The Third-Party Risk Analyst manages and mitigates risks associated with the company’s third-party relationships. This role involves assessing and monitoring third-party vendors, conducting in-depth risk assessments, and working collaboratively across departments to ensure vendors meet security, compliance, and operational standards. The ideal candidate will have a strong background in risk management, vendor assessments, and regulatory compliance, with the ability to develop and implement effective third-party risk management strategies.
Bachelor’s degree in Information Security, Risk Management, Business, or a related field. Relevant certifications such as CTPRP, CTPRA, or TPCRA a plus.
Minimum of 2+ years of experience in third-party risk management, vendor management, or a related field.
Understanding of cybersecurity principles, data privacy laws, and regulatory requirements.
Familiarity with third-party risk management tools and platforms (e.g., Black Kite, Vanta).
Proficient in risk management frameworks (NIST, ISO 27001/27018, FAIR)
A Strong analytical and problem-solving skills, with the ability to interpret complex risk data and make informed decisions.
Excellent written and verbal communication skills, capable of articulating complex risk concepts to technical and non-technical audiences.
Meticulous with an eye for identifying risks and gaps in vendor assessments.
Ability to work cross-functionally with various departments, balancing diverse perspectives and objectives.