1

Third Party Cybersecurity Risk Jobs in Georgia (NOW HIRING)

Lead enterprise-wide and targeted risk assessments focused on strategic, operational, technology, cybersecurity, resilience, third-party, and emerging risks. * Develop and maintain risk assessment ...

... to third-party risk management and cybersecurity risks and industry standards and guidance (i.e., FFIEC IT Handbook and NIST CSF) * Previous SP supervision experience a plus * Strong critical ...

next page

Showing results 1-20

Third Party Cybersecurity Risk information

How much does a third party risk analyst make?

A third party risk analyst typically earns between $70,000 and $110,000 annually, depending on experience, location, and industry. Professionals in cybersecurity risk management often hold certifications like CISSP or CRISC, which can influence salary levels.

Is third party risk management a good career?

Third Party Cybersecurity Risk management is a growing field that involves assessing and mitigating risks from external vendors and partners. It requires knowledge of cybersecurity principles, risk assessment tools, and often certifications like CISSP or CISM. The role offers opportunities in various industries with increasing demand due to the importance of supply chain security.

What is third-party risk management in cybersecurity?

Third-party risk management in cybersecurity involves identifying, assessing, and mitigating risks posed by external vendors, suppliers, or partners that have access to an organization’s systems or data. For cybersecurity professionals, this includes evaluating third-party security controls, conducting audits, and ensuring compliance with standards like ISO 27001 or NIST frameworks to reduce potential vulnerabilities. Effective management helps prevent data breaches and maintains the organization’s security posture.

What is the difference between Third Party Cybersecurity Risk vs Cybersecurity Analyst?

AspectThird Party Cybersecurity RiskCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+, CEH
Work EnvironmentVendor assessments, risk management teams, client organizationsSecurity operations centers, IT departments, consulting firms
Industry UsageSupply chain, vendor management, complianceNetwork security, incident response, vulnerability assessment

Third Party Cybersecurity Risk professionals focus on evaluating and managing risks from external vendors and partners, ensuring compliance and reducing supply chain vulnerabilities. Cybersecurity Analysts primarily monitor, analyze, and respond to security threats within an organization’s own systems. While both roles require security certifications and involve risk assessment, their focus areas and work environments differ significantly.

Can you make $500,000 a year in cyber security?

Third Party Cybersecurity Risk professionals can potentially earn $500,000 annually, especially at senior levels or in executive roles such as Chief Information Security Officer (CISO). Achieving this salary typically requires extensive experience, advanced certifications like CISSP or CISM, and leadership responsibilities overseeing large security programs. Compensation varies based on industry, company size, location, and individual expertise.
What job categories do people searching Third Party Cybersecurity Risk jobs in Georgia look for? The top searched job categories for Third Party Cybersecurity Risk jobs in Georgia are:
What cities in Georgia are hiring for Third Party Cybersecurity Risk jobs? Cities in Georgia with the most Third Party Cybersecurity Risk job openings:

Senior Security Third Party Risk (TPRM) Analyst

OneTrust

Atlanta, GA

Other

Posted 26 days ago


Job description

The Challenge

We are looking for a dynamic Senior Information Security GRC Analyst to support IT and InfoSec by performing various governance, risk, and compliance activities as part of the OneTrust InfoSec GRC team.

Your Mission

This role will support InfoSec by performing various governance, risk, and compliance activities as part of the OneTrust InfoSec GRC team.  In addition, this role will collaborate with architecture, legal, compliance, and privacy as part of our TPRM (Third Party Risk Management) process.  This role will help review risk assessments for customers/vendors, data flow diagrams, architecture diagrams, certifications, questionnaires, etc.   

You Are

This a team player who can work well within the GRC team. 

  • Collaborate with IT, InfoSec, and within the GRC team to mature the compliance process
  • Review vendor due diligence documentation, including SOC reports, ISO certifications, penetration testing reports, policies, and security questionnaires.
  • Evaluate supplier control environments against established risk management standards and frameworks.
  • Document risk findings and communicate recommendations to business stakeholders.
  • Execute risk assessments of third-party vendors
  • Mentor Junior Security Analysts, and work with them to evaluate and remediate complex security incidents 
  • Responsible for generation and continued delivery of relevant KPIs and metrics 
  • Provide feedback on solutions and processes to mature overall capabilities 
  • Impart expertise on the OneTrust environment and security best practices to others on the team
  • BA/BS in Computer Science, Cybersecurity, Information assurance or related subject 
You Experience Includes
  • 5+ years, hands on experience in cybersecurity/risk management  
  • Experience reviewing SOC 1, SOC 2 reports & ISO 27001 certifications
  • Experience reviewing security questionnaires, business continuity and disaster recovery plans as well as vendor contracts and security requirements
  • Understanding of information security best practices around confidentiality, integrity and availability 
  • Cloud experience in at least one cloud provider 
  • Understanding of applicable laws and regulations, including but not limited to, GDPR, CCPA, PCI-DSS, SOC 2, ISO, and FedRAMP
  • Understanding of the standards for the processing practice of third-party management
  • Understanding of technology domains including governance, risk management, security, privacy, and information technology and business continuity
Preferred Experience
  • Certifications: CRISC, Security+, CISSP, CISM, CCSP, CISA, Azure
  • Knowledge of OneTrust security/GRC products.