Third-Party Risk Management 1

Millennium

New York (NY)

On-site

USD 175,000 - 250,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Millennium is seeking a seasoned Third-Party Risk Manager in New York to lead security risk assessments for vendors and subprocessors. You will evaluate findings, define compensating controls, and present risk implications to both technical teams and business stakeholders.

You will partner with procurement, legal, and IT to embed security requirements in contracts and onboarding, monitor incidents, and drive governance and automation improvements across the TPRM program.

Qualifications

  • Experience conducting vendor or third-party security risk assessments.
  • Familiar with NIST CSF, SOC 2, ISO 27001, CIS Controls, SIG, and CAIQ.
  • Ability to analyze findings and recommend remediation or risk acceptance.

Responsibilities

  • Conduct security risk assessments for vendors and subprocessors.
  • Evaluate materiality and business impact of findings and recommend controls.
  • Prepare risk reports and maintain third-party risk inventory.
  • Communicate findings to technical teams and senior leaders.
  • Track remediation and partner with procurement, legal, and IT.

Skills

Vendor risk assessments
NIST CSF
SOC 2
ISO 27001
CIS Controls
CAIQ
Penetration testing reviews

Education

Bachelor’s degree in Computer Science/Engineering/Cybersecurity
Security certifications: CTPRP/CTPRA/CISA/CISSP

Tools

TPRM platforms
GPU inference
Windows
Linux
macOS
Cloud and on-prem infra

Job description

About Millennium

Millennium is a global, diversified alternative investment firm, founded in 1989. Defined by evolution, innovation and focus, Millennium’s mission is to deliver results for our investors.

About Millennium

Millennium is a global, diversified alternative investment firm, founded in 1989. Defined by evolution, innovation and focus, Millennium’s mission is to deliver results for our investors.

Our people are empowered with both independence and support: the autonomy to pursue ideas with conviction and the backing of a global network committed to collaboration, disciplined risk management and continuous learning. With opportunities to deepen expertise and accelerate development, talent at Millennium is equipped to adapt, evolve and build lasting impact over time. Discover how transformative growth accelerates impact.

Meet the Team

Information Technology is core to the health and growth of Millennium’s active, multi-manager business model, which demands flexible, scalable technology and advanced proprietary systems. The Information Security team protects the firm’s people, data, and technology across a complex, fast-moving global trading environment, partnering with technology, trading, and business stakeholders to embed security throughout global operations. The team combines deep technical expertise with pragmatic risk management and is advancing innovative applications of artificial intelligence to strengthen the firm’s defenses.

What You’ll Do
  • Conduct security risk assessments for prospective and existing vendors, including questionnaire reviews, evidence validation, technical discussions, and identification of fourth-party and subprocessor dependencies.
  • Evaluate the materiality and business impact of findings, identify compensating controls, and recommend remediation or risk acceptance based on residual risk.
  • Prepare clear risk assessment reports and maintain accurate third-party risk inventory and assessment records.
  • Communicate findings, recommendations, and implementation requirements to technical teams, business stakeholders, and senior leaders.
  • Track remediation of identified security gaps and follow up on implementation requirements.
  • Partner with vendor management, procurement, legal, and business teams to embed security requirements into vendor contracts and onboarding processes.
  • Monitor existing vendors for security incidents and adverse news, engaging vendors to assess impact, root cause, and corrective actions.
  • Strengthen the third-party risk management program through improvements to methodology, questionnaires, monitoring, reporting, quality assurance, and automation.
What You Bring
  • Experience conducting vendor or third-party security risk assessments, including familiarity with NIST CSF, SOC 2, ISO 27001, CIS Controls, SIG, and CAIQ.
  • Ability to analyze penetration-test reports and architecture or data-flow diagrams to assess vulnerability severity, connectivity, trust boundaries, and associated security risks.
  • Strong critical thinking and risk judgment, with the ability to assess materiality, business impact, and compensating controls.
  • Excellent written and verbal communication skills, with the ability to translate technical issues into clear risk and business implications for stakeholders.
  • Ability to manage multiple assessments and deadlines effectively in a fast-paced, high-stakes environment.
  • Bachelor’s degree or higher in Computer Science, Computer Engineering, Cybersecurity, Information Security, or a related field, or commensurate work experience.
  • Five or more years of hands-on third-party risk management experience: relevant security certifications, such as CTPRP, CTPRA, CISA, or CISSP, are preferred.
  • Experience with the secure use, deployment, and governance of AI models, tools, and supporting infrastructure, including GPUs and inferencing workloads; familiarity with on-premises and cloud infrastructure, TPRM platforms, reporting and automation tools, and Windows, Linux, and macOS environments is preferred.
Salary Range

Millennium offers a total compensation package which includes a base salary, discretionary performance bonus, and comprehensive benefits. The estimated base salary range for this position is $175,000 to $250,000, which is specific to New York and may change in the future. When finalizing an offer, we take into consideration an individual’s experience level and the qualifications they bring to the role to formulate a competitive total compensation package

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Third-Party Risk Manager (Security & AI)
Senior Third-Party Risk Manager (Security & AI)

Millennium • New York (NY)

On-site
USD 175,000 - 250,000
Risk Controls Manager
Risk Controls Manager

Millennium • New York (NY)

On-site
USD 160,000 - 250,000
Base salary + bonus
Comprehensive benefits
Software Engineer - Digital Assets Trading
Software Engineer - Digital Assets Trading

Millennium • New York (NY)

On-site
USD 175,000 - 250,000
Senior Portfolio Researcher
Senior Portfolio Researcher

Millennium • New York (NY)

On-site
USD 160,000 - 250,000
Project Manager
Project Manager

Millennium • New York (NY)

On-site
USD 70,000 - 160,000
Rates, Credit, FX and Mortgage Portfolio Pricing and Analytics, Technical Business Analyst/Proj[...]
Rates, Credit, FX and Mortgage Portfolio Pricing and Analytics, Technical Business Analyst/Proj[...]

Millennium • Miami (FL)

On-site
USD 100,000 - 175,000
Discretionary bonus
Comprehensive benefits
Rates, Credit, FX and Mortgage Portfolio Pricing and Analytics, Technical Business Analyst/Proj[...]
Rates, Credit, FX and Mortgage Portfolio Pricing and Analytics, Technical Business Analyst/Proj[...]

Millennium • New York (NY)

On-site
USD 100,000 - 175,000
Forward Deployed Software Engineer - Equities Technology
Forward Deployed Software Engineer - Equities Technology

Millennium • New York (NY)

On-site
USD 175,000 - 250,000
Compliance Analyst
Compliance Analyst

Millennium • New York (NY)

On-site
USD 70,000 - 160,000
Equity Portfolio Pricing and Analytics, Technical Business Analyst
Equity Portfolio Pricing and Analytics, Technical Business Analyst

Millennium • New York (NY)

On-site
USD 90,000 - 170,000