Third Party Cyber Risk Analyst
Third-Party Cyber Risk Analyst
A global financial services organization is seeking an Information Security & Third-Party Risk Analyst to support the oversight of vendor and external partner risk. This individual will play a key role in evaluating the cybersecurity posture of suppliers, service providers, and other external organizations that support business operations.
The successful candidate will partner with stakeholders across risk, technology, legal, compliance, and procurement teams to ensure third-party relationships meet established security standards and regulatory expectations.
Key Responsibilities
- Evaluate cybersecurity and technology risks associated with new and existing third-party relationships.
- Analyze security artifacts such as SOC reports, independent audit reports, business continuity plans, information security policies, penetration testing results, and certification documentation.
- Identify control gaps, document findings, and assign risk ratings based on established assessment methodologies.
- Support vendor onboarding, contract reviews, renewals, and termination activities from a security risk perspective.
- Monitor ongoing third-party cybersecurity developments, incidents, and emerging risks that could affect the organization.
- Maintain accurate records within third-party risk management systems and ensure timely completion of risk reviews.
- Collaborate with internal stakeholders to track remediation efforts and risk mitigation activities.
- Assist with regulatory examinations, audit requests, and governance initiatives related to third-party risk oversight.
- Contribute to the enhancement of risk management procedures, standards, and operating practices.
Desired Background
- Experience conducting technology, cybersecurity, or vendor risk assessments.
- Working knowledge of the third-party risk management lifecycle.
- Familiarity with industry frameworks and standards such as NIST, ISO 27001, CRI Profile, or similar control frameworks.
- Experience reviewing independent assurance reports including SOC 1 and SOC 2 examinations.
- Understanding of information security principles including access management, business continuity, incident response, data protection, and cybersecurity governance.
- Familiarity with vendor risk management platforms and workflow tools.
- Strong analytical, organizational, and communication skills.
- Prior experience within banking, financial services, fintech, or other regulated industries is advantageous.
FAQs
Congratulations, we understand that taking the time to apply is a big step. When you apply, your details go directly to the consultant who is sourcing talent. Due to demand, we may not get back to all applicants that have applied. However, we always keep your resume and details on file so when we see similar roles or see skillsets that drive growth in organizations, we will always reach out to discuss opportunities.
Yes. Even if this role isn’t a perfect match, applying allows us to understand your expertise and ambitions, ensuring you're on our radar for the right opportunity when it arises.
We also work in several ways, firstly we advertise our roles available on our site, however, often due to confidentiality we may not post all. We also work with clients who are more focused on skills and understanding what is required to future-proof their business.
That's why we recommend registering your resume so you can be considered for roles that have yet to be created.
Yes, we help with resume and interview preparation. From customized support on how to optimize your resume to interview preparation and compensation negotiations, we advocate for you throughout your next career move.