Назад
Company hidden
2 часа назад

Vendor Security Analyst (Cybersecurity)

120 500 - 146 200$
Формат работы
onsite
Тип работы
fulltime
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Vendor Security Analyst (Cybersecurity): Evaluating third-party and vendor engagements, security questionnaires, certifications, and controls to identify, rank, and mitigate vendor risk with an accent on cloud services, technical security reviews, and risk repositories. Focus on conducting onsite audits of high-risk vendors, analyzing penetration and vulnerability tests, and assessing SOC and ISO 27001 documentation.

Location: Louisville GBC, United States

Salary: $120,500–$146,200 per year in Washington, D.C.; additional discretionary bonuses may be available.

Company

hirify.global is a global law firm advising clients on finance, business, and regulation, with more than 3,100 lawyers worldwide.

What you will do

  • Evaluate third-party risk and guide vendor relationships.
  • Review vendor responses to security questionnaires and recommend risk mitigation measures.
  • Maintain the vendor risk repository, including certifications and assessment artifacts.
  • Assign risk scores to suppliers and partners.
  • Conduct onsite security and controls audits of high-risk vendors.
  • Support emerging information risk priorities and Responsible Business initiatives.

Requirements

  • Demonstrated experience identifying, assessing, and ranking information security risks, including risks related to cloud services.
  • Understanding of systems, networks, and security architecture best practices.
  • Broad knowledge of risk management, vulnerability management, and third-party risk.
  • Ability to make independent decisions and explain technical concepts in clear, non-technical language.
  • Ability to analyze security documentation accurately and interact effectively with external vendors.
  • Experience with SIG questionnaires, penetration tests, vulnerability tests, SOC 1 and SOC 2 Type 2 reports, and ISO 27001 is preferred; a bachelor's degree is preferred.

Culture & Benefits

  • Standard 37.5-hour workweek with core hours generally Monday through Friday, 9:00 a.m. to 5:30 p.m.
  • Additional or adjusted hours may be required based on business needs.
  • Benefits include medical, dental, and vision insurance.
  • 401(k) retirement plan and paid time off are provided, subject to applicable plan terms.
  • Equal opportunity employer with reasonable accommodation support for applicants and candidates with disabilities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →