
1001 - 5000 employees
đ¤ B2B
đ¤ Non-profit
B2B ⢠Non-profit ⢠Software
Momentive Software is a provider of a comprehensive suite of software solutions tailored for nonprofits and associations. The company aims to streamline operations, enhance member and donor engagement, and drive impactful results for mission-driven organizations. Their offerings include tools for association management, fundraising, event management, learning management, and data analytics, allowing organizations to efficiently manage their financials and foster deeper community connections.
đĽ 2 minutes ago
Improve your chances of getting an interview by checking your resume score before you apply.

1001 - 5000 employees
đ¤ B2B
đ¤ Non-profit
B2B ⢠Non-profit ⢠Software
Momentive Software is a provider of a comprehensive suite of software solutions tailored for nonprofits and associations. The company aims to streamline operations, enhance member and donor engagement, and drive impactful results for mission-driven organizations. Their offerings include tools for association management, fundraising, event management, learning management, and data analytics, allowing organizations to efficiently manage their financials and foster deeper community connections.
⢠Maintain Momentive's global inventory of third-party providers, applications, and services from onboarding through termination ⢠Lead vendor cybersecurity assessments and coordinate with Cybersecurity Engineering, Legal, and business owners ⢠Assess vendor maturity using NIST CSF, CIS, CMMC, GDPR, PCI DSS, SOC 2, and other frameworks ⢠Oversee vendor SLAs, RPO/RTO commitments, breach notification requirements, and cybersecurity insurance documentation ⢠Document findings, recommendations, and remediation plans for vendor assessments ⢠Liaise with internal and external auditors on vendor-related controls and evidence collection ⢠Provide evidence, documentation, and control validation for SOC 2 Type II and PCI DSS assessments ⢠Maintain audit-ready documentation, including policies, standards, procedures, and risk treatment plans ⢠Track vendor exceptions and compensating controls ⢠Support vulnerability notifications to clients who manage their own cybersecurity controls ⢠Provide consultative guidance to clients on risk impact, remediation expectations, and cybersecurity practices ⢠Maintain documentation and metrics for client notifications, follow-up actions, and closure ⢠Improve the ISMS by aligning vendor risk processes with company policies, standards, and procedures ⢠Provide input on control selection, risk treatment plans, and cybersecurity control effectiveness metrics ⢠Monitor emerging threats, regulatory changes, and industry trends affecting third-party risk ⢠Support disaster recovery/business continuity planning related to vendor dependencies and resiliency ⢠Coordinate with Legal, Cybersecurity, and leadership on vendor-related risk reduction strategies ⢠Promote enterprise-wide cybersecurity culture through outreach, training, and awareness activities ⢠Support internal and external stakeholders with professional, consultative service ⢠Mentor team members and contribute to internal training materials and documentation
⢠5+ years of experience in cybersecurity, risk management, audit, or compliance ⢠Deep understanding of PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST ⢠Experience evaluating legacy and modern cloud technologies, including AWS, GCP, and Azure ⢠Strong knowledge of APIs, application cybersecurity, encryption, endpoint, and network cybersecurity concepts ⢠Familiarity with SIEM, IDS, log management, vulnerability management, and threat intelligence ⢠Ability to assess vendor controls, map them to frameworks, and articulate risk to non-technical stakeholders ⢠Strong project management, multitasking, and organizational skills ⢠Excellent written and verbal communication skills ⢠Experience supporting SOC 2 Type II and PCI DSS audits preferred ⢠Experience with EGRC/ITGRC platforms such as Jira Service Manager GRC, Archer, OneTrust, and LogicGate preferred ⢠Certifications such as CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP preferred ⢠Eligibility to work in the United States without sponsorship ⢠Minimum age of 18
⢠Medical, Dental & Vision Benefits ⢠401(k) Savings Plan with Company Match ⢠Flexible Planned Paid Time Off ⢠Generous Sick Leave ⢠Inclusive & Welcoming Environment ⢠Purpose-Driven Culture ⢠Work-Life Balance ⢠Commitment to Community Involvement ⢠Employer-Paid Parental Leave ⢠Employer-Paid Short-Term Disability ⢠Remote Work Flexibility
Apply NowđĽ 4 hours ago
ServiceNow Business Analyst translating federal customersâ business requirements into ServiceNow ITSM solutions. Supporting implementations, testing, stakeholder adoption, and ongoing platform improvement.
đşđ¸ United States â Remote
đľ $85k - $105k / year
â° Full Time
đĄ Mid-level
đ Senior
đ§ Business Analyst
đĽ 6 hours ago
Business Analyst and Scrum Master supporting federal data integration for Miami Technology Solutions. Translating stakeholder needs into Agile backlogs and coordinating delivery from discovery through validation.
đĽ 13 hours ago
Security Business Analyst improving client security outcomes for Thriveâs AI, cybersecurity, and cloud managed services. Leading client meetings, reporting, onboarding, and feedback-driven service improvements.
đ Yesterday
Senior Clinical Business Analyst advancing BlueCross BlueShield of Tennesseeâs medical policy operations. Applying healthcare analytics, process improvement, interoperability, and AI-enabled solutions.
đ Yesterday
Senior Medicaid Business Analyst translating Medicaid policy into MMIS configuration and design artifacts. Supporting testing, deployment, and client delivery for Gainwellâs healthcare technology services.
đşđ¸ United States â Remote
đľ $69.4k - $99.2k / year
đ° Grant on 2023-06
â° Full Time
đ Senior
đ§ Business Analyst
đŚ H1B Visa Sponsor