
Senior Third-Party Risk Management Analyst
Posted 15 hours ago

Posted 15 hours ago
This is a fully remote position, open to applicants in United States.
• Manage Momentive's global inventory of third-party providers, applications, and services from onboarding to termination.
• Lead cybersecurity evaluations of vendors and collaborate with Cybersecurity Engineering, Legal, and business stakeholders.
• Evaluate vendor maturity utilizing frameworks such as NIST CSF, CIS, CMMC, GDPR, PCI DSS, SOC 2, and others.
• Supervise vendor SLAs, RPO/RTO commitments, breach notification protocols, and cybersecurity insurance documentation.
• Record findings, suggestions, and remediation strategies based on vendor evaluations.
• Collaborate with internal and external auditors regarding vendor-related controls and evidence gathering.
• Provide documentation, evidence, and control validation for SOC 2 Type II and PCI DSS evaluations.
• Keep audit-ready documentation, including policies, standards, procedures, and risk treatment strategies.
• Monitor vendor exceptions and compensating controls.
• Assist with vulnerability notifications to clients managing their own cybersecurity controls.
• Offer consultative guidance to clients on risk implications, remediation expectations, and cybersecurity practices.
• Maintain documentation and metrics for client notifications, follow-up actions, and resolution.
• Enhance the ISMS by aligning vendor risk processes with company policies, standards, and procedures.
• Contribute to control selection, risk treatment strategies, and metrics for cybersecurity control effectiveness.
• Stay informed on emerging threats, regulatory updates, and industry trends impacting third-party risk.
• Assist in disaster recovery and business continuity planning concerning vendor dependencies and resilience.
• Collaborate with Legal, Cybersecurity, and leadership on strategies for mitigating vendor-related risks.
• Foster a cybersecurity culture throughout the enterprise via outreach, training, and awareness initiatives.
• Provide professional, consultative support to internal and external stakeholders.
• Mentor team members and aid in the development of internal training resources and documentation.
• Over 5 years of experience in cybersecurity, risk management, audit, or compliance.
• In-depth knowledge of PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST.
• Experience assessing both legacy and modern cloud technologies, including AWS, GCP, and Azure.
• Strong understanding of APIs, application cybersecurity, encryption, endpoint, and network security concepts.
• Familiarity with SIEM, IDS, log management, vulnerability management, and threat intelligence.
• Ability to evaluate vendor controls, align them with frameworks, and explain risks to non-technical stakeholders.
• Exceptional project management, multitasking, and organizational abilities.
• Outstanding written and verbal communication skills.
• Experience supporting SOC 2 Type II and PCI DSS audits is preferred.
• Familiarity with EGRC/ITGRC platforms such as Jira Service Manager GRC, Archer, OneTrust, and LogicGate is preferred.
• Certifications like CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP are preferred.
• Must be eligible to work in the United States without sponsorship.
• Minimum age requirement of 18.
• Medical, Dental & Vision Benefits.
• 401(k) Savings Plan with Company Match.
• Flexible Planned Paid Time Off.
• Generous Sick Leave.
• Inclusive & Welcoming Environment.
• Purpose-Driven Culture.
• Work-Life Balance.
• Commitment to Community Involvement.
• Employer-Paid Parental Leave.
• Employer-Paid Short-Term Disability.
• Remote Work Flexibility.
Funcional Health Tech
CACI International Inc
Bold
Get handpicked remote jobs straight to your inbox weekly.