Third Party Risk Specialist (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Third Party Risk Specialist (Cybersecurity): Evaluating and managing the risk of third-party vendors across information security, financial, and regulatory domains with an accent on control evaluation and risk mitigation. Focus on performing security assessments, managing vendor diligence questionnaires (DDQs), and tracking remediation plans to ensure system integrity.
Location: Hybrid in Salt Lake City, Utah (Monday-Thursday in office, Friday remote)
Salary: $70,000 – $85,000
Company
is a fintech platform specializing in alternative investments for wealth management.
What you will do
- Perform security assessment activities, including evaluating vendor controls and independent audit reports via GRC systems.
- Coordinate directly with third-party vendors to obtain artifacts and complete diligence questionnaires (DDQs).
- Recommend mitigating and compensating controls for vendor security programs.
- Track and communicate remediation plans with vendors and internal technology partners.
- Maintain and present vendor risk program metrics to management.
- Support the Assurance team with client-facing DDQs.
Requirements
- 5 years of technology experience, including 2-3 years specifically in a vendor risk role.
- Bachelor's degree in Computer Science, Technology, or an Information Security-related field.
- Knowledge of ISO-27001 or NIST 800 security program standards.
- Understanding of regulatory requirements, privacy laws, and cloud security (IaaS, SaaS, AaaS).
- Strong English writing and communication skills.
- Must be based in or able to work from Salt Lake City, Utah to comply with the hybrid office schedule.
Nice to have
- Experience with Upguard or other vendor GRC tools.
- Experience with RiskRecon or security risk measurement tools.
Culture & Benefits
- Comprehensive compensation package including base salary, equity, and annual performance bonus.
- Employer-matched retirement plan.
- Subsidized healthcare with 100% employer-paid dental, vision, and virtual mental health counseling.
- Unlimited paid time off (PTO) and parental leave.
- Flexible hybrid work arrangement (Remote Fridays).
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →