Jobs · Rhode Island

Third Party Risk Sr Analyst - Cybersecurity

Citizens · Johnston, RI · Today
$95k–$123k/yrFull-time

About the role

The Third Party Risk Sr Analyst manages vendor issues, completes quality assurance functions, and executes Third Party Vendor Assessment reviews. This includes managing relationships with business leaders and vendors while providing insight on business risk and the adequacy and effectiveness of control processes. The role delivers assessment reviews and opinions on the vendor control environment to meet Citizens policies, identifying issues and assisting in creating action plans to mitigate risks. The function adds value by providing assurance on vendors related to customer, financial, or reputational risk and driving action plans to address risks while leveraging best practices bank-wide.

Responsibilities

  • Collaborate with senior management to influence key decisions.
  • Evaluate third-party vendors' control infrastructure effectiveness and obtain evidence of controls.
  • Apply experience in audit, security, and regulatory frameworks including ISO 27001, GLBA, SOX, PCI, HIPAA, State Privacy Regulations, and FFIEC.
  • Assist in Governance Risk and Compliance (GRC) program design, process reengineering, enhancements, and tool/technology implementations.
  • Lead current risk assessments, continual risk assessments, and risk metrics/visualizations.
  • Perform quality assurance on vendor assessment and remediation activities.
  • Work directly with key business leaders to facilitate risk analysis and risk management processes, identifying acceptable levels of risk and establishing roles/responsibilities.
  • Maintain and monitor the enterprise risk exception process to identify areas of noncompliance.
  • Support and participate in regulatory exam preparation, execution, and remediation.
  • Coach and mentor junior analysts while articulating Third Party Vendor Assessment program goals and objectives.
  • Produce Third Party Vendor Assessment reports that clearly articulate risks for varied audiences.
  • Translate security risk and communicate effectively to business partners.
  • Travel within the United States is required.

Requirements

  • Previous experience completing Third Party Vendor Assessments.
  • Understanding of Cyber Security controls.

Pay

The salary range for this position is $95,000–$123,000 per year, plus an opportunity to earn an annual discretionary bonus. Actual pay is based on factors including budget, work location, and relevant skills and experience.

Benefits

  • Comprehensive medical, dental, and vision coverage.
  • Retirement benefits.
  • Maternity/paternity leave.
  • Flexible work arrangements (4 days in office, 1 day remote).
  • Education reimbursement.
  • Wellness programs.
  • Paid time off policy exceeding mandatory local and state requirements.

Schedule

Hours per Week: 40
Work Schedule: Monday – Friday

This role is not eligible for new employer-sponsored or current H-1B visa holders. Applicants must be authorized to work in the U.S. without the need for new employer sponsorship for themselves or their spouses now and in the future.

Similar jobs