Lead Analyst, Security Strategy & Assurance
Core
Lead the Third Party Risk Management (TPRM) program and drive enterprise risk activities to shape how the organization manages risk across its vendor ecosystem and broader business.
Role type
Lead Analyst, Security Strategy & Assurance
Builds
Scalable TPRM processes, enterprise risk registers, and compliance programs supporting SOC 2, ISO 27001, PCI, and HIPAA.
Domain
Information Security, Risk Management, Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Third-party risk management, enterprise risk management frameworks (NIST RMF, ISO 31000, COSO), security control frameworks (ISO 27001, SOC 2, NIST CSF), audit management, program ownership, cross-functional alignment
Preferred skills
GRC platforms, emerging third-party risk regulations (DORA, NIS2, CMMC), PCI DSS, HIPAA, SaaS/cloud environment experience, mentoring
Technologies
GRC platforms
Responsibilities
Define and drive TPRM strategy including risk tiering and assessment frameworks; lead end-to-end vendor risk assessments; own and evolve the enterprise risk register; develop key risk indicators and executive-level risk reporting; serve as primary point of contact for internal and external audits; mentor team members and develop policies and standards
Seniority
Senior, hands-on IC with mentorship responsibilities