1

Grc Third Party Risk Analyst Jobs in Alabama (NOW HIRING)

... Third-Party Risk Management workstreams in partnership with architects and product owners ... Experience with Performance Analytics, Predictive Intelligence, Now Assist, or generative ...

Logan, Everest's growing proprietary 3rd party capital platform, covering the respective risk oversight responsibilities such as RCSAs, Operational Risk Heatmap and risk assessments of strategic ...

... Third-Party Risk Management workstreams in partnership with architects and product owners ... Experience with Performance Analytics, Predictive Intelligence, Now Assist, or generative ...

... risk registers Prepare documentation and participate in quarterly ISMS and GRC reporting cycles Operates under the direction of the GRC Manager with a focus on execution and coordination, not ...

Independently performs ad hoc analysis of often complex credit risk issues, frequently requiring ... Twelve (12) years of credit-related experience, or eight (8) years of third line of defense credit ...

Internal Audit Manager

Huntsville, AL · On-site

$120K - $170K/yr

Experience with third-party risk management programs. * Working knowledge of IT General Controls ... Curious, analytical, and highly collaborative. * A strategic thinker who can balance risk ...

Infrastructure Analyst - Vulnerability & Patch Management 12-month Fixed Term Contract Up to 55,000 ... third-party coordination. The role is weighted more toward vulnerability remediation than ...

Showing results 21-40

Grc Third Party Risk Analyst information

What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?

As a GRC Third Party Risk Analyst, you may face challenges such as obtaining timely and complete responses from vendors, especially when dealing with large or international organizations. Navigating varying levels of vendor maturity in risk management practices can also be difficult. Additionally, balancing the need for thorough risk assessments with fast-paced business timelines requires strong communication and prioritization skills. Collaborating closely with procurement, legal, and IT teams is essential to ensure all risks are properly identified and managed.

What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?

To thrive as a GRC Third Party Risk Analyst, you need a strong understanding of risk management frameworks, compliance regulations, and vendor risk assessment methodologies, typically supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (like Archer or ServiceNow), third-party risk management tools, and certifications such as CISA or CRISC is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills are essential soft skills for this role. These competencies ensure that organizations can accurately assess and mitigate third-party risks, maintaining compliance and protecting sensitive data.

What is a GRC Third Party Risk Analyst?

A GRC Third Party Risk Analyst is a professional who assesses and manages the risks associated with an organization’s external vendors, suppliers, or partners. Their role involves evaluating third-party compliance with regulatory standards and internal policies, identifying potential risks such as data breaches or non-compliance, and recommending mitigation strategies. They use frameworks like GRC (Governance, Risk, and Compliance) to help ensure that third-party relationships do not compromise the organization's security or reputation. This role often collaborates with procurement, legal, and IT teams to maintain robust risk management processes.

What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?

AspectGrc Third Party Risk AnalystGrc Vendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSame certifications commonly required
Work EnvironmentFocuses on third-party relationships and risk assessmentsPrimarily evaluates vendor-specific risks and compliance
Industry UsageUsed across finance, healthcare, and tech sectorsCommonly found in industries with extensive vendor networks

The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

What are popular job titles related to Grc Third Party Risk Analyst jobs in Alabama? For Grc Third Party Risk Analyst jobs in Alabama, the most frequently searched job titles are:
What cities in Alabama are hiring for Grc Third Party Risk Analyst jobs? Cities in Alabama with the most Grc Third Party Risk Analyst job openings:
Infographic showing various Grc Third Party Risk Analyst job openings in Alabama as of August 2026, with employment types broken down into 3% Internship, 90% Full Time, and 7% Part Time. Highlights an 90% In-person, 7% Hybrid, and 3% Remote job distribution.

Full-time

Medical, Dental, Vision, Life, Retirement

Re-posted 3 days ago


Carpenter Technology rating

6.8

Company rating: 6.8 out of 10

Based on 29 frontline employees who took The Breakroom Quiz


Job description

Carpenter Technology Corporation is a leading producer and distributor of premium specialty alloys, including titanium alloys, nickel and cobalt based superalloys, stainless steels, alloy steels and tool steels. Carpenter Technology's high-performance materials and advanced process solutions are an integral part of critical applications used within the aerospace, transportation, medical and energy markets, among other markets. Building on its history of innovation, Carpenter Technology's wrought and powder technology capabilities support a range of next-generation products and manufacturing techniques, including novel magnetic materials and additive manufacturing.

Cybersecurity Professional - Raleigh, NC; Reading, PA; Tanner, AL

Primary Responsibilities for the Cybersecurity Professional:

  • Assists with cyber-threat monitoring and Security Operations Center (SOC) duties.
  • Performs daily security operations duties including handling service requests from Business and IT teams. Updates standard operating procedures and as-built documentation. Routinely publish performance metrics.
  • Monitors key security intelligence feeds and escalates relevant risks.
  • Participates in cybersecurity technology projects and lifecycle management.
  • Provides security technical assistance for IT projects intended to enable or advance business initiatives.
  • Supports secure integration of Cloud and Third-party Applications.
  • Assists with recurring patch and vulnerability management tasks.
  • Facilitates third-party penetration testing (Ethical Hacking) to confirm design and operational effectiveness of security controls.
  • Guides employees with security policy (e.g., password complexity, encryption settings, etc.) and advances cybersecurity awareness campaigns (e.g., Phishing email simulations).
  • Routinely publishes Governance, Risk, and Compliance (GRC) metrics.
  • Examines design and operational effectiveness of security controls. Coordinates audit engagements led by Internal Audit, Regulator, or external audit firm.
  • Supports assessment of internal and third-party cybersecurity risk. Examine audit reports (e.g., SOC 1, SOC 2, ISO 27001, etc.). Assist with customer inquiries about Carpenter compliance related to IT and Security.

Required for the Cybersecurity Professional:

  • Bachelor of Science degree in computer science or related field preferred. Or equivalent work experience.
  • Associate's degree in computer science or related field minimum required with a combination of Cybersecurity related certifications (e.g., CISSP, CISM, GCIH, GCIA, CEH, Security+, etc.) and additional 2 years' experience.
  • Minimum 7 years of related experience with Security Operations, Network Security, Vulnerability Management, Compliance, or Audit.

Preferred for the Cybersecurity Professional:

  • Advanced understanding of information technology.
  • Advanced knowledge of multiple security domains and common security controls.
  • Expert knowledge of 2-3 security domains.
  • Familiarity with common hacking techniques (e.g., malware, phishing, etc.) and effective counter measures.
  • Adoption of security best practices and industry standards (e.g. NIST, ISO, CIS, COBIT, etc.).
  • Hands-on operation of cybersecurity infrastructure (e.g., Firewalls, Intrusion Detection, AV, PKI, Encryption, etc.) and configuration experience.
  • Security Incident Response handling.
  • Malware analysis.
  • Multi-task and manage demands of multiple projects, incidents, and tasks.
  • Meet deadlines and manage changing priorities.
  • Perform effectively both independently and in a team environment.

Carpenter Technology Company offers a competitive salary and a comprehensive benefits package including life, medical, dental, vision, flexible spending accounts, disability coverage, 401k with company contributions as well as many other options to employees.

Carpenter Technology Corporation's policy is to fully and effectively maintain a program of equal employment opportunity and nondiscrimination for all employees, to employ affirmative action for all protected classes, and to recruit and develop the best qualified persons available regardless of age, race, color, religion, sex, gender identity, sexual orientation, marital status, national origin, political affiliation or any other characteristic protected by law. The Company also will recruit, develop and provide opportunities for qualified persons with disabilities and protected veterans.


What Carpenter Technology employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom