1

Third Party Security Analyst Jobs (NOW HIRING)

Validate third party security controls and AI controls to ensure compliance with organizational policies, standards, regulatory requirements, contractual commitments, and recognized frameworks.

Validate third party security controls and AI controls to ensure compliance with organizational policies, standards, regulatory requirements, contractual commitments, and recognized frameworks.

This position will work closely with business stakeholders, and third-party security partners to ... Strong analytical, problem-solving, and communication skills. * Experience supporting manufacturing ...

This position will work closely with business stakeholders, and third-party security partners to ... Strong analytical, problem-solving, and communication skills. * Experience supporting manufacturing ...

This position will work closely with business stakeholders, and third-party security partners to ... Strong analytical, problem-solving, and communication skills. * Experience supporting manufacturing ...

This position will work closely with business stakeholders, and third-party security partners to ... Strong analytical, problem-solving, and communication skills. * Experience supporting manufacturing ...

This position will work closely with business stakeholders, and third-party security partners to ... Strong analytical, problem-solving, and communication skills. * Experience supporting manufacturing ...

Security Analyst

Columbia, MD · Hybrid

$55 - $60/hr

... the third-party risk management process • Maintain and update the risk register and track ... Security Analyst • Contract alignment • Implementing Security controls • Risk Management ...

next page

Showing results 1-20

Third Party Security Analyst information

See salary details

$39.5K

$107.3K

$141K

How much do third party security analyst jobs pay per year?

As of Sep 10, 2026, the average yearly pay for third party security analyst in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is a third party security analyst?

A Third Party Security Analyst is a cybersecurity professional responsible for assessing and managing the security risks associated with an organization's external vendors, partners, or service providers. Their main duties include evaluating the security practices of third parties, conducting risk assessments, and ensuring compliance with security standards and policies. By identifying and mitigating potential vulnerabilities introduced by external relationships, they help protect the organization from data breaches, compliance violations, and other cyber threats.

How does a third party security analyst typically collaborate with vendors and internal teams to manage security risks?

A Third Party Security Analyst regularly communicates with both external vendors and internal stakeholders to assess, monitor, and mitigate risks associated with third-party relationships. This often involves conducting security assessments of vendors, reviewing their compliance with organizational standards, and coordinating remediation plans for identified vulnerabilities. The role requires strong interpersonal and project management skills, as analysts must facilitate discussions between technical teams, procurement, and vendors to ensure security requirements are clearly defined and met throughout the partnership lifecycle.

What are the key skills and qualifications needed to thrive as a third party security analyst, and why are they important?

To thrive as a Third Party Security Analyst, you need a solid understanding of cybersecurity principles, risk management, and compliance frameworks, often supported by a degree in information security or related field. Familiarity with security assessment tools, vendor risk management platforms, and certifications such as CISSP or CISA is highly beneficial. Strong analytical thinking, attention to detail, and effective communication are critical soft skills for evaluating vendor risks and collaborating with stakeholders. These competencies are vital to ensure that third-party relationships do not introduce unacceptable security threats to an organization.

What is the difference between Third Party Security Analyst vs Vulnerability Analyst?

AspectThird Party Security AnalystVulnerability Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentExternal client sites, third-party vendors, consulting firmsInternal security teams, IT departments
Employer & Industry UsageSecurity consulting firms, corporations managing third-party risksOrganizations' internal cybersecurity teams
Primary FocusAssessing third-party security posture, risk managementIdentifying and mitigating vulnerabilities within systems

The main difference is that a Third Party Security Analyst focuses on evaluating and managing security risks posed by external vendors and partners, while a Vulnerability Analyst concentrates on identifying and fixing security weaknesses within an organization's own systems. Both roles require similar certifications and often work in overlapping environments, but their primary responsibilities differ based on scope and focus.

What cities are hiring for Third Party Security Analyst jobs?

Cities with the most Third Party Security Analyst job openings:

What states have the most Third Party Security Analyst jobs?

States with the most job openings for Third Party Security Analyst jobs include:

What are popular job titles related to Third Party Security Analyst jobs?

For Third Party Security Analyst jobs, the most frequently searched job titles are:

Infographic showing various Third Party Security Analyst job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 10% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $107,334 per year, or $51.6 per hour.

Third Party Information Security Analyst

Manhattan, NY • Hybrid

SUMITOMO MITSUI TRUST BANK, LIMITED
Commercial Banking • 201 - 500 employees

$90K - $125K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 20 days ago


Job description


This role is located in New York City and will require a hybrid work schedule of at least 2 days in office per week.


This role is for Officer level candidates. 


About the Bank

Sumitomo Mitsui Trust Bank, Limited was established through the merger of The Sumitomo Trust and Banking Co., Ltd with Chuo Mitsui Trust and Banking, Ltd. on April 1, 2012. We are one of the largest asset managers in Asia and number one among Japanese financial institutions by AUM, with approximately $850 Billion USD in AUM. The Bank provides an assortment of financial solutions and manages a broad spectrum of financial products across its global branches.
Department Overview:

The Americas Division (“AD”) was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch) (“SMTBNY”) to perform corporate functions and supervise U.S. entities. Established under the AD are the “Global Banking Unit (“GBU”), Americas Division” and “Global Markets Unit (“GMU”), Americas Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch wide framework that is in-line with the Head Office and regulatory requirements and addresses Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate and cyber security and information security risks inherent in the Branch Operations. IRG is directly involved in all information and cyber security related projects, matters and issues.


Your Role Overview:

The Third Party Information Security Analyst supports the Bank’s Third Party Risk Management function by focusing on assessing and monitoring information security risks associated with 3rd, 4th, Nth parties. This role assists with vendor due diligence, security reviews, information security risk assessments, and ongoing monitoring activities to ensure these third party relationships align with the organization’s security requirements.


Your Duties and Responsibilities:

  1. Conduct initial and continuous information security risk assessments of third (Nth) parties.
  2. Review third party provided security documentation including SOC reports, ISO 27001 certifications, security questionnaires, and Business Continuity and Disaster Recovery documentation. 
  3. Document assessment findings and risk ratings in the Bank’s TPRM platform and maintain an up-to-date tracking sheet that provides management with clear visibility into the status, due date, and completion of each assessment and related follow-up actions.
  4. For vendor due-diligence, with a focus on information security risks, coordinate with relevant Teams (Administration, Legal, etc.) for vendor onboarding and offboarding activities
  5. Perform on-going monitoring of information security-related incidents involving third-parties and coordinate with relevant stakeholders to facilitate requests for necessary information from the relevant third-parties and support the assessment of potential impact to the Bank.
  6. Participate in internal audits and external examinations related to the information security risk domains of third party risk management
  7. Assist in maintaining information security-related TPRM policies and procedures. 
  8. Performs other duties and responsibilities as assigned by management.


Your Qualifications:
  1. 3+ Years of experience with risk assessment methodologies and techniques as well as Third Party Risk Management Lifecycle. 
  2. Prior experience with financial industry structure and concepts a plus. 
  3. Prior experience working on a Third Party Risk Management (TPRM) platform, such as Prevalent.
  4. Prior experience working with and assessing information security-related documentation such as SOC 2 reports, ISO 27001 certification, etc.
  5. Strong knowledge of information security and risk management frameworks, including NIST Cybersecurity Framework, ISO/IEC 27001, and the Cyber Risk Institute Profile.
  6. Strong Microsoft Office skills
  7. Strong verbal and written communication skills.
  8. Strong analytical skills
  9. Self-motivated with good time management skills.



Why you should join SuMi Trust:SuMi Trust embraces flexible ways of working when the business and role permits. We provide employees with a hybrid working model, allowing for in-office work and work from home. Our diverse and inclusive environment along with our global presence enables us to collaborate and communicate to meet our business needs. We believe that efficient teams need truth, loyalty, and a strong sense of purpose to balance risk and their targets. We make sustainable business decisions to improve our society and the world. We believe that each person brings a unique value that drives the business though their creativity and passion.
  • The Employee Benefits package includes: Paid Time Off, medical, HSA, vision, dental, FSA, 401(k), profit sharing, legal plan, cancer indemnity plan, disability insurance, life insurance, employee assistance program, commuter benefits, business travel accident, paid volunteer day, paid memberships, paid seminars, and tuition assistance.
  • We offer many socialization opportunities for wellness, financial wellbeing, runs/walks, team building, happy hours, and activities to support the Sustainable Developmental Goals.

Check out our LinkedIn for our employee experience: https://www.linkedin.com/company/smtbny



We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law. SuMi Trust provides reasonable accommodations for employees and applicants with disabilities consistent with applicable law. If you need a reasonable accommodation during the application