Назад
3 часа назад

Security Analyst, Third-Party Ecosystem Risk Management

119 000 - 176 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Страна
US
vacancy_detail.hirify_telegram_tooltipВакансия из Telegram канала -

Мэтч & Сопровод

Покажет вашу совместимость и напишет письмо

Описание вакансии

TL;DR
Security Analyst, Third-Party Ecosystem Risk Management (Third-Party Risk): Running vendor and partner security risk assessments, risk rating, remediation, and ecosystem risk reporting with an accent on third-party risk lifecycle management, security documentation review, and program maturation. Focus on building AI-assisted assessment workflows, maintaining risk registers and tiering, and tracking remediation to closure.

Security Analyst, Third-Party Ecosystem Risk Management

Company

Plaid

Conditions

6 days agoSeniorSalary: 119K - 176KNew York City Office; Raleigh Office; San Francisco HQ; Seattle Office Hybrid Full Time Cybersecurity Jobs by Plaid

Skills

Access Control Artificial Intelligence Audit Automation Encryption Incident Response Iso 27001 Legal Nist Csf Procurement Questionnaires Remediation Reporting Risk Acceptance Risk Management Security Assessment Soc 2 Third-Party Risk Tprm Vendor Risk

Candidate Availability

Hybrid · New York · Required New York City · Required Raleigh · Required San Francisco · Required Seattle · Required Hybrid · Required Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will run third-party security risk assessments from intake through risk rating and remediation, assess customers and partners, maintain risk tiering and the risk register, mature questionnaires and workflows, report on ecosystem risk, and build AI-assisted assessment and reporting workflows.

Requirements

  • 4+ years of vendor risk management experience
  • Third-party security risk assessment experience
  • Vendor security risk assessment experience
  • SOC 2 knowledge
  • ISO 27001 knowledge
  • NIST CSF knowledge
  • Access control knowledge
  • Encryption knowledge
  • Incident response knowledge
  • Business continuity and disaster recovery knowledge
  • Third-party risk lifecycle knowledge
  • Third-party risk program maturation experience
  • Assessment execution at volume
  • Analytical skills
  • Documentation skills
  • Written communication skills
  • Verbal communication skills
  • AI tooling experience
  • CTPRP, CISA, or CISSP credential
  • TPRM platform experience

Responsibilities

  • Run vendor security risk assessments
  • Review vendor questionnaires, SOC 2 reports, ISO reports, and security documentation
  • Rate risk and document findings and exceptions
  • Vet customer and partner security posture
  • Maintain risk tiering and reassessment cadence
  • Track remediation to closure
  • Maintain the risk register
  • Improve questionnaires, tiering criteria, intake, runbooks, and tooling
  • Report on ecosystem risk and program health
  • Build AI-assisted workflows for assessment review, questionnaire analysis, and reporting

Benefits

  • Equity
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • 401(k)

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →

Текст вакансии взят без изменений

Источник -