Lead Analyst, Security Strategy – Assurance

🕒 June 11

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of OutSystems

OutSystems

1001 - 5000 employees

Founded 2001

💼 Consulting

🏥 Healthcare

📣 Marketing

Consulting • Healthcare • Marketing

OutSystems is a software company that provides a low-code application development platform. It allows organizations to develop, deploy, and manage enterprise-grade applications with minimal coding effort. By simplifying the process of application development, OutSystems helps businesses accelerate their digital transformation and improve productivity.

📋 Description

• Own and Mature the Third Party Risk Management Program • Define and drive OutSystems’ TPRM strategy, including risk tiering methodology, assessment frameworks, and ongoing monitoring cadences for critical and high-risk vendors. • Lead end-to-end vendor risk assessments and architect scalable processes that can grow with the business. • Proactively identify gaps between current TPRM practices and industry standards, and build solutions to close them. • Partner with Digital, Procurement, Legal, and Engineering to embed risk requirements into vendor selection and contracting, influencing how partner teams operate. • Maintain the vendor risk inventory, track remediation of identified issues, and report status to leadership with clarity and consistency. • Monitor the threat and regulatory landscape for developments that affect the third-party risk surface. • Own and evolve the enterprise risk register for the Security division, ensuring risks are consistently identified, assessed, and treated across business units. • Design and facilitate risk workshops with functional and business leaders to surface emerging risks and validate control effectiveness. • Develop key risk indicators (KRIs) and produce executive-level risk reporting, including dashboards and trend analyses, that connect security posture to business outcomes. • Integrate risk management into business planning cycles and cross-functional initiatives, ensuring security considerations are embedded early. • Serve as a senior contributor to compliance programs supporting certifications such as SOC 2, ISO 27001, PCI, HIPAA, and regional regulatory frameworks, elevating the work beyond execution to program ownership and continuous improvement.

🎯 Requirements

• Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience. • 7–10 years of experience in information security, risk management, or compliance, with at least 3–4 years focused on third-party or vendor risk. • Demonstrated experience owning and maturing a TPRM program, including framework design, risk tiering, and remediation management. • Strong working knowledge of enterprise risk management frameworks (e.g., NIST RMF, ISO 31000, COSO) and security control frameworks (ISO 27001, SOC 2, NIST CSF). • Experience supporting or leading internal and external audits across certifications such as SOC 2, ISO 27001, or equivalent. • Ability to operate with significant autonomy, define scope on complex and ambiguous projects, and drive cross-functional alignment. • Excellent communication skills

🏖️ Benefits

• Professional development opportunities • Flexible working hours • Health insurance • Remote work options

Apply Now

Similar Jobs

🕒 June 10

Simple Technology Solutions

51 - 200

💼 Consulting

🏥 Healthcare

📦 Logistics

Security Engineer with ISSO Support responsibility on federal data engineering team. Protecting sensitive financial data and ensuring compliance with federal security requirements.

AWS

🕒 June 10

Tevora

201 - 500

🏥 Healthcare

🛡️ Insurance

⚖️ Legal

Senior Pre-Sales Security Architect serving as strategic advisor in cybersecurity for enterprise clients. Bridging cybersecurity strategy, solution architecture, and commercial execution across a broad partner ecosystem.

AWS

Cloud

Cyber Security

🕒 June 10

Doppel

1 - 10

💼 Consulting

📦 Logistics

📣 Marketing

Manage Email Security Architects at Doppel, providing social engineering defense for clients. Establish operational excellence and guide customers in their security deployments.

🕒 June 9

Aimpoint Digital

51 - 200

🤖 Artificial Intelligence

💼 Consulting

Lead AI Security Architect at Aimpoint Digital designing secure AI security architectures for enterprise implementations. Transforming risk management in generative AI across various industries.

AWS

Azure

BigQuery

Cloud

Cyber Security

Google Cloud Platform

Python

SDLC

Splunk

Terraform

🕒 June 9

KITC, LLC (8(a) SDB)

11 - 50

🔒 Cybersecurity

🏛️ Government

💼 Consulting

Security Control Assessor evaluating cybersecurity controls for state agencies. Conducting assessments aligned to NIST CSF 2.0 and documenting findings and recommendations.

Cyber Security