5 дней назад
Third-Party Cyber Risk Management Engineer II (Cybersecurity)
60 000 - 215 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Third-Party Cyber Risk Management Engineer II (Cybersecurity) (GRC/TPCRM): Executing third-party security assessments, reassessments, inventory management, and secure data-sharing reviews for GEICO’s cybersecurity program with an accent on data quality, risk frameworks, and issue remediation. Focus on reconciling records across enterprise systems, monitoring remediation SLAs, and applying AI/automation to streamline assessment workflows and reporting.
Location: Bethesda, MD, United States
Annual salary: $60,000–$215,000
Company
is a large United States auto insurer and a member of the Berkshire Hathaway family of companies.
What you will do
- Execute third-party security assessments and reassessments using recognized risk assessment and workflow tools.
- Manage the third-party inventory and resolve records missing required security assessments.
- Reconcile third-party data across risk assessment tools and enterprise systems, identifying and closing data-quality gaps.
- Validate secure data-sharing methods and track third-party security issues, remediation status, and SLA compliance.
- Prepare accurate assessment, reassessment, and issue-management metrics for quarterly and executive reporting.
- Collaborate with Supplier Management, Legal, Data Protection Engineering, and business stakeholders on risk reviews and data-sharing gaps.
Requirements
- 1–2+ years of experience in cybersecurity, IT risk, or third-party/vendor risk management.
- Experience conducting security or risk assessments and supporting reassessment or renewal processes.
- Experience with GRC, TPCRM, workflow, ticketing, or case-management platforms such as Archer, ServiceNow, or OneTrust.
- Knowledge of third-party risk frameworks and standards including NIST, ISO 27001, CIS, and relevant data-privacy regulations.
- Experience with data reconciliation, reporting, or dashboarding; Excel, Power BI, and SQL are relevant examples.
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or equivalent education or experience.
Nice to have
- CompTIA Security+ or Cybersecurity Analyst+ certification.
- CISSP, CISM, CRISC, or CTPRP certification.
- Familiarity with AWS, GCP, or Azure environments.
- Interest or experience applying AI and automation to data classification, workflow routing, approvals, or reporting.
Culture & Benefits
- Mentorship from senior engineers and opportunities to build technical and domain expertise.
- Personalized development programs and certification assistance.
- Inclusive and collaborative culture.
- Benefits and flexibility designed to support well-being and professional growth.
- will consider sponsoring employment authorization for a qualified new applicant.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
9 дней назад
Cybersecurity Engineer II (GRC)
84 000 - 132 300$
8 дней назад
Senior Information Security Specialist (Cybersecurity)
120 000 - 160 000$
8 дней назад
Analyst, GRC – Public Sector (Cybersecurity)
120 000 - 145 000$
9 дней назад
Acquisition Security & Privacy Analyst (Cybersecurity)
115 000 - 125 000$
11 дней назад
Security Engineer III (Cybersecurity)
152 200 - 228 400$
10 дней назад
Security Engineer II (Cloud Security)
104 700 - 157 100$