Senior Analyst for Third-Party Security at a leading law firm. Responsible for program execution and risk assessment regarding vendors and service providers.
Responsibilities
Conduct information security due diligence including secure by design reviews, during vendor onboarding, at renewal, and periodic review cycles.
Apply a risk-based approach to third party security assessments, including documenting compensating controls and risks acceptances where appropriate.
Evaluate third-party architectures, including network connectivity (VPN, reverse proxy), data flows, encryption models, and access controls.
Assess risks related to cloud environments (AWS/Azure/GCP), SaaS platforms, and API integrations.
Analyze external risk intelligence sources (e.g., BitSight, SecurityScorecard) and correlate with internal findings.
Review and challenge secure design, identity/access models (SSO, OAuth, SCIM), and data protection mechanisms.
Enhance and maintain a comprehensive vendor inventory, including vendor profiling and inherent risk determination.
Enhance and maintain a third-party risk register and track mitigation efforts for identified security risks.
Develop and implement strategies to mitigate identified risks, working closely with third parties and internal stakeholders to address security gaps.
Support a continuous monitoring program to assess third-party security posture and follow up on identified vulnerabilities and security risks.
Partner with general counsel and vendor management to incorporate information security requirements into third-party contracts.
Work with internal security teams to investigate and respond to third-party related security incidents.
Support and enhance escalation procedures and remediation requirements related to third-party security breaches.
Prepare and present third-party risk metrics, dashboards, trends, and highlighted risks to senior management and IT leadership.
Contribute to the continuous improvement and scalability of the Firm’s third-party security risk management program.
Partner with the Third Party Security Senior Manager to build and enhance strategic objectives of the program.
Requirements
Bachelor’s degree or related experience required
10+ years of progressive experience in information security, third-party risk management, IT risk, or cybersecurity assurance, with at least 3 years focused on third party risk management.
Strong understanding of information security controls and frameworks (ISO 27001/27002, NIST CSF, CIS Controls, etc.)
Proficient understanding of third-party security domains, including data protection, access controls, incident response and cloud security.
Proven ability to perform third-party security risk assessments by reviewing security questionnaires, audit reports, policies and penetration test results to identify control gaps, formulate follow-up inquiries, and document remediation requirements.
Deep knowledge of technology supplier ecosystems (software, cloud, IT labor, and infrastructure) and associated risk dynamics.
Network Security Engineer maintaining network stability and security at Clearwater Paper. Responsible for operational support, troubleshooting, and security administration across enterprise networks.
Analista de Application Security Pleno ensuring code integrity and security at Evertec, a tech company for the financial sector in Brazil. Responsible for security scanning, remediation support, and CI/CD integration.
Senior Application Security Analyst ensuring code integrity and security at Evertec, leading security strategies and initiatives in software development.
Senior Principal Security Engineer at Workday acting as technical contact for Enterprise Security. Bridging cybersecurity strategy with hands - on execution to tackle complex security challenges.
Leitung des Sachgebiets Infrastruktur und Sicherheit mit Verantwortung für den Betrieb der technischen Basisdienste. Enger Austausch mit Amtsleitung und Fachbereichen zur IT - Strategie der Stadt Elmshorn.
As a Producer, support the Senior Producer in delivering AAA projects for Behaviour Interactive, a gaming industry leader. Collaborate with the leadership team to ensure high - quality product alignment.
Business Information Security Officer responsible for ensuring cybersecurity compliance in Europe for Boeing. Leading regional security initiatives and managing relationships with stakeholders across the continent.
IT Cybersecurity Specialist handling technical support in information security for MODEC's operations. Ensuring strategic and compliance alignment with global cybersecurity standards.
Product Security Engineer ensuring security in cloud - native product development at Trainline. Collaborating with cross - functional teams to improve security practices and safeguard digital channels.
Information Security Engineer supporting day - to - day information security operations. Working with cross - functional partners to ensure security compliance and risk management.