Назад
Company hidden
5 дней назад

Third-Party Cyber Risk Management Engineer II (Cybersecurity)

60 000 - 215 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Third-Party Cyber Risk Management Engineer II (Cybersecurity) (GRC/TPCRM): Executing third-party security assessments, reassessments, inventory management, and secure data-sharing reviews for GEICO’s cybersecurity program with an accent on data quality, risk frameworks, and issue remediation. Focus on reconciling records across enterprise systems, monitoring remediation SLAs, and applying AI/automation to streamline assessment workflows and reporting.

Location: Bethesda, MD, United States

Annual salary: $60,000–$215,000

Company

hirify.global is a large United States auto insurer and a member of the Berkshire Hathaway family of companies.

What you will do

  • Execute third-party security assessments and reassessments using recognized risk assessment and workflow tools.
  • Manage the third-party inventory and resolve records missing required security assessments.
  • Reconcile third-party data across risk assessment tools and enterprise systems, identifying and closing data-quality gaps.
  • Validate secure data-sharing methods and track third-party security issues, remediation status, and SLA compliance.
  • Prepare accurate assessment, reassessment, and issue-management metrics for quarterly and executive reporting.
  • Collaborate with Supplier Management, Legal, Data Protection Engineering, and business stakeholders on risk reviews and data-sharing gaps.

Requirements

  • 1–2+ years of experience in cybersecurity, IT risk, or third-party/vendor risk management.
  • Experience conducting security or risk assessments and supporting reassessment or renewal processes.
  • Experience with GRC, TPCRM, workflow, ticketing, or case-management platforms such as Archer, ServiceNow, or OneTrust.
  • Knowledge of third-party risk frameworks and standards including NIST, ISO 27001, CIS, and relevant data-privacy regulations.
  • Experience with data reconciliation, reporting, or dashboarding; Excel, Power BI, and SQL are relevant examples.
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or equivalent education or experience.

Nice to have

  • CompTIA Security+ or Cybersecurity Analyst+ certification.
  • CISSP, CISM, CRISC, or CTPRP certification.
  • Familiarity with AWS, GCP, or Azure environments.
  • Interest or experience applying AI and automation to data classification, workflow routing, approvals, or reporting.

Culture & Benefits

  • Mentorship from senior engineers and opportunities to build technical and domain expertise.
  • Personalized development programs and certification assistance.
  • Inclusive and collaborative culture.
  • Benefits and flexibility designed to support well-being and professional growth.
  • hirify.global will consider sponsoring employment authorization for a qualified new applicant.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →