Information Security Analyst (f/m/x)
Core
Conduct Information Security Third Party risk assessments, including onsite reviews, and manage security risks for third-party vendors.
Role type
Information Security Analyst (Third Party Risk)
Builds
Security control framework and risk assessment processes for third-party vendors
Domain
Financial Services / Information Security / Third-Party Risk Management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IT and Information Security controls, risk management, ISO27001, NIST, ENISA, SOC2, PCI, MITRE ATT&CK, financial regulations (DORA, GDPR, NYDFS), Cloud Security Alliance tools (CCM, CAIQ)
Preferred skills
data reporting, MS Office Suite
Responsibilities
Conduct Information Security Third Party risk assessments, Review Third Party policies and evidence against DB security requirements, Analyze and document security gaps and their business impact, Coordinate Third Party Information Security Review processes and escalate issues, Support improvements to the security control framework and stakeholder communication
Seniority
Individual Contributor