
Cyber Risk Specialist, Third-Party Risk
Posted Jul 23

Posted Jul 23
This is a fully remote position, open to applicants in Brazil.
• Perform cybersecurity and privacy risk evaluations for both new and existing vendors.
• Evaluate security measures, privacy protocols, and AI governance structures.
• Examine due diligence materials, including SOC reports, ISO certifications, security policies, and privacy documentation.
• Collaborate with Procurement and Legal teams to enhance contractual security, privacy, and AI stipulations.
• Oversee vendor risk, monitor remediation efforts, and assist in ongoing improvement initiatives.
• Deliver clear, business-oriented recommendations to stakeholders and executive leadership.
• Contribute to the enhancement of our global Third-Party Risk Management (TPRM) program.
• A minimum of 5 years of experience in Third-Party Risk Management, Cybersecurity, Privacy, Governance, Risk and Compliance (GRC), Audit, or related disciplines.
• Proven experience in conducting vendor risk assessments and analyzing security controls.
• Familiarity with cybersecurity frameworks such as NIST, ISO 27001, or CIS Controls.
• Knowledge of privacy regulations, including GDPR, CCPA, and comparable frameworks.
• Understanding of AI/ML risk concepts and emerging technologies is strongly preferred.
• Excellent communication skills with the capability to articulate technical risks in terms of business recommendations.
• Proficient in managing multiple projects and stakeholders within a dynamic global setting.
• Competitive benefits package.
• Option for remote work availability.
The Cigna Group
Handspring Health
Bicycle Health
Get handpicked remote jobs straight to your inbox weekly.