1

Overnight Third Party Risk Analyst Jobs in California

Support ITRC team members as needed in conducting third-party security risk assessments for changes ... Strong analytical, issue identification, prioritization, resolution, and report writing skills ...

The Due Diligence Analyst will support the client's Global Security, Compliance, and Risk ... third-party risk assessments. * Engage with cross-functional stakeholders including Security ...

AVP, Business Risk Analyst

El Monte, CA ยท On-site

$93K - $114K/yr

This role provides analytical capabilities, risk data coordination, and operational support to ... third party onboarding and ongoing monitoring activities by supporting respective BRCOs and ...

Staff Risk Strategy Analyst

Redwood City, CA ยท On-site

$150 - $210/hr

Experience leveraging internal and third-party risk decisioning, orchestration, identity, or fraud ... Strong analytical and problem-solving skills with the ability to break down complex problems and ...

Conduct third-party risk assessments and security reviews of third-party agreements. * Work closely ... Strong analytical and problem-solving skills. * Strong written and verbal communication skills ...

Conduct third-party risk assessments and security reviews of third-party agreements. * Work closely ... Strong analytical and problem-solving skills. * Strong written and verbal communication skills ...

$93 - $120/hr

IT - Gov Analyst, Status: Exempt, Reports to: Manager - IT - Governance Risk and Compliance ... Support third-party risk assessments and manage third-party risk and remediation activities.

Third Party and Supplier Cybersecurity Risk * Administer and support the third party risk ... Strong analytical, communication, documentation, presentation, and interpersonal skills are ...

Showing results 41-60

Overnight Third Party Risk Analyst information

What does an overnight third party risk analyst do?

An Overnight Third Party Risk Analyst is responsible for assessing and monitoring the risks associated with an organization's external vendors and partners during overnight hours. This role involves analyzing vendor compliance, identifying potential security or financial risks, and ensuring that third-party relationships align with company policies and regulatory requirements. Working overnight, they provide continuous risk oversight, promptly addressing any issues that arise outside of standard business hours to maintain the organization's security and compliance posture.

What are the key skills and qualifications needed to thrive as an overnight third party risk analyst?

To thrive as an Overnight Third Party Risk Analyst, you need strong analytical skills, attention to detail, and knowledge of risk management principles, often supported by a degree in finance, business, or a related field. Familiarity with risk assessment tools, third-party risk management software, and frameworks like ISO 27001 or NIST is typically required, and certifications such as CRISC or CTPRP are advantageous. Excellent communication, problem-solving abilities, and the capacity to work independently during off-hours make candidates stand out. These skills ensure accurate risk evaluations, clear reporting, and effective incident response to safeguard the organization's interests around the clock.

What are some common challenges faced by overnight third party risk analysts, and how can they be managed?

Overnight Third Party Risk Analysts often work independently during non-standard hours, which can make real-time collaboration with colleagues and stakeholders more challenging. Additionally, they may need to quickly assess and escalate urgent vendor risk issues that arise outside of regular business hours. To manage these challenges, strong communication skills, clear documentation practices, and familiarity with escalation protocols are essential. Regular alignment with daytime teams and leveraging comprehensive handover notes can also help ensure continuity and accuracy in risk management processes.

What is the difference between Overnight Third Party Risk Analyst vs Third Party Risk Analyst?

AspectOvernight Third Party Risk AnalystThird Party Risk Analyst
Work HoursTypically overnight or shift-basedStandard business hours
CertificationsOften requires risk management or compliance certificationsSimilar certifications, but less emphasis on shift work
Work EnvironmentFinancial institutions, 24/7 operationsCorporate offices, regular hours
Job FocusMonitoring third-party risks during off-hoursOngoing third-party risk assessments

The Overnight Third Party Risk Analyst specializes in monitoring and managing third-party risks during overnight shifts, often within financial institutions that operate 24/7. In contrast, the Third Party Risk Analyst typically works during regular hours, focusing on ongoing risk assessments. Both roles require similar certifications and industry knowledge, but their work hours and environments differ significantly.

What are the most commonly searched types of Third Party Risk Analyst jobs in California?

The most popular types of Third Party Risk Analyst jobs in California are:

What are popular job titles related to Overnight Third Party Risk Analyst jobs in California?

For Overnight Third Party Risk Analyst jobs in California, the most frequently searched job titles are:

What job categories do people searching Overnight Third Party Risk Analyst jobs in California look for?

The top searched job categories for Overnight Third Party Risk Analyst jobs in California are:

What cities in California are hiring for Overnight Third Party Risk Analyst jobs?

Cities in California with the most Overnight Third Party Risk Analyst job openings:

IT Risk & Compliance Analyst

Superbeo

San Francisco, CA โ€ข On-site

Contractor

Re-posted 25 days ago


Job description

Job Title: IT Risk & Compliance Analyst

Job Location: San Francisco, CA 94104

  • Please local candidates that are able to work hybrid work schedule, Tuesday and Wednesday, at the SF Offices.

Job Duration: 6 months (Possibility of extension)

Qualifications (Must Have):

  • Ability to map key Information Security and Technology controls identified in policies, standards, and process documents to industry frameworks such as NIST CSF, NIST 800-53, CSA CCM, CIS v8.1, and regulatory requirements in FHFA Advisory Bulletins.
  • Interpret compliance information to create a recurring cadence of reports of open findings, observations, self-identified issues, progress on risk and compliance initiatives.
  • Willingness to learn/use ITRC tools (e.g., ProcessUnity, Black Kite) and support ITRC team lead with supply chain cyber risk program management

Primary Responsibilities:

  • Conduct readiness assessments, including reviews of relevant documentation in advance of audits, 2LOD assessments, and external assessments.
  • Maintain the inventory of SOX IT General Controls (ITGC) and control tests in ServiceNow, updating as directed, and identifying opportunities for improvements in reporting and in using automation.
  • Liaison between control owner and internal auditors, and 2LOD assessors during audits and assessments, responsible for supporting control owners in the timely submission of artifacts.
  • Ability to map key Information Security and Technology controls identified in policies, standards, and process documents to industry frameworks such as NIST CSF, NIST 800-53, CSA CCM, CIS v8.1, and regulatory requirements in FHFA Advisory Bulletins.
  • Ability to identify and document technology processes.
  • Manage the LogicGate Governance Library ensuring Information Security and Technology documents align with approval and publication requirements, relying equally on automated reminders as well as active engagement with document owners.
  • Maintain ITRC document archives in the ITRC shared repository.
  • Responsible for reporting status at a recurring cadence of open findings, observations, recommendations, and self-identified issues, and for submitting formal audit observation closure documentation.
  • As directed by the ITRC MD, document and report the progress and value of in-flight ITRC initiatives, identified risks, and planned initiatives.
  • Provide compliance review of requests for deviations from Information Security and Technology policies and standards, confirming compliance with Technology Exception requirements for components such as compensating controls, risk assessment, and  documentation supporting exception request rationale.
  • Participate as a key stakeholder in the Architecture Assessment Review process, documenting meeting decisions,  tracking deliverable commitments, and ensuring next steps are completed for proposed new technologies or changes in existing technologies.
  • Support ITRC team members as needed in conducting third-party security risk assessments for changes to existing third parties or proposed third party technologies.

Skills/Knowledge:

  • Required Core Competencies:  Customer Focus, Decision Quality, Ensures Accountability, Drives Results, Drives Engagement, Collaborates, Values Differences, Communicates Effectively with all levels of staff and management, Instills Trust
  • 3 - 5 years of experience in technology risk or IT audit.
  • Knowledge and experience with technology frameworks is required, e.g., CIS v8.1, CSA CCM, CoBIT, NIST, ITIL, et al.
  • Knowledge of Operational Risk Management and Technology Risk Management.
  • Demonstrated ability to promote teamwork, act as a change agent, effectively remove obstacles, maintain high level of morale and motivation, and lead by example.
  • Familiarity with SOX ITGC
  • Must be proficient with Microsoft Office (Word, Excel, PowerPoint) and Microsoft SharePoint.
  • Must have strong communication skills and be able to effectively communicate with all functional levels of the organization.
  • Project management, planning, problem-solving and organizational skills required, preferably using Atlassian JIRA
  • Strong analytical, issue identification, prioritization, resolution, and report writing skills required.
  • Must be proactive and must be able to meet established deadlines.
  • Experience with a Governance, Risk and Compliance (GRC) tool is highly desirable, preferably ServiceNow and LogicGate.
  • Ability to learn use of the ProcessUnity/CyberGRX third party risk management platform