Security Analyst III
You will conduct vendor and internal risk assessments, respond to security questionnaires, and collect audit evidence. You will identify security risks, deliver awareness training, maintain compliance metrics, partner across business functions, and improve security controls and workflows.
Responsibilities
- Conduct third-party vendor risk assessments and internal risk evaluations
- Identify, document, and report vulnerabilities and control gaps
- Respond to vendor security questionnaires and prospect security questions
- Collect evidence for SOC 2 and ISO 27001 audits
- Identify emerging threats and develop practical security solutions
- Deliver security awareness training
- Assure compliance with external regulations
- Maintain security and compliance metrics
- Partner with business functions to enforce security policies
- Improve security controls and workflows
Requirements
- Bachelor’s degree in information security assurance, business management, or a related field
- 3+ years of experience in third-party risk management, GRC, or customer due diligence
- NIST 800-53
- ISO 27001
- SOC 2
- Risk management
- Cloud application familiarity preferred
- CRISC preferred
- CISSP preferred
- CISA preferred
- SSCP preferred
- CC preferred
- Security+ preferred
- CySA+ preferred
- AWS preferred
- GCP preferred
- Azure preferred
- GRC automation
Benefits
- Hybrid workplace with remote, office-based, or combined work options depending on role and team needs