
Cyber Risk Specialist, Third-Party Risk
Posted Jul 23

Posted Jul 23
This is a fully remote position, open to applicants in Brazil.
• Perform cyber and privacy risk evaluations for both new and existing vendors.
• Assess security measures, privacy protocols, and AI governance frameworks.
• Analyze due diligence documents including SOC reports, ISO certifications, security policies, and privacy materials.
• Collaborate with Procurement and Legal teams to enhance security, privacy, and AI contractual stipulations.
• Oversee vendor risk, monitor remediation efforts, and assist in ongoing improvement initiatives.
• Deliver clear, business-oriented recommendations to stakeholders and leadership.
• Contribute to the advancement of our global Third-Party Risk Management (TPRM) program.
• Over 5 years of experience in Third-Party Risk Management, Cybersecurity, Privacy, Governance, Risk & Compliance (GRC), Audit, or similar fields.
• Proven experience in executing vendor risk assessments and analyzing security controls.
• Familiarity with cybersecurity frameworks such as NIST, ISO 27001, or CIS Controls.
• Understanding of privacy laws and regulations (GDPR, CCPA, and comparable frameworks).
• Desirable knowledge of AI/ML risk concepts and emerging technologies.
• Excellent communication skills with the capability to convert technical risks into business-centric recommendations.
• Proficient in managing multiple projects and stakeholders in a dynamic global setting.
• Health insurance
• Flexible work arrangements
The Cigna Group
Handspring Health
Bicycle Health
Get handpicked remote jobs straight to your inbox weekly.