RISK ASSESSMENTS: * Use WBD processes and tools to perform 3rd party vendor risk assessments, for new and existing vendors * Work with business to understand the "what" and "how" of services provided ...
RISK ASSESSMENTS: * Use WBD processes and tools to perform 3rd party vendor risk assessments, for new and existing vendors * Work with business to understand the "what" and "how" of services provided ...
RISK ASSESSMENTS: * Use WBD processes and tools to perform 3rd party vendor risk assessments, for new and existing vendors * Work with business to understand the "what" and "how" of services provided ...
RISK ASSESSMENTS: * Use WBD processes and tools to perform 3rd party vendor risk assessments, for new and existing vendors * Work with business to understand the "what" and "how" of services provided ...
VP, Generative AI Risk Oversight
Alpharetta, GA · On-site
$110K - $185K/yr
Perform or oversee AI risk assessments (use case, model, vendor, and process), documenting inherent/residual risk, control effectiveness, and remediation plans. * GenAI and LLM risk controls:
VP, Generative AI Risk Oversight
Alpharetta, GA · On-site
$110K - $185K/yr
Perform or oversee AI risk assessments (use case, model, vendor, and process), documenting inherent/residual risk, control effectiveness, and remediation plans. * GenAI and LLM risk controls:
... IT risk assessments, maintaining governance processes, overseeing the security operations vendor partner relationship, developing risk reporting and dashboards, and partnering with technology and ...
... IT risk assessments, maintaining governance processes, overseeing the security operations vendor partner relationship, developing risk reporting and dashboards, and partnering with technology and ...
The Director will lead a team responsible for external audits, customer compliance activities, third-party risk assessments, and vendor oversight, with particular focus on SOC 2 Type II, PCI DSS, and ...
The Director will lead a team responsible for external audits, customer compliance activities, third-party risk assessments, and vendor oversight, with particular focus on SOC 2 Type II, PCI DSS, and ...
Support vendor risk assessments and business continuity planning for critical service providers, including escalation support and contingency planning where appropriate. * Help ensure vendor ...
Support vendor risk assessments and business continuity planning for critical service providers, including escalation support and contingency planning where appropriate. * Help ensure vendor ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
... Party Vendor Risk Management, improved Business Continuity, and the overall ERM program. * Facilitate the enterprise risk assessment and related reporting including 10-K Risk Factors, key risk ...
... Party Vendor Risk Management, improved Business Continuity, and the overall ERM program. * Facilitate the enterprise risk assessment and related reporting including 10-K Risk Factors, key risk ...
Support vendor risk assessments and business continuity planning for critical service providers, including escalation support and contingency planning where appropriate. * Help ensure vendor ...
Support vendor risk assessments and business continuity planning for critical service providers, including escalation support and contingency planning where appropriate. * Help ensure vendor ...
Support vendor risk assessments and business continuity planning for critical service providers, including escalation support and contingency planning where appropriate. * Help ensure vendor ...
Support vendor risk assessments and business continuity planning for critical service providers, including escalation support and contingency planning where appropriate. * Help ensure vendor ...
Support vendor risk assessments and business continuity planning for critical service providers, including escalation support and contingency planning where appropriate. * Help ensure vendor ...
Support vendor risk assessments and business continuity planning for critical service providers, including escalation support and contingency planning where appropriate. * Help ensure vendor ...
Senior Security Engineer
Atlanta, GA · On-site
$110K - $151K/yr
... vendor risk assessments. • Experience across Information Security domains such as governance & compliance, incident response, identity & access management, penetration testing, or e-discovery ...
Senior Security Engineer
Atlanta, GA · On-site
$110K - $151K/yr
... vendor risk assessments. • Experience across Information Security domains such as governance & compliance, incident response, identity & access management, penetration testing, or e-discovery ...
Risk Analyst
Atlanta, GA · On-site +1
$87K - $110K/yr
Perform third-party security and compliance risk assessments for new and existing vendors, evaluating risk exposure, control effectiveness, business impact, and remediation requirements * Review SOC ...
Risk Analyst
Atlanta, GA · On-site +1
$87K - $110K/yr
Perform third-party security and compliance risk assessments for new and existing vendors, evaluating risk exposure, control effectiveness, business impact, and remediation requirements * Review SOC ...
... vendor relationships in the role of Staff Risk Analyst. The ideal candidate will have proven ... Create and conduct supplier assessments and development plans including supplier evaluation ...
... vendor relationships in the role of Staff Risk Analyst. The ideal candidate will have proven ... Create and conduct supplier assessments and development plans including supplier evaluation ...
... vendor relationships in the role of Staff Risk Analyst. The ideal candidate will have proven ... Create and conduct supplier assessments and development plans including supplier evaluation ...
New
... vendor relationships in the role of Staff Risk Analyst. The ideal candidate will have proven ... Create and conduct supplier assessments and development plans including supplier evaluation ...
New
... vendor relationships in the role of Staff Risk Analyst. The ideal candidate will have proven ... Create and conduct supplier assessments and development plans including supplier evaluation ...
... vendor relationships in the role of Staff Risk Analyst. The ideal candidate will have proven ... Create and conduct supplier assessments and development plans including supplier evaluation ...
The ideal candidate will conduct application and vendor risk assessments, produce risk remediation reports and/or risk waivers, assist in addressing any network security corrective actions, and work ...
The ideal candidate will conduct application and vendor risk assessments, produce risk remediation reports and/or risk waivers, assist in addressing any network security corrective actions, and work ...
Perform risk assessments across Data Protection, Supplier Management, and Enterprise Risk ... Ability to establish and maintain effective working relationships with employees, vendors, clients ...
Perform risk assessments across Data Protection, Supplier Management, and Enterprise Risk ... Ability to establish and maintain effective working relationships with employees, vendors, clients ...
Lead Catastrophe Risk Analyst
Duluth, GA · On-site
Assess data quality of exposure data. * Manipulate and prepare large databases of property ... Maintain inventories of vendor/broker catastrophe models, vendor products, and data sources.
Lead Catastrophe Risk Analyst
Duluth, GA · On-site
Assess data quality of exposure data. * Manipulate and prepare large databases of property ... Maintain inventories of vendor/broker catastrophe models, vendor products, and data sources.
Vendor Risk Assessment information
See Atlanta, GA salary details
$49.5K - $59.9K
4% of jobs
$59.9K - $70.2K
6% of jobs
$70.2K - $80.6K
11% of jobs
$84.5K is the 25th percentile. Wages below this are outliers.
$80.6K - $91K
11% of jobs
The median wage is $99.2K / yr.
$91K - $101.3K
23% of jobs
$101.3K - $111.7K
13% of jobs
$118.5K is the 75th percentile. Wages above this are outliers.
$111.7K - $122K
12% of jobs
$122K - $132.4K
8% of jobs
$132.4K - $142.8K
6% of jobs
$142.8K - $153.1K
4% of jobs
$153.1K - $163.5K
2% of jobs
$49.5K
$107.3K
$163.5K
How much do vendor risk assessment jobs pay per year?
What is a vendor risk assessment?
What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?
What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?
What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?
| Aspect | Vendor Risk Assessment | Vendor Compliance Analyst |
|---|---|---|
| Primary Focus | Evaluating risks associated with vendors and third-party providers | Ensuring vendors comply with policies, regulations, and contractual obligations |
| Certifications | Certifications like CISSP, CISA, or vendor risk management courses | Certifications such as CCEP, CISA, or compliance-specific credentials |
| Work Environment | Risk management teams, procurement, cybersecurity departments | Compliance teams, legal, procurement, and audit departments |
| Industry Usage | Common in finance, healthcare, and IT sectors | Prevalent in regulated industries like finance, healthcare, and manufacturing |
Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.
Senior Information Security Risk Analyst (3rd Party Vendor Risk)
Atlanta, GA • On-site
Full-time
Re-posted 5 days ago
Warner Bros. Discovery rating
7.7
Based on 55 frontline employees who took The Breakroom Quiz
32nd of 78 rated media
Job description
Who We Are...
When we say, "the stuff dreams are made of," we're not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth. Behind WBD's vast portfolio of iconic content and beloved brands, are the storytellers bringing our characters to life, the creators bringing them to your living rooms and the dreamers creating what's next...
From brilliant creatives, to technology trailblazers, across the globe, WBD offers career defining opportunities, thoughtfully curated benefits, and the tools to explore and grow into your best selves. Here you are supported, here you are celebrated, here you can thrive.
*Must work a hybrid schedule (3 days onsite) out of our Atlanta office.*
THE JOB:
The Senior Information Security Risk Analyst will support the assessment of information security risks across all of Warner Bros. Discovery's (WBD's) third party suppliers/vendors. This role requires the ability to understand and assess information security risks posed by third parties and clearly communicate those risks to the business. It will apply global IT industry best practices to ensure WBD uses third party information security risk management to foster business-enabling insights.
RISK ASSESSMENTS:
- Use WBD processes and tools to perform 3rd party vendor risk assessments, for new and existing vendors
- Work with business to understand the "what" and "how" of services provided by vendor to assess level of risk and scope of assessment
- Perform timely assessments of Vendor controls to identify, document, and communicate key deficiencies to the business and Information Security management
- Report on assessment outcomes, risk level and associated recommendations to remediate issues
- Perform 2nd-level peer reviews of assessment outputs, prior to reports being finalized, to drive consistency and completeness of findings based on risk of engagement
- Assist with follow-up on documentation requests for initial and periodic assessments
FINDINGS MANAGEMENT:
- Monitor corrective action plans against agreed upon timelines
- Review of remediation evidence for closure of findings
CONTRACT REVIEWS:
- Review contracts to ensure appropriate data security terms are included
- Provide comment and acceptable alternatives to vendor contract revisions, in alignment with defined guidance
- Escalate provision changes, as needed
OTHER:
- Assist with contract intake to ensure pipeline of assessments is managed in a timely and efficient manner
- Provide periodic status updates
- Maintain accurate and complete data within the identified system of record
- Contribute to the team's continuous improvement efforts by identifying opportunities and helping to implement them
THE ESSENTIALS:
- BS/BA degree required
- 3-5 years' experience in information security, with at least one (1) year experience in third party risk management
- Knowledge of IP network infrastructure (firewalls, intrusion detection/prevention), access control, data encryption and physical security; Cloud security knowledge a plus
- Excellent communication skills, including the ability to communicate effectively in English, both written and verbal
- Ability to present complex topics in clear, non-technical language
- Ability to work collaboratively within team and across business and technology functions
- Detail-oriented individual with critical thinking, analytical, and problem-solving skills
- Demonstrated ability to be proactive and take ownership of and solve problems
- Active learner - able to enhance personal, professional, and business growth through new knowledge and experiences
- Ability to handle multiple assignments concurrently within an iterative environment
THE NICE TO HAVES:
- One or more of the following certifications: CISSP, CRISC, CISA
- 2+ years of prior experience in a related field (media, entertainment, business development or streaming services industry experience a plus)
- Familiarity with streaming and similar products/services
- Experience working in a national or global company
How We Get Things Done...
This last bit is probably the most important! Here at WBD, our guiding principles are the core values by which we operate and are central to how we get things done. You can find them at www.wbd.com/guiding-principles/ along with some insights from the team on what they mean and how they show up in their day to day. We hope they resonate with you and look forward to discussing them during your interview.
Championing Inclusion at WBD
Warner Bros. Discovery embraces the opportunity to build a workforce that reflects a wide array of perspectives, backgrounds and experiences. Being an equal opportunity employer means that we take seriously our responsibility to consider qualified candidates on the basis of merit, without regard to race, color, religion, national origin, gender, sexual orientation, gender identity or expression, age, mental or physical disability, and genetic information, marital status, citizenship status, military status, protected veteran status or any other category protected by law.
If you're a qualified candidate with a disability and you require adjustments or accommodations during the job application and/or recruitment process, please visit our accessibility page for instructions to submit your request.
What Warner Bros. Discovery employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Warner Bros. Discovery
Sourced by ZipRecruiter
Industry
Media and telecom
Company size
10,000+ Employees
Headquarters location
New York, NY, US
Year founded
2022