Senior Analyst, Third-Party Risk Management (TPRM)
Responsibilities
- Oversight of new TPRM assessments, including vendor assignments.
- Initiation and review of risk assessments for current and prospective third-party relationships.
- Building and maintaining relationships with internal business units for third-party environment inventories.
- Management and maintenance of the TPRM platform, including integrations into internal processes like supply chain and vendor compliance.
- Supporting regular reporting to the Information Security and AI Steering Committee leadership.
- Ensuring completeness of third-party vendor inventories for the TPRM process.
- Collaboration with the Cybersecurity Operations team for identifying and remediating third-party vulnerabilities.
Qualifications
- Bachelor’s degree or equivalent work experience required.
- A minimum of 4 years of TPRM or risk-related experience required; 3-5 years of industry or related experience preferred.
- Knowledge of the third-party or vendor management lifecycle, including related controls, processes, and risk exposure.
- Strong knowledge and experience with operational risk management, covering the full lifecycle of activities, including risk identification, assessment, mitigation, prioritization, monitoring, and reporting.
- Understanding of related regulatory requirements and expectations related to TPRM.
- Strong organization, planning, and project management skills; ability to prioritize tasks for self and team to meet requirements and deadlines.
- Excellent written and verbal communication skills and ability to interact well with internal and external parties.
- Ability to work with different functional groups and levels of employees to effectively and professionally achieve results.
- Strong computer skills, including Microsoft Office suite and Oracle.
- In-depth knowledge of access, security, and risk assessment methods and technologies.
- Knowledge of Information Security Standards (ISO 27001/27002, ITIL, etc.) and Data Privacy and Compliance Regulations (MA CMR 201, HIPPA, Red Flag, etc.).
About Us
The Team: The Senior Analyst Third Party Risk & Security, a member of the Information Security – Governance Risk and Compliance (GRC) team, focuses on monitoring operations relating to Third-Party Risk Management (TPRM) including managing risk assessments, and ensuring adherence to regulatory and internal security standards.
What You Can Offer Us: Oversee onboarding of new TPRM assessments, initiate and review risk assessments of current and prospective third-party relationships, partner and build relationships with internal business units to inventory third-party environments, manage and maintain the TPRM platform, support regular reporting to Information Security and AI Steering Committee leadership, ensure inventory completeness for third-party vendors needing to be tracked through the TPRM process, partner with Cybersecurity Operations team on identifying and remediating third party vulnerabilities, and other duties as assigned.
About Us: American Tower is a global digital infrastructure company serving customers through tower sites and other real estate solutions that support connectivity and opportunity, focused on achieving our vision of Building a More Connected World. Our success is rooted in the potential of our people and the power of local teams at our offices and sites across 25 countries. We are one of the largest global Real Estate Investment Trusts (REITs) and a publicly traded (NYSE:AMT), Fortune 500 Company headquartered in Boston, Massachusetts. The next decade will be an exciting time as we evolve our infrastructure to meet tomorrow’s needs and position our people to elevate their impact, their potential, and our shared success. Come grow your career with us!
For more information about how American Tower is building a more connected world, visit americantower.com. American Tower is proud to be an equal opportunity employer and will not discriminate against an applicant or employee based on age, sex, sexual orientation, gender identity, race, color, creed, religion, national origin or ancestry, citizenship, marital status, familial status, disability, military or veteran status, genetic information, pregnancy, reproductive decisions, or any other characteristic protected under applicable law. American Tower is committed to fair and equitable compensation practices. Placement within the salary range is based on a variety of factors, including relevant experience, skills, certifications, job level, and location. For U.S.-based candidates only, please see the base salary range for this position listed below. This position is also eligible for annual bonus, and annual equity award and participation in the Employee Stock Purchase Plan (ESPP). For candidates outside of the U.S., salary and benefits are based upon local market practice. American Tower also offers a comprehensive benefits package, which includes healthcare coverage, a 401(k) savings plan, paid time off, company holidays, sick leave, parental leave, and access to an Employee Assistance Program focused on mental and financial wellness, please click here to learn more.