Senior Security Risk Management Analyst
TalentBurst, an Inc 5000 company · Palo Alto, CA · 1 mo ago
On-siteFinanceContract
Responsibilities
- Lead and conduct comprehensive risk assessments of new and existing third-party vendors and service providers, focusing on cybersecurity, and regulatory compliance.
- Evaluate third-party security questionnaires, audit reports (e.g., SOC 2, ISO 27001), and risk documentation.
- Cook up coordination with vendors to request and verify security controls, remediation plans, and ongoing compliance.
- Oversee facilitation of risk remediation efforts agreed upon with suppliers, ensuring timely resolution.
- Collaborate during supplier contract development, reviewing deviations from security requirements and offering subject matter expertise on risk remediation.
- Classify vendors according to risk tiers and maintain a comprehensive database of vendor risk profiles.
- Participate in continuous security monitoring of existing suppliers to track changing risk profiles.
- Partner with Procurement, Legal, Privacy, and InfoSec teams to improve supplier security management processes.
- Identify opportunities to automate parts of the assessment process, thereby reducing manual work and enhancing efficiency.
- Keep abreast of emerging risks, industry standards, and regulatory requirements affecting third-party vendors.
- Contribute to broader cybersecurity risk management initiatives, including identifying, assessing, and tracking information security risks beyond the third-party domain.
- Provide guidance and knowledge transfer to team members, supporting a collaborative team environment.
Qualifications
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, Risk Management, or a related field.
- 6-8 years of professional experience in third-party risk assessment within cybersecurity or information risk management.
- Solid understanding of risk assessment methodologies and best practices.
- Ability to synthesize and communicate complex risk findings to both technical and non-technical audiences.
- Detail-oriented, process-driven, and capable of managing multiple vendor assessments concurrently.
- Experience with tools such as Coupa, OneTrust, JIRA and Coverbase is a plus.
- Professional certifications in Information Security or Risk Management (e.g. CISA, CISM, CISSP, CRISC) is a plus.