Third Party Cyber Risk Analyst

Selby Jennings

New York (NY)

On-site

USD 90,000 - 140,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Selby Jennings is seeking an Information Security & Third-Party Risk Analyst to oversee vendor and external partner risk across the organization. The role evaluates cybersecurity posture of suppliers and service providers supporting business operations.

You will partner with risk, technology, legal, compliance and procurement teams to ensure third-party relationships meet security standards and regulatory expectations.

Qualifications

  • Experience with technology, cybersecurity, or vendor risk assessments.
  • Knowledge of the third-party risk management lifecycle.
  • Familiarity with NIST, ISO 27001, CRI Profile frameworks.
  • Experience reviewing SOC 1 and SOC 2 reports.
  • Understanding of information security principles including access management, continuity, incident response, data protection.

Responsibilities

  • Evaluate cybersecurity risks in third-party relationships.
  • Analyze security artifacts and reports (SOC, audits, BCPs, policies).
  • Identify control gaps and assign risk ratings.
  • Support onboarding, contracts, renewals, and terminations from a security risk perspective.
  • Monitor ongoing third-party cybersecurity developments and incidents.
  • Maintain records in risk management systems and complete risk reviews.
  • Collaborate to track remediation and risk mitigation activities.
  • Assist regulatory examinations and governance initiatives.
  • Contribute to improving risk management procedures and standards.

Skills

Vendor risk assessments
Cybersecurity risk analysis
Risk management lifecycle
Analytical skills
Communication skills
Regulated industry experience

Tools

Third-party risk platforms
Workflow tools

Job description

A global financial services organization is seeking an Information Security & Third-Party Risk Analyst to support the oversight of vendor and external partner risk. This individual will play a key role in evaluating the cybersecurity posture of suppliers, service providers, and other external organizations that support business operations.

The successful candidate will partner with stakeholders across risk, technology, legal, compliance, and procurement teams to ensure third-party relationships meet established security standards and regulatory expectations.

Key Responsibilities
  • Evaluate cybersecurity and technology risks associated with new and existing third-party relationships.
  • Analyze security artifacts such as SOC reports, independent audit reports, business continuity plans, information security policies, penetration testing results, and certification documentation.
  • Identify control gaps, document findings, and assign risk ratings based on established assessment methodologies.
  • Support vendor onboarding, contract reviews, renewals, and termination activities from a security risk perspective.
  • Monitor ongoing third-party cybersecurity developments, incidents, and emerging risks that could affect the organization.
  • Maintain accurate records within third-party risk management systems and ensure timely completion of risk reviews.
  • Collaborate with internal stakeholders to track remediation efforts and risk mitigation activities.
  • Assist with regulatory examinations, audit requests, and governance initiatives related to third-party risk oversight.
  • Contribute to the enhancement of risk management procedures, standards, and operating practices.
Desired Background
  • Experience conducting technology, cybersecurity, or vendor risk assessments.
  • Working knowledge of the third-party risk management lifecycle.
  • Familiarity with industry frameworks and standards such as NIST, ISO 27001, CRI Profile, or similar control frameworks.
  • Experience reviewing independent assurance reports including SOC 1 and SOC 2 examinations.
  • Understanding of information security principles including access management, business continuity, incident response, data protection, and cybersecurity governance.
  • Familiarity with vendor risk management platforms and workflow tools.
  • Strong analytical, organizational, and communication skills.
  • Prior experience within banking, financial services, fintech, or other regulated industries is advantageous.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Third Party Risk Analyst
Third Party Risk Analyst

Addison Group • Chicago (IL)

On-site
USD 70,000 - 90,000
(On-site) Information Security Vendor Management Analyst
(On-site) Information Security Vendor Management Analyst

Centreville Bank • Warwick (RI)

On-site
USD 70,000 - 90,000
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

Intercontinental Exchange Holdings, Inc. • Atlanta (GA)

On-site
USD 80,000 - 120,000
Third Party Risk Management Analyst
Third Party Risk Management Analyst

Phyton Talent Advisors • Red Bank (NJ)

On-site
USD 90,000 - 130,000
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

ICE • Atlanta (GA)

On-site
USD 85,000 - 120,000
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

ICE Clear Europe Limited • Northern (KY)

Hybrid
USD 90,000 - 120,000
Third party Risk Specialist
Third party Risk Specialist

Atlas Search • New York (NY)

On-site
USD 100,000 - 130,000
Tech Risk - Third Party Lead
Tech Risk - Third Party Lead

JPMorgan Chase & Co. • Jersey City (NJ)

On-site
USD 140,000 - 230,000
Senior Third-Party Risk Management Analyst
Senior Third-Party Risk Management Analyst

Phyton Talent Advisors • Red Bank (NJ)

On-site
USD 90,000 - 150,000
Commercial and Investment Bank, Controls – Third Party and Resiliency Risk & Control Manager - Executive Director
Commercial and Investment Bank, Controls – Third Party and Resiliency Risk & Control Manager - Executive Director

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 240,000