Senior Information Security Analyst, Third-Party Security and Data Breach Expert (T & I) (Telework/Hybrid)
Core
Lead the organization-wide Third-Party Risk Management (TPRM) program, overseeing vendor security assessments, defining risk frameworks, and managing data breach response for external partners.
Role type
Senior IC Information Security Analyst (Third-Party Risk & Data Breach)
Builds
Third-Party Risk Management (TPRM) program, risk registers, and security compliance frameworks for vendors.
Domain
Information Security, Third-Party Risk Management, Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Third-Party Risk Management (TPRM), security assessment methodologies, regulatory compliance (GDPR, Law 25), contractual security requirements, risk mitigation strategies, vendor negotiation, security incident response, risk register management, security standards (ISO 27001, NIST), cloud architecture security, network security, cryptographic principles, business continuity planning.
Preferred skills
CISSP, CRISC, CBCP, CISA, CISM certifications.
Technologies
ISO/IEC 27001, NIST SP 800-53, COBIT, ITIL, SOC 2 Type II, GDPR, Law 25, firewalls, IDS/IPS, DNS, encryption.
Responsibilities
Lead and oversee the organization-wide TPRM program from process development to implementation. Define and maintain third-party risk classification frameworks and security assessment questionnaires. Evaluate third-party security posture by reviewing SOC 2, ISO 27001, and penetration test results. Assess security gaps and formulate risk mitigation strategies or compensating controls. Define and validate complex contractual security requirements including audit rights and incident notification SLAs. Negotiate directly with vendor security leaders to enforce organizational security requirements. Provide technical leadership during third-party security incidents or data breaches. Maintain an up-to-date mapping and inventory of all external partners and their risk levels. Schedule and perform ongoing security evaluations based on vendor criticality. Produce governance dashboards and metrics (KPIs/KRIs) for leadership. Advance the TPRM strategy in response to emerging cyber threats and regulatory updates.
Seniority
Senior, hands-on IC
