Senior Security Risk Management Analyst

Payrate: $70.00 – $75.00/hr.

Summary:
Company is seeking an experienced professional to join our Third-Party/ Vendor Risk Assessment team. This team focuses on analyzing and managing risks associated with our vendors, service providers, and other third parties, ensuring our organization upholds the highest standards of compliance, security, and business resilience. While your primary responsibility will be Third-Party Risk Management, you will also collaborate on other cybersecurity risk management initiatives. Building strong cross-functional relationships across the company is a key component of this role. To excel, you must showcase exceptional leadership, communication, and decision-making skills, and have a proven track record in managing third-party risk, vendor governance, or related domains.

Responsibilities:
• Lead and conduct comprehensive risk assessments of new and existing third-party vendors and service providers, focusing on cybersecurity, and regulatory compliance.
• Evaluate third-party security questionnaires, audit reports (e.g., SOC 2, ISO 27001), and risk documentation.
• Coordinate with vendors to request and verify security controls, remediation plans, and ongoing compliance.
• Oversee facilitation of risk remediation efforts agreed upon with suppliers, ensuring timely resolution.
• Collaborate during supplier contract development, reviewing deviations from security requirements and offering subject matter expertise on risk remediation.
• Classify vendors according to risk tiers and maintain a comprehensive database of vendor risk profiles.
• Participate in continuous security monitoring of existing suppliers to track changing risk profiles.
• Partner with Procurement, Legal, Privacy, and InfoSec teams to improve supplier security management processes.
• Identify opportunities to automate parts of the assessment process, thereby reducing manual work and enhancing efficiency.
• Keep abreast of emerging risks, industry standards, and regulatory requirements affecting third-party vendors.
• Contribute to broader cybersecurity risk management initiatives, including identifying, assessing, and tracking information security risks beyond the third-party domain.
• Provide guidance and knowledge transfer to team members, supporting a collaborative team environment.

Preferred Qualifications:
• Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Risk Management, or a related field.
• 6-8 years of professional experience in third-party risk assessment within cybersecurity or information risk management.
• Understanding of relevant information security frameworks, including related regulatory compliance requirements, such as ISO 27001/2 (including ISO 27017 & 18), FedRAMP, SOC 2 Trust Services Criteria, PCI DSS, NIST CSF.
• Solid understanding of risk assessment methodologies and best practices.
• Ability to synthesize and communicate complex risk findings to both technical and non-technical audiences.
• Detail-oriented, process-driven, and capable of managing multiple vendor assessments concurrently.
• Experience with tools such as Coupa, OneTrust, JIRA and Coverbase is a plus.
• Professional certifications in Information Security or Risk Management (e.g. CISA, CISM, CISSP, CRISC) is a plus.

Pay Transparency: The typical base pay for this role across the U.S. is: $70.00 – $75.00 /hr. Non-exempt positions are eligible for overtime at a rate of 1.5 times the base hourly rate for all hours worked in excess of 40 in a work week, or as required by state or local law. Final offer amounts, within the base pay set forth above, are determined by factors including your relevant skills, education and experience. Full-time employees are eligible to select from different benefits packages. Packages may include medical, dental, and vision benefits, health savings accounts with qualified medical plan enrollment, 10 paid days off, 3 days paid bereavement leave, 401(k) plan participation with employer match, life and disability insurance, commuter benefits, dependent care flexible spending account, accident insurance, critical illness insurance, hospital indemnity insurance, accommodations and reimbursement for work travel, and discretionary performance or recognition bonus. Sick leave and mobile phone reimbursement provided based on state or local law.

Consent to Communication and Use of AI Technology: By submitting your application for this position and providing your email address(es) and/or phone number(s), you consent to receive text (SMS), email, and/or voice communication whether automated (including auto telephone dialing systems or automatic text messaging systems), pre-recorded, AI-assisted, or individually initiated from Aditi Consulting, our agents, representatives, or affiliates at the phone number and/or email address you have provided. These communications may include information about potential opportunities and information. Message and data rates may apply. Message frequency may vary.
You represent and warrant that the email address(es) and/or telephone number(s) you provided to us belong to you and that you are permitted to receive calls, text (SMS) messages, and/or emails at these contacts. You also acknowledge and agree to Aditi Consulting LLC’s use of AI technology during the sourcing process, including calls from an AI Voice Recruiter. AI is used solely to gather data and does not replace human-based decision-making in employment decisions.  Calls may be recorded.

Consent is not a condition of purchasing any property, goods, or services. You may revoke your consent at any time by replying “STOP” to :messages or by contacting [email protected].

For information about our collection, use, and disclosure of applicant’s personal information as well as applicants’ rights over their personal information, please see our Privacy Policy

#AditiConsulting
#26-03881

Location: , ,

Salary: 70 – 75

Benefits:

  • Health Insurance
  • Paid Time Off
  • Dental Coverage

LinkedIn: Apply Here