
Lead Analyst, Third Party Security
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in California.
• Oversee intricate technical security evaluations of partners, vendors, and third-party integrations.
• Convert assessment results into actionable, risk-based recommendations.
• Transform the third-party security assessment program from a document-focused approach to a dynamic, scalable, and continuously evolving capability.
• Create and develop AI-driven tools and automation for analyzing evidence, identifying risks, monitoring, scoring, and managing assessment workflows.
• Implement proactive monitoring strategies to detect and prioritize emerging security threats within Circle’s third-party ecosystem.
• Collaborate with Security Engineering, Legal, Procurement, and business teams to establish and enforce security requirements during the onboarding of third parties and ongoing oversight.
• Convey significant third-party security risks, control deficiencies, and recommendations to technical stakeholders, business partners, and executive leadership.
• Enhance third-party security methodologies, standards, tools, and processes, increasing the quality of assessments while minimizing manual efforts.
• A minimum of 7 years of pertinent experience in cybersecurity, technology risk, or compliance, including substantial experience with third-party or vendor security evaluations.
• Capability to independently conduct intricate security assessments and assess control effectiveness beyond simple questionnaire or compliance-based reviews.
• Technical expertise in cloud security, API security, network architecture, identity and access management, and cryptography.
• Practical experience utilizing AI, GenAI, automation, or internally developed tools to enhance security, risk, or compliance workflows.
• Background in modernizing security, risk, or compliance programs through automation, improved methodologies, or process redesign.
• Excellent communication and stakeholder management abilities, with a talent for translating complex security risks into straightforward recommendations for both technical and non-technical audiences.
• Preferred: experience within financial services, fintech, digital assets, or another highly regulated sector.
• Preferred: familiarity with DORA, SOC 2, ISO 27001, or relevant regulatory guidance.
• Preferred: knowledge of blockchain and digital asset technologies, including crypto-native vendors, wallets, smart contracts, or decentralized infrastructure.
• Flexible work environment.
• Inclusive workplace.
• Interview accommodations or assistance for candidates with disabilities.
GuidePoint Security
Gravie
Your Software Supplier
Dragonfli Group
Get handpicked remote jobs straight to your inbox weekly.