Third-Party Cyber Risk Specialist
Core
Execute risk management programs for third-party vendors and service providers, focusing on cyber threats and vulnerabilities within the ecosystem.
Role type
Third-party cyber risk specialist
Builds
Vendor security posture assessments and compliance documentation
Domain
Financial services / Cybersecurity risk management
Deliverable
client delivery
Required skills
Third-party risk management, vendor management, security incident response, cyber management, NIST framework knowledge, SOC 2 compliance, GDPR compliance, ISO 27001 compliance, vendor risk assessments, third-party risk platforms
Preferred skills
Vendor risk management platforms experience
Technologies
Questionnaires, security tools, response management software
Responsibilities
Manage incoming client requests for assessments and questionnaires; Facilitate communication between business, legal, technology, and information security teams; Serve as a point of contact for internal stakeholders regarding client due diligence inquiries; Function as the subject matter expert for response management software; Manage and maintain a standardized library of responses for client due diligence questionnaires; Assist team with onboarding new vendor relationships; Collect, review, and process information and documentation from third-party vendors; Conduct third-party risk assessments and due diligence reviews; Perform comprehensive security reviews of potential and existing third-party vendors; Analyze identified risks and prioritize them based on impact and likelihood; Coordinate with internal security team to respond to cyber incidents involving third-party vendors; Assist with regulatory exams by obtaining documentation and drafting responses to regulator inquiries.
Seniority
Mid-level, hands-on IC