1

Grc Third Party Risk Analyst Jobs in Alabama (NOW HIRING)

Logan, Everest's growing proprietary 3rd party capital platform, covering the respective risk oversight responsibilities such as RCSAs, Operational Risk Heatmap and risk assessments of strategic ...

... Third-Party Risk Management workstreams in partnership with architects and product owners ... Experience with Performance Analytics, Predictive Intelligence, Now Assist, or generative ...

... Third-Party Risk Management workstreams in partnership with architects and product owners ... Experience with Performance Analytics, Predictive Intelligence, Now Assist, or generative ...

Governance, Risk, and Compliance (GRC) Reports To: GRC Manager Employment Type: Full-Time Exempt ... Mentor GRC Analysts and GRC Consultants while contributing to the continuous improvement of MAD ...

Governance, Risk, and Compliance (GRC) Reports To: GRC Manager Employment Type: Full-Time Exempt ... Mentor GRC Analysts and GRC Consultants while contributing to the continuous improvement of MAD ...

Working knowledge of secure systems engineering and software assurance, including static analysis, secure configuration, FOSS/third-party risk, SBOM concepts, and OWASP/DISA application-security ...

Working knowledge of secure systems engineering and software assurance, including static analysis, secure configuration, FOSS/third-party risk, SBOM concepts, and OWASP/DISA application-security ...

Working knowledge of secure systems engineering and software assurance, including static analysis, secure configuration, FOSS/third-party risk, SBOM concepts, and OWASP/DISA application-security ...

... risk registers Prepare documentation and participate in quarterly ISMS and GRC reporting cycles Operates under the direction of the GRC Manager with a focus on execution and coordination, not ...

Independently performs ad hoc analysis of often complex credit risk issues, frequently requiring ... Twelve (12) years of credit-related experience, or eight (8) years of third line of defense credit ...

... third-party reports for accuracy and compliance with Investor requirements and participate in the ... Analyze and evaluate borrower ownership structures to ensure that the application meets ...

Internal Audit Manager

Huntsville, AL · On-site

$94K - $124K/yr

Experience with third-party risk management programs. * Working knowledge of IT General Controls ... Curious, analytical, and highly collaborative. * A strategic thinker who can balance risk ...

Showing results 21-40

Grc Third Party Risk Analyst information

What is a GRC Third Party Risk Analyst?

A GRC Third Party Risk Analyst is a professional who assesses and manages the risks associated with an organization’s external vendors, suppliers, or partners. Their role involves evaluating third-party compliance with regulatory standards and internal policies, identifying potential risks such as data breaches or non-compliance, and recommending mitigation strategies. They use frameworks like GRC (Governance, Risk, and Compliance) to help ensure that third-party relationships do not compromise the organization's security or reputation. This role often collaborates with procurement, legal, and IT teams to maintain robust risk management processes.

What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?

As a GRC Third Party Risk Analyst, you may face challenges such as obtaining timely and complete responses from vendors, especially when dealing with large or international organizations. Navigating varying levels of vendor maturity in risk management practices can also be difficult. Additionally, balancing the need for thorough risk assessments with fast-paced business timelines requires strong communication and prioritization skills. Collaborating closely with procurement, legal, and IT teams is essential to ensure all risks are properly identified and managed.

What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?

To thrive as a GRC Third Party Risk Analyst, you need a strong understanding of risk management frameworks, compliance regulations, and vendor risk assessment methodologies, typically supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (like Archer or ServiceNow), third-party risk management tools, and certifications such as CISA or CRISC is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills are essential soft skills for this role. These competencies ensure that organizations can accurately assess and mitigate third-party risks, maintaining compliance and protecting sensitive data.

What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?

AspectGrc Third Party Risk AnalystGrc Vendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSame certifications commonly required
Work EnvironmentFocuses on third-party relationships and risk assessmentsPrimarily evaluates vendor-specific risks and compliance
Industry UsageUsed across finance, healthcare, and tech sectorsCommonly found in industries with extensive vendor networks

The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

What are popular job titles related to Grc Third Party Risk Analyst jobs in Alabama?

For Grc Third Party Risk Analyst jobs in Alabama, the most frequently searched job titles are:

What job categories do people searching Grc Third Party Risk Analyst jobs in Alabama look for?

The top searched job categories for Grc Third Party Risk Analyst jobs in Alabama are:

What cities in Alabama are hiring for Grc Third Party Risk Analyst jobs?

Cities in Alabama with the most Grc Third Party Risk Analyst job openings:

Infographic showing various Grc Third Party Risk Analyst job openings in Alabama as of August 2026, with employment types broken down into 100% Full Time. Highlights an 84% In-person, 8% Hybrid, and 8% Remote job distribution.

Chief Information Security Officer

Origin Bank

Mobile, AL

Full-time

Re-posted yesterday


Job description

Your Career. Your Story. Let's Write the Next Chapter Together.

At Origin Bank, a job isn't just a paycheck - it's a meaningful journey. We're committed to helping you grow both professionally and personally in an environment where people come first. We offer a competitive total rewards package, including generous benefits and compensation tailored to your skills, experience, and education.

What truly sets us apart is our people-first culture. Here, you'll be supported by unique initiatives like our Dream Manager program, one-on-one guidance from a nationally certified health and wellness coach, and free access to certified financial professionals who are here to help you plan for your future.

If you're looking for a career that empowers you to make meaningful connections, positively impact others, and pursue your personal and professional dreams-we'd love to meet you. Apply today and start the most rewarding chapter of your career with us.

Job Description

The Chief Information Security Officer (CISO) is a senior leadership role responsible for the development, implementation, and ongoing oversight of the Bank's enterprise information security, cybersecurity, and data protection program.
This role will support the Bank's ability to protect the confidentiality, integrity, and availability of information assets while aligning cybersecurity practices with business objectives, regulatory expectations, and the Bank's risk appetite framework.
The CISO operates with appropriate independence within the Risk organization and provides objective oversight, escalation of cybersecurity risks, and subject matter expertise to executive leadership, Board committees, and business stakeholders. The role is accountable for maintaining a sound control environment, effective risk management processes, and regulatory readiness.
The preferred work location for this role will be based within one of our Louisiana, Texas, Alabama, Florida, or Mississippi markets.

Information Security Governance & Program Leadership

  • Develops, implements, and manages the Bank's enterprise information security program in alignment with strategic priorities and risk appetite
  • Establishes and maintains information security policies, standards, and procedures consistent with regulatory guidance and industry frameworks
  • Provides regular reporting to the Chief Risk Officer and senior leadership on:
    • Cybersecurity risks and emerging threat landscape
    • Key risk indicators (KRIs) and program performance
    • Control effectiveness and remediation status
  • Supports Board and Risk Committee reporting by preparing materials and analysis as needed
  • Promotes enterprise-wide security awareness and accountability

Control Assurance & Monitoring

  • Oversees the design and operation of key cybersecurity controls and monitoring processes
  • Supports control assurance activities, including:
    • Control validation and testing coordination
    • Vulnerability management and remediation tracking
  • Ensures control issues are identified, escalated, and remediated in a timely manner
  • Partners with Internal Audit and Risk teams to support independent testing and validation efforts

Threat Protection & Security Operations

  • Oversees day-to-day security operations, including monitoring, detection, and response processes
  • Directs threat intelligence, vulnerability management, and penetration testing activities
  • Ensures effective implementation of core security controls, including:
    • Identity and access management
    • Data protection and encryption
    • Endpoint and network security
  • Supports continuous improvement of detection and response capabilities

Incident Response & Resilience Coordination

  • Maintains the Bank's cyber incident response framework and supporting procedures
  • Coordinates response to cybersecurity incidents in partnership with Technology, Risk, Legal, and leadership teams
  • Conducts post-incident reviews and supports remediation tracking
  • Facilitates cyber incident tabletop exercises and scenario testing with key stakeholders
  • Aligns cybersecurity incident response with broader business continuity and disaster recovery plans

Third-Party Risk Oversight

  • Supports the Bank's third-party cybersecurity risk management program across the vendor lifecycle:
    • Due diligence and onboarding
    • Ongoing monitoring
    • Issue Identification and remediation
  • Works with Vendor Management, Risk, and Legal to ensure third-party security expectations are met
  • Provides risk assessments and recommendations for third-party engagements

Data Protection & Privacy Alignment

  • Supports the Bank's data protection strategy, including:
    • Data classification and handling standards
    • Protection of sensitive and confidential information
  • Coordinates with Legal, Compliance, and Risk to ensure alignment with privacy requirements
  • Monitors controls designed to prevent unauthorized data access or loss

Technology & Emerging Risk Advisory

  • Partners with Technology teams to ensure security considerations are incorporated into system design and implementation
  • Provides input into risk assessments for:
    • Cloud environments
    • Digital transformation initiatives
    • Emerging technologies (e.g., AI, APIs, fintech integrations)
  • Promotes consistent application of secure development and architecture practices

Regulatory & Audit Support

  • Supports regulatory examinations and audits related to cybersecurity and information security
  • Assists in the preparation and coordination of responses to regulatory and audit inquiries
  • Tracks and supports remediation of findings, including documentation and evidence collection
  • Maintains documentation to demonstrate compliance with applicable regulatory expectations

Leadership & Collaboration

  • Serves as a key advisor to Risk leadership and business units on cybersecurity matters
  • Build relationships with internal stakeholders, auditors, and external partners
  • Leads and develops the Information Security team, including talent development and performance management
  • Promotes a collaborative, risk-aware culture across the organization

Supervisory Responsibilities

Manages the Information Security function, including cybersecurity operations and risk support activities. Responsible for staffing, performance management, and alignment with departmental and enterprise risk priorities.

Qualifications:

Education and Experience

  • Bachelor's degree in Information Security, Computer Science, Information Systems, or related field required; advanced degree preferred

  • 8-12+ years of experience in cybersecurity, information security, or IT risk management

  • 5+ years of leadership experience within a financial services or regulated environment

  • Experience supporting regulatory examinations and interacting with senior leadership

Certifications (Preferred)

  • CISSP

  • CISM

  • CRISC or comparable

Skills

To perform the job successfully, an individual should demonstrate the following skills:

Culture & Conduct Expectations

  • Demonstrates alignment with the Bank's core values and risk culture

  • Promotes shared accountability for cybersecurity across the organization

  • Maintains professionalism, integrity, and confidentiality

Physical Demands

While performing the duties of this job, the employee is frequently required to stand; walk; sit; use hands to finger, handle, or feel and talk or hear. The employee is occasionally required to reach with hands and arms; climb or balance and stoop, kneel, crouch, or crawl. The employee must frequently lift and/or move up to 10 pounds and occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision and ability to adjust focus.

Work Environment

The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

This position operates in a professional banking environment and routinely uses standard office equipment and digital tools such as secure financial systems, computers, phones, photocopiers, and scanners. The role requires maintaining a high level of professionalism, confidentiality, and attention to detail in all interactions.

Work is typically performed in a corporate office setting with a moderate noise level and a dynamic, collaborative, and inclusive workplace where innovation thrives. Expect a fast-paced, supportive atmosphere where your ideas are heard, and your contributions make an impact. This role may occasionally require travel.

This job description reflects management's assignment of essential functions. It does not prescribe or restrict the tasks that may be assigned. Origin Bank shall, in its discretion, modify or adjust the position to meet the Bank's changing needs. This job description is not a contract and may be adjusted as deemed appropriate in the Bank's sole discretion.

Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws. Know Your Rights