architecture diagrams, data flow diagrams, and technical configurations.
  • Recommend practical risk mitigation strategies, including compensating controls, secure design changes, and contractual safeguards to support risk-informed decisions.
  • Partner with business, technology, procurement, and legal teams to support risk acceptance, exception management, and third-party risk governance.
  • Contribute to the evolution of FM’s third-party risk management framework,methodology, and standards in alignment with NIST, ISO 27001, NYDFS, and other applicable regulatory expectations.
Qualifications
  • 5+ years of experience in cybersecurity, information security, or cyber risk, with a background in third-party risk management (TPRM), IT risk, audit, incident response, or access management.
  • Experience assessing vendor security posture in cloud (SaaS/PaaS)and enterprise environments.
Technical Expertise
  • Strong understanding of systems, networks, application architecture, cloud security, and secure system design across AWS, Azure, SaaS, PaaS, APIs, and enterprise integrations.
  • Experience evaluating data flows, data classification, data protection, data governance, and secure data handling practices.
  • Knowledge of IAM, SSO, federation, privileged access, cyber threats, vulnerabilities, and attack methodologies.
  • Ability to interpret SOC 1, SOC 2, ISO certifications, and other third-party assurance artifacts toidentifycontrol gaps and residual risk.
Risk & Analysis:
  • Ability toidentify, assess, and clearly communicate complex cyber risks, trade-offs, and residual risk.
  • Experience recommending practical, business-alignedrisk base
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Third-Party Cyber Risk Analyst
Senior Third-Party Cyber Risk Analyst

FM • Johnston (RI)

On-site
USD 110,000 - 150,000
Information Security Vendor Management Analyst
Information Security Vendor Management Analyst

Centreville Bank • West Warwick (RI)

On-site
USD 75,000 - 100,000
Security Third Party Risk Management Lead
Security Third Party Risk Management Lead

Cloudflare • Austin (TX)

On-site
USD 150,000 - 190,000
(On-site) Information Security Vendor Management Analyst
(On-site) Information Security Vendor Management Analyst

Centreville Bank • Warwick (RI)

On-site
USD 70,000 - 90,000
Senior Risk and Compliance Analyst
Senior Risk and Compliance Analyst

cbrands • United States

On-site
USD 97,000 - 148,000
Third-Party Cyber Risk Specialist
Third-Party Cyber Risk Specialist

Jobtailor • Illinois

On-site
USD 85,000 - 110,000
Security Third Party Risk Management Lead
Security Third Party Risk Management Lead

Webhosting • Austin (TX)

On-site
USD 140,000 - 210,000
Director, Security Risk Management
Director, Security Risk Management

CardWorks Servicing LLC • United States

Hybrid
USD 151,000 - 168,000
Medical, Dental, and Vision coverage
401(k) Plan with Company Match
Paid vacation and sick days
Senior Information Security Analyst
Senior Information Security Analyst

Marotta Controls • Parsippany-Troy Hills (NJ)

On-site
USD 120,000 - 160,000
Sr. Security Risk Analyst
Sr. Security Risk Analyst

VC5 Consulting • Houston (TX)

On-site
USD 110,000 - 140,000