This includes reviewing both the vendor's security control environment and the specific solution ... Risk & Analysis: * Ability to identify, assess, and clearly communicate complex cyber risks, trade ...
This includes reviewing both the vendor's security control environment and the specific solution ... Risk & Analysis: * Ability to identify, assess, and clearly communicate complex cyber risks, trade ...
This includes reviewing both the vendor's security control environment and the specific solution ... Risk & Analysis: * Ability to identify, assess, and clearly communicate complex cyber risks, trade ...
This includes reviewing both the vendor's security control environment and the specific solution ... Risk & Analysis: * Ability to identify, assess, and clearly communicate complex cyber risks, trade ...
Senior Information Security Risk Analyst
Johnston, RI ยท On-site
$106K/yr
This includes reviewing both the vendor's security control environment and the specific solution ... Risk & Analysis: * Ability to identify, assess, and clearly communicate complex cyber risks, trade ...
Senior Information Security Risk Analyst
Johnston, RI ยท On-site
$106K/yr
This includes reviewing both the vendor's security control environment and the specific solution ... Risk & Analysis: * Ability to identify, assess, and clearly communicate complex cyber risks, trade ...
This includes reviewing both the vendor's security control environment and the specific solution ... Risk & Analysis: * Ability to identify, assess, and clearly communicate complex cyber risks, trade ...
This includes reviewing both the vendor's security control environment and the specific solution ... Risk & Analysis: * Ability to identify, assess, and clearly communicate complex cyber risks, trade ...
Senior Information Security Risk Analyst
Johnston, RI ยท On-site
$106K - $152K/yr
This includes reviewing both the vendor's security control environment and the specific solution ... Risk & Analysis: * Ability to identify, assess, and clearly communicate complex cyber risks, trade ...
Senior Information Security Risk Analyst
Johnston, RI ยท On-site
$106K - $152K/yr
This includes reviewing both the vendor's security control environment and the specific solution ... Risk & Analysis: * Ability to identify, assess, and clearly communicate complex cyber risks, trade ...
Risk Transformation & Delivery Analyst
Johnston, RI ยท Hybrid
$94K - $134K/yr
Budget, Vendor, and Resource Management * Assist the Head of Risk Transformation in managing the Risk organization's budget, including forecasting, tracking, and variance analysis. * Support vendor ...
Risk Transformation & Delivery Analyst
Johnston, RI ยท Hybrid
$94K - $134K/yr
Budget, Vendor, and Resource Management * Assist the Head of Risk Transformation in managing the Risk organization's budget, including forecasting, tracking, and variance analysis. * Support vendor ...
Third Party Risk Sr Analyst
Johnston, RI ยท Hybrid
Description Payment Network Compliance Senior Analyst (Visa/Mastercard/Discover) Merchant ... This is a hands-on, execution-focused role -not a traditional vendor risk/GRC position. The work is ...
Third Party Risk Sr Analyst
Johnston, RI ยท Hybrid
Description Payment Network Compliance Senior Analyst (Visa/Mastercard/Discover) Merchant ... This is a hands-on, execution-focused role -not a traditional vendor risk/GRC position. The work is ...
Risk Transformation & Delivery Analyst
Johnston, RI ยท On-site
$94K - $134K/yr
Budget, Vendor, and Resource Management * Assist the Head of Risk Transformation in managing the Risk organization's budget, including forecasting, tracking, and variance analysis. * Support vendor ...
Risk Transformation & Delivery Analyst
Johnston, RI ยท On-site
$94K - $134K/yr
Budget, Vendor, and Resource Management * Assist the Head of Risk Transformation in managing the Risk organization's budget, including forecasting, tracking, and variance analysis. * Support vendor ...
Risk Transformation & Delivery Analyst
Johnston, RI ยท Hybrid
$94K - $134K/yr
Budget, Vendor, and Resource Management * Assist the Head of Risk Transformation in managing the Risk organization's budget, including forecasting, tracking, and variance analysis. * Support vendor ...
Risk Transformation & Delivery Analyst
Johnston, RI ยท Hybrid
$94K - $134K/yr
Budget, Vendor, and Resource Management * Assist the Head of Risk Transformation in managing the Risk organization's budget, including forecasting, tracking, and variance analysis. * Support vendor ...
Risk Transformation & Delivery Analyst
Johnston, RI ยท Hybrid
$94K - $134K/yr
Budget, Vendor, and Resource Management * Assist the Head of Risk Transformation in managing the Risk organization's budget, including forecasting, tracking, and variance analysis. * Support vendor ...
Risk Transformation & Delivery Analyst
Johnston, RI ยท Hybrid
$94K - $134K/yr
Budget, Vendor, and Resource Management * Assist the Head of Risk Transformation in managing the Risk organization's budget, including forecasting, tracking, and variance analysis. * Support vendor ...
Third Party Risk Sr Analyst
Johnston, RI ยท Hybrid
Payment Network Compliance Senior Analyst (Visa/Mastercard/Discover) Merchant Compliance ... This is a hands-on, execution-focused role -not a traditional vendor risk/GRC position. The work is ...
Third Party Risk Sr Analyst
Johnston, RI ยท Hybrid
Payment Network Compliance Senior Analyst (Visa/Mastercard/Discover) Merchant Compliance ... This is a hands-on, execution-focused role -not a traditional vendor risk/GRC position. The work is ...
... vendor solutions, mainframe, network environments, and AI) * Demonstrated technical abilities in ... risk using your advanced analytical and critical thinking skills * Your ability to build and ...
... vendor solutions, mainframe, network environments, and AI) * Demonstrated technical abilities in ... risk using your advanced analytical and critical thinking skills * Your ability to build and ...
Third Party Risk Sr Analyst
Johnston, RI ยท Hybrid
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Third Party Risk Sr Analyst
Johnston, RI ยท Hybrid
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Third Party Risk Sr Analyst
Johnston, RI ยท Hybrid
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Third Party Risk Sr Analyst
Johnston, RI ยท Hybrid
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Third Party Risk Sr Analyst
Johnston, RI ยท Hybrid
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Third Party Risk Sr Analyst
Johnston, RI ยท Hybrid
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Third Party Risk Sr Analyst
Johnston, RI ยท On-site
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Third Party Risk Sr Analyst
Johnston, RI ยท On-site
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI ยท Hybrid
$95K - $123K/yr
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI ยท Hybrid
$95K - $123K/yr
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI ยท Hybrid
$95K - $123K/yr
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI ยท Hybrid
$95K - $123K/yr
Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI ยท Hybrid
$95K - $123K/yr
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI ยท Hybrid
$95K - $123K/yr
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI ยท On-site
$95K - $123K/yr
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Third Party Risk Sr Analyst - Cybersecurity
Johnston, RI ยท On-site
$95K - $123K/yr
As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...
Internship Vendor Risk Analyst information
What is an internship vendor risk analyst?
What are some common challenges internship vendor risk analysts face when assessing third-party vendors?
What are the key skills and qualifications needed to thrive as an internship vendor risk analyst, and why are they important?
What is the difference between Internship Vendor Risk Analyst vs Vendor Risk Analyst?
| Aspect | Internship Vendor Risk Analyst | Vendor Risk Analyst |
|---|---|---|
| Credentials | Typically pursuing or recent graduate, some certifications optional | Usually requires professional certifications like CRISC or CTP |
| Work Environment | Internship setting, entry-level tasks, learning-focused | Full-time role, responsible for ongoing risk assessments |
| Industry Usage | Common in finance, consulting, and tech companies for training | Established position in risk management departments across industries |
The Internship Vendor Risk Analyst is an entry-level role designed for students or recent graduates gaining experience in vendor risk management. In contrast, the Vendor Risk Analyst is a full-time professional responsible for ongoing risk assessments and mitigation strategies. While both roles involve evaluating vendor risks, the internship focuses on learning and support, whereas the analyst role involves independent decision-making and expertise.
Other
Medical, Dental, Vision, Life, Retirement, PTO
Posted 17 days ago
Job description
Established nearly two centuries ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineering expertise are solely dedicated to property risk management and the resilience of its policyholder-owners. These owners, who share the belief that the majority of property loss is preventable, represent many of the worldโs largest organizations, including one of every four Fortune 500 companies. They work with FM to better understand the hazards that can impact their business continuity to make cost-effective risk management decisions, combining property loss prevention with insurance protection.
Work Schedule
This position requires on-site work one day per week at our Corporate Headquarters and flexibility to be on-site when needed based on the demands of the business
Relocation is not offered for this position.
Position Summary
FM is seeking a Senior Information Security Analyst with deep expertise in Third-Party Risk Management (TPRM), you will play a critical role in protecting FM by assessing how external vendors, SaaS platforms, and cloud solutions interact with our systems and data. This high-impact role where your expertise in cyber risk, vendor security, and cloud architecture will help shape business decisions, strengthen our security posture, and support innovation in a secure way. This includes reviewing both the vendorโs security control environment and the specific solution being implemented, with a focus on data handling, storage, and integration with internal systems.
You will partner closely with business, technology, and procurement teams to identify risks and recommend practical, business-aligned mitigation strategies.
You will lead end-to-end cybersecurity risk assessments of third-party vendors and solutionsโgoing beyond standard due diligence to evaluate real-world risk across systems, data, and integrations.
Key Responsibilities
- Lead end-to-end third-party solution risk assessments and vendor security reviews across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, and reassessments.
- Evaluate vendor security programs, control effectiveness, and governance, along with deep-dive assessment of the specific product being implemented including solution architecture, data flows, and integration points.
- Identify and communicate inherent and residual cyber risks related to data protection, privacy, IAM, privileged access, system connectivity, and external attack surface exposure.
- Review and interpret security documentation, including SOC 1/SOC 2 reports, ISO 27001 certifications, audit reports, architecture diagrams, data flow diagrams, and technical configurations.
- Recommend practical risk mitigation strategies, including compensating controls, secure design changes, and contractual safeguards to support risk-informed decisions.
- Partner with business, technology, procurement, and legal teams to support risk acceptance, exception management, and third-party risk governance.
- Contribute to the evolution of FMโs third-party risk management framework, methodology, and standards in alignment with NIST, ISO 27001, NYDFS, and other applicable regulatory expectations.
- 5+ years of experience in cybersecurity, information security, or cyber risk, with a background in third-party risk management (TPRM), IT risk, audit, incident response, or access management.
- Experience assessing vendor security posture in cloud (SaaS/PaaS)and enterprise environments.
Technical Expertise
- Strong understanding of systems, networks, application architecture, cloud security, and secure system design across AWS, Azure, SaaS, PaaS, APIs, and enterprise integrations.
- Experience evaluating data flows, data classification, data protection, data governance, and secure data handling practices.
- Knowledge of IAM, SSO, federation, privileged access, cyber threats, vulnerabilities, and attack methodologies.
- Ability to interpret SOC 1, SOC 2, ISO certifications, and other third-party assurance artifacts to identify control gaps and residual risk.
Risk & Analysis:
- Ability to identify, assess, and clearly communicate complex cyber risks, trade-offs, and residual risk.
- Experience recommending practical, business-aligned risk based mitigation strategies, including compensating controls and secure design changes.
- Strong analytical judgment, attention to detail, and risk-based decision-making.
Collaboration & Communication
- Ability to translate technical findings into clear, business-relevant insights and recommendations.
- Strong stakeholder management and partnership across business, technology, procurement, and legal teams.
- Collaborative, solutions-focused mindset with strong influencing skills in a fast-paced assessment environment.
- High degree of professional skepticism and curiosity when evaluating vendor claims and evidence
- Ability to manage multiple priorities independently while maintaining quality and consistency of assessments
Tools & Certifications:
- Proficiency with Microsoft Office tools.
- Relevant certifications such as CISSP, CISA, CSA, CISM, Security+, GIAC, CEH, or similar are strongly desired.
Education
Bachelor's degree in information security, Computer Science, Information Technology, or a related field required. An equivalent of relevant work experience will also be considered.
The hiring range for this position is $106,000- $152,000. The final salary offer will vary based on geographic location, individual education, skills, and experience. The position is eligible to participate in FMโs comprehensive Total Rewards program that includes an incentive plan, medical, dental and vision insurance, life and disability insurance, well-being programs, a 401(k) and pension plan, career development opportunities, tuition reimbursement, flexible work, and time off, including vacation and sick time.
FM is an Equal Opportunity Employer and is committed to attracting, developing, and retaining a diverse workforce.
#LI-NL1
#FMG
About FM
Sourced by ZipRecruiter
Industry
Plastics product manufacturing
Company size
51 - 200 Employees
Headquarters location
Rogers, AR, US
Year founded
1980