Lead Analyst, Security Strategy – Assurance

🕒 June 11

🇺🇸 United States – Remote

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of OutSystems

OutSystems

1001 - 5000 employees

Founded 2001

💼 Consulting

🏥 Healthcare

📣 Marketing

Consulting • Healthcare • Marketing

OutSystems is a software company that provides a low-code application development platform. It allows organizations to develop, deploy, and manage enterprise-grade applications with minimal coding effort. By simplifying the process of application development, OutSystems helps businesses accelerate their digital transformation and improve productivity.

📋 Description

• Own and Mature the Third Party Risk Management Program • Define and drive OutSystems’ TPRM strategy, including risk tiering methodology, assessment frameworks, and ongoing monitoring cadences for critical and high-risk vendors. • Lead end-to-end vendor risk assessments and architect scalable processes that can grow with the business. • Proactively identify gaps between current TPRM practices and industry standards, and build solutions to close them. • Partner with Digital, Procurement, Legal, and Engineering to embed risk requirements into vendor selection and contracting, influencing how partner teams operate. • Maintain the vendor risk inventory, track remediation of identified issues, and report status to leadership with clarity and consistency. • Monitor the threat and regulatory landscape for developments that affect the third-party risk surface. • Own and evolve the enterprise risk register for the Security division, ensuring risks are consistently identified, assessed, and treated across business units. • Design and facilitate risk workshops with functional and business leaders to surface emerging risks and validate control effectiveness. • Develop key risk indicators (KRIs) and produce executive-level risk reporting, including dashboards and trend analyses, that connect security posture to business outcomes. • Integrate risk management into business planning cycles and cross-functional initiatives, ensuring security considerations are embedded early. • Serve as a senior contributor to compliance programs supporting certifications such as SOC 2, ISO 27001, PCI, HIPAA, and regional regulatory frameworks, elevating the work beyond execution to program ownership and continuous improvement.

🎯 Requirements

• Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience. • 7–10 years of experience in information security, risk management, or compliance, with at least 3–4 years focused on third-party or vendor risk. • Demonstrated experience owning and maturing a TPRM program, including framework design, risk tiering, and remediation management. • Strong working knowledge of enterprise risk management frameworks (e.g., NIST RMF, ISO 31000, COSO) and security control frameworks (ISO 27001, SOC 2, NIST CSF). • Experience supporting or leading internal and external audits across certifications such as SOC 2, ISO 27001, or equivalent. • Ability to operate with significant autonomy, define scope on complex and ambiguous projects, and drive cross-functional alignment. • Excellent communication skills

🏖️ Benefits

• Professional development opportunities • Flexible working hours • Health insurance • Remote work options

Apply Now

Similar Jobs

🕒 June 10

Simple Technology Solutions

51 - 200

💼 Consulting

🏥 Healthcare

📦 Logistics

Security Engineer with ISSO Support responsibility on federal data engineering team. Protecting sensitive financial data and ensuring compliance with federal security requirements.

🕒 June 10

Tevora

201 - 500

🏥 Healthcare

🛡️ Insurance

⚖️ Legal

Senior Pre-Sales Security Architect serving as strategic advisor in cybersecurity for enterprise clients. Bridging cybersecurity strategy, solution architecture, and commercial execution across a broad partner ecosystem.

🕒 June 10

Doppel

1 - 10

💼 Consulting

📦 Logistics

📣 Marketing

Manage Email Security Architects at Doppel, providing social engineering defense for clients. Establish operational excellence and guide customers in their security deployments.

🕒 June 9

Aimpoint Digital

51 - 200

🤖 Artificial Intelligence

💼 Consulting

Lead AI Security Architect at Aimpoint Digital designing secure AI security architectures for enterprise implementations. Transforming risk management in generative AI across various industries.

🕒 June 9

Akamai Technologies

5001 - 10000

🔒 Cybersecurity

API Security Sales Specialist empowering world-leading companies with cybersecurity solutions. Collaborating across teams to achieve customer success and driving sales growth with entrepreneurial expertise.