Search Remote Jobs

Senior Third-Party Risk Management Analyst

Job not on LinkedIn

🔥 2 minutes ago

🇺🇸 United States – Remote

⏰ Full Time

🟠 Senior

🧐 Business Analyst

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Momentive Software

Momentive Software

1001 - 5000 employees

🤝 B2B

🤝 Non-profit

B2B • Non-profit • Software

Momentive Software is a provider of a comprehensive suite of software solutions tailored for nonprofits and associations. The company aims to streamline operations, enhance member and donor engagement, and drive impactful results for mission-driven organizations. Their offerings include tools for association management, fundraising, event management, learning management, and data analytics, allowing organizations to efficiently manage their financials and foster deeper community connections.

📋 Description

• Maintain Momentive's global inventory of third-party providers, applications, and services from onboarding through termination • Lead vendor cybersecurity assessments and coordinate with Cybersecurity Engineering, Legal, and business owners • Assess vendor maturity using NIST CSF, CIS, CMMC, GDPR, PCI DSS, SOC 2, and other frameworks • Oversee vendor SLAs, RPO/RTO commitments, breach notification requirements, and cybersecurity insurance documentation • Document findings, recommendations, and remediation plans for vendor assessments • Liaise with internal and external auditors on vendor-related controls and evidence collection • Provide evidence, documentation, and control validation for SOC 2 Type II and PCI DSS assessments • Maintain audit-ready documentation, including policies, standards, procedures, and risk treatment plans • Track vendor exceptions and compensating controls • Support vulnerability notifications to clients who manage their own cybersecurity controls • Provide consultative guidance to clients on risk impact, remediation expectations, and cybersecurity practices • Maintain documentation and metrics for client notifications, follow-up actions, and closure • Improve the ISMS by aligning vendor risk processes with company policies, standards, and procedures • Provide input on control selection, risk treatment plans, and cybersecurity control effectiveness metrics • Monitor emerging threats, regulatory changes, and industry trends affecting third-party risk • Support disaster recovery/business continuity planning related to vendor dependencies and resiliency • Coordinate with Legal, Cybersecurity, and leadership on vendor-related risk reduction strategies • Promote enterprise-wide cybersecurity culture through outreach, training, and awareness activities • Support internal and external stakeholders with professional, consultative service • Mentor team members and contribute to internal training materials and documentation

🎯 Requirements

• 5+ years of experience in cybersecurity, risk management, audit, or compliance • Deep understanding of PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST • Experience evaluating legacy and modern cloud technologies, including AWS, GCP, and Azure • Strong knowledge of APIs, application cybersecurity, encryption, endpoint, and network cybersecurity concepts • Familiarity with SIEM, IDS, log management, vulnerability management, and threat intelligence • Ability to assess vendor controls, map them to frameworks, and articulate risk to non-technical stakeholders • Strong project management, multitasking, and organizational skills • Excellent written and verbal communication skills • Experience supporting SOC 2 Type II and PCI DSS audits preferred • Experience with EGRC/ITGRC platforms such as Jira Service Manager GRC, Archer, OneTrust, and LogicGate preferred • Certifications such as CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP preferred • Eligibility to work in the United States without sponsorship • Minimum age of 18

🏖️ Benefits

• Medical, Dental & Vision Benefits • 401(k) Savings Plan with Company Match • Flexible Planned Paid Time Off • Generous Sick Leave • Inclusive & Welcoming Environment • Purpose-Driven Culture • Work-Life Balance • Commitment to Community Involvement • Employer-Paid Parental Leave • Employer-Paid Short-Term Disability • Remote Work Flexibility

Apply Now

Similar Jobs

🔥 4 hours ago

Electrosoft

51 - 200

🔒 Cybersecurity

🤖 Artificial Intelligence

🏛️ Government

ServiceNow Business Analyst translating federal customers’ business requirements into ServiceNow ITSM solutions. Supporting implementations, testing, stakeholder adoption, and ongoing platform improvement.

🔥 6 hours ago

Miami Federal

51 - 200

🏛️ Government

🏗️ Construction

💼 Consulting

Business Analyst and Scrum Master supporting federal data integration for Miami Technology Solutions. Translating stakeholder needs into Agile backlogs and coordinating delivery from discovery through validation.

🔥 13 hours ago

Thrive

1001 - 5000

🔒 Cybersecurity

💼 Consulting

Security Business Analyst improving client security outcomes for Thrive’s AI, cybersecurity, and cloud managed services. Leading client meetings, reporting, onboarding, and feedback-driven service improvements.

🕒 Yesterday

BlueCross BlueShield of Tennessee

5001 - 10000

🏥 Healthcare

💼 Consulting

🛡️ Insurance

Senior Clinical Business Analyst advancing BlueCross BlueShield of Tennessee’s medical policy operations. Applying healthcare analytics, process improvement, interoperability, and AI-enabled solutions.

🕒 Yesterday

Gainwell Technologies

10,000+ employees

💼 Consulting

📦 Logistics

⚕️ Healthcare Insurance

Senior Medicaid Business Analyst translating Medicaid policy into MMIS configuration and design artifacts. Supporting testing, deployment, and client delivery for Gainwell’s healthcare technology services.