Third-Party Risk Management Analyst
Location: Plano, TX (Onsite)
Summary
- Lead Third-Party Cyber Risk Management (TPCRM) initiatives throughout the project lifecycle.
- Conduct third-party cybersecurity risk assessments and identify security gaps.
- Perform inherent risk assessments, validate risk ratings, and evaluate security controls.
- Track remediation activities and ensure timely closure of identified risks.
- Utilize GRC platforms and AI-driven automation to streamline assessments and reporting.
- Collaborate with Cybersecurity, Procurement, Legal, Internal Audit, and business stakeholders.
- Improve TPRM processes through workflow and tooling enhancements.
- Develop metrics, dashboards, and executive reports for leadership.
- Promote cybersecurity awareness and secure third-party practices.
Required Skills
- Third-Party Risk Management (TPRM)
- Third-Party Cyber Risk Management (TPCRM)
- Vendor Risk Management
- Cybersecurity Risk Assessments
- Inherent Risk Assessments
- Risk Analysis
- Risk Remediation
- Security Control Validation
- Governance, Risk & Compliance (GRC)
- GRC Platforms (Archer, ServiceNow GRC, OneTrust, ProcessUnity, MetricStream)
- AI-Driven Risk Automation
- NIST
- SOC 2
- ISO 27001
- PCI DSS
- Security Controls
- Compliance
- Stakeholder Management
- Project Management
- Executive Reporting
- Metrics & Dashboards
- Strong Documentation & Communication
Preferred Candidate Background
- 3โ5 years of experience in Cybersecurity, Third-Party Risk Management, IT Risk, or GRC.
- Experience performing vendor security assessments and due diligence.
- Knowledge of security frameworks such as NIST, ISO 27001, SOC 2, and PCI DSS.
- Experience with GRC platforms and cross-functional stakeholder coordination.
- Ability to document risks, remediation plans, and recommendations clearly.
#ThirdPartyRiskManagement #TPRM #TPCRM #VendorRisk #CyberRisk #CyberSecurity #CyberRiskManagement #RiskAssessment #InherentRisk #VendorSecurity #GRC #GovernanceRiskCompliance #ServiceNow #Archer #OneTrust #NIST #SOC2 #ISO27001 #PCIDSS #Compliance #RiskRemediation #ITRisk #InformationSecurity #CyberGovernance #VendorAssessment #AI #AIGovernance #ProjectManagement #StakeholderManagement #ProcessImprovement