Third Party Cybersecurity GRC Advisor Information Security Advisor ( Third Party Cybersecurity GRC ... analysts by providing guidance on assessment quality, evidence review, control interpretation, risk ...
Third Party Cybersecurity GRC Advisor Information Security Advisor ( Third Party Cybersecurity GRC ... analysts by providing guidance on assessment quality, evidence review, control interpretation, risk ...
Third Party Cybersecurity GRC Advisor Information Security Advisor ( Third Party Cybersecurity GRC ... analysts by providing guidance on assessment quality, evidence review, control interpretation, risk ...
Third Party Cybersecurity GRC Advisor Information Security Advisor ( Third Party Cybersecurity GRC ... analysts by providing guidance on assessment quality, evidence review, control interpretation, risk ...
Our Cyber Defense & Risk Analyst is responsible for strengthening Veritiv's security posture ... This position partners closely with IT teams, Legal, Internal Audit, and third-party security ...
Our Cyber Defense & Risk Analyst is responsible for strengthening Veritiv's security posture ... This position partners closely with IT teams, Legal, Internal Audit, and third-party security ...
Our Cyber Defense & Risk Analyst is responsible for strengthening Veritiv's security posture ... This position partners closely with IT teams, Legal, Internal Audit, and third-party security ...
Our Cyber Defense & Risk Analyst is responsible for strengthening Veritiv's security posture ... This position partners closely with IT teams, Legal, Internal Audit, and third-party security ...
Risk Manager / Senior Risk Analyst
Atlanta, GA · On-site
$120K - $150K/yr
Dealer General Warranty (DGW) is our specialized Third-Party Administration (TPA) business focused ... Lead internal analysis and reporting functions by identifying and measuring key KPIs in Sales and ...
Risk Manager / Senior Risk Analyst
Atlanta, GA · On-site
$120K - $150K/yr
Dealer General Warranty (DGW) is our specialized Third-Party Administration (TPA) business focused ... Lead internal analysis and reporting functions by identifying and measuring key KPIs in Sales and ...
Risk Manager / Senior Risk Analyst
Atlanta, GA · On-site
$120K - $150K/yr
Dealer General Warranty (DGW) is our specialized Third-Party Administration (TPA) business focused ... Lead internal analysis and reporting functions by identifying and measuring key KPIs in Sales and ...
Quick apply
Risk Manager / Senior Risk Analyst
Atlanta, GA · On-site
$120K - $150K/yr
Dealer General Warranty (DGW) is our specialized Third-Party Administration (TPA) business focused ... Lead internal analysis and reporting functions by identifying and measuring key KPIs in Sales and ...
Risk Analyst
Atlanta, GA · On-site
$95K - $110K/yr
Risk Analyst - Atlanta To Apply Now - email your resume to [email protected] Who: A growing auto finance company building out its credit risk team. What: Analyze and forecast repossessions ...
Risk Analyst
Atlanta, GA · On-site
$95K - $110K/yr
Risk Analyst - Atlanta To Apply Now - email your resume to [email protected] Who: A growing auto finance company building out its credit risk team. What: Analyze and forecast repossessions ...
Vendor Analyst, AI & Technology Risk
Atlanta, GA · Hybrid
$85K - $110K/yr
Support Vendor Management in aligning with third-party risk requirements AI Governance Operations * Support execution of AI intake and governance workflows: * Track AIA Forms and FactSheets * Ensure ...
Vendor Analyst, AI & Technology Risk
Atlanta, GA · Hybrid
$85K - $110K/yr
Support Vendor Management in aligning with third-party risk requirements AI Governance Operations * Support execution of AI intake and governance workflows: * Track AIA Forms and FactSheets * Ensure ...
Facilitate legal review and Third Party Risk Management Assessment processes. What We are Looking ... Ability to analyze data to identify potential opportunities for cost savings, cost avoidance and ...
Facilitate legal review and Third Party Risk Management Assessment processes. What We are Looking ... Ability to analyze data to identify potential opportunities for cost savings, cost avoidance and ...
Staff Cybersecurity Analyst, Risk Management
$140K - $186K/yr
The analyst will leverage Rivian's risk platforms and AI-enabled tooling to improve efficiency ... Third-Party Risk Management (TPRM) lead, security engineering teams, and other functions.
Staff Cybersecurity Analyst, Risk Management
$140K - $186K/yr
The analyst will leverage Rivian's risk platforms and AI-enabled tooling to improve efficiency ... Third-Party Risk Management (TPRM) lead, security engineering teams, and other functions.
Staff Cybersecurity Analyst, Risk Management
Riverdale, GA · On-site
$140K - $175K/yr
The analyst will leverage Rivian's risk platforms and AI-enabled tooling to improve efficiency ... Third-Party Risk Management (TPRM) lead, security engineering teams, and other functions.
Staff Cybersecurity Analyst, Risk Management
Riverdale, GA · On-site
$140K - $175K/yr
The analyst will leverage Rivian's risk platforms and AI-enabled tooling to improve efficiency ... Third-Party Risk Management (TPRM) lead, security engineering teams, and other functions.
Staff Cybersecurity Analyst, Risk Management
Riverdale, GA · On-site
$140K - $186K/yr
The analyst will leverage Rivian's risk platforms and AI-enabled tooling to improve efficiency ... Third-Party Risk Management (TPRM) lead, security engineering teams, and other functions.
Staff Cybersecurity Analyst, Risk Management
Riverdale, GA · On-site
$140K - $186K/yr
The analyst will leverage Rivian's risk platforms and AI-enabled tooling to improve efficiency ... Third-Party Risk Management (TPRM) lead, security engineering teams, and other functions.
Manager, Third Party Vendor Management
Alpharetta, GA · On-site +1
Facilitate legal review and Third Party Risk Management Assessment processes. What We are Looking ... Ability to analyze data to identify potential opportunities for cost savings, cost avoidance and ...
Manager, Third Party Vendor Management
Alpharetta, GA · On-site +1
Facilitate legal review and Third Party Risk Management Assessment processes. What We are Looking ... Ability to analyze data to identify potential opportunities for cost savings, cost avoidance and ...
... analyze, and monitor all operational risk management activities within the company's business units. This position will also be responsible for oversight and program management of third-party risk ...
... analyze, and monitor all operational risk management activities within the company's business units. This position will also be responsible for oversight and program management of third-party risk ...
... Third Party Risk Management and Corporate Insurance frameworks and programs. These programs ... Strong analytical, organizational, and communication skills. Knowledge of risk management and ...
... Third Party Risk Management and Corporate Insurance frameworks and programs. These programs ... Strong analytical, organizational, and communication skills. Knowledge of risk management and ...
Risk Analyst I
Atlanta, GA · On-site
$31/hr
Title - Risk Analyst I Duration - 12 months Shift - 8 am to 5 pm Location - Atlanta GA 30308 ... Must be able to work Weekends and most holidays. Potential workdays pending assignment after start ...
Quick apply
Risk Analyst I
Atlanta, GA · On-site
$31/hr
Title - Risk Analyst I Duration - 12 months Shift - 8 am to 5 pm Location - Atlanta GA 30308 ... Must be able to work Weekends and most holidays. Potential workdays pending assignment after start ...
Understanding of risk, compliance, controls, audit, business continuity, or third-party risk * Ability to support users, troubleshoot issues, manage data quality, and improve workflows * Experience ...
New
Understanding of risk, compliance, controls, audit, business continuity, or third-party risk * Ability to support users, troubleshoot issues, manage data quality, and improve workflows * Experience ...
New
Strong analytical and problem-solving skills with attention to detail * Ability to explain ... Third-Party Risk Management) * Familiarity with the eDiscovery lifecycle and litigation holds.
Strong analytical and problem-solving skills with attention to detail * Ability to explain ... Third-Party Risk Management) * Familiarity with the eDiscovery lifecycle and litigation holds.
Reviews the work of third-party contractors and provides directional leadership regarding ... Provides guidance to less experienced Collateral Risk Analysts in Collateral Services department ...
Reviews the work of third-party contractors and provides directional leadership regarding ... Provides guidance to less experienced Collateral Risk Analysts in Collateral Services department ...
3rd Party Collections Specialists
Atlanta, GA · On-site +1
$17.50 - $23.75/hr
... Analyze account histories to determine appropriate collection strategies Maintain accurate and compliant account documentation What We're Looking For Minimum 2 years of 3rd-party collections ...
3rd Party Collections Specialists
Atlanta, GA · On-site +1
$17.50 - $23.75/hr
... Analyze account histories to determine appropriate collection strategies Maintain accurate and compliant account documentation What We're Looking For Minimum 2 years of 3rd-party collections ...
Weekend Third Party Risk Analyst information
What are Weekend Third Party Risk Analysts?
What are the key skills and qualifications needed to thrive as a Weekend Third Party Risk Analyst, and why are they important?
What is the difference between Weekend Third Party Risk Analyst vs Weekend Vendor Risk Analyst?
| Aspect | Weekend Third Party Risk Analyst | Weekend Vendor Risk Analyst |
|---|---|---|
| Certifications | Certifications like CRCM, CRM, or FRM often preferred | Similar certifications, often including vendor management or risk certifications |
| Work Environment | Financial institutions, banks, or corporations assessing third-party risks on weekends | Organizations managing vendor relationships and assessing vendor risks during weekends |
| Industry Usage | Common in banking, finance, and regulated industries | Used across various sectors including retail, healthcare, and technology |
The Weekend Third Party Risk Analyst and Weekend Vendor Risk Analyst roles share similar responsibilities in assessing risks related to external entities during weekend hours. Both require knowledge of risk management, compliance, and vendor or third-party oversight. The main difference lies in terminology and industry usage, with the Third Party Risk Analyst often associated with financial institutions and the Vendor Risk Analyst more common in diverse industries. Both roles are crucial for maintaining organizational security and compliance during weekend operations.
What are the primary challenges a Weekend Third Party Risk Analyst faces, and how can they be effectively addressed?
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 7 days ago
Elevance Health rating
7.8
Based on 331 frontline employees who took The Breakroom Quiz
166th of 260 rated insurance
Job description
Anticipated End Date:
2026-06-12Position Title:
Third Party Cybersecurity GRC AdvisorJob Description:
Information Security Advisor ( Third Party Cybersecurity GRC Advisor )
Information Security Risk Management
Hybrid 1: This role requires associates to be in-office 1 - 2 days per week in the Indianapolis, IN or Atlanta, GA office, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace.
- Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.
TheInformation Security Advisor is responsible for independently assessing, documenting, and monitoring cybersecurity risks associated with third-party vendors, service providers, and business partners. This role evaluates vendor security controls, reviews assurance evidence, identifies control gaps, supports remediation and risk acceptance decisions, and provides subject matter expertise throughout the vendor lifecycle.
How you will make an impact:
- Evaluate vendor security documentation, including SOC reports, ISO certifications, HITRUST certifications, penetration test summaries, security questionnaires, policies, data flow diagrams, and remediation evidence.
- Assess vendor controls related to access management, encryption, vulnerability management, incident response, business continuity, disaster recovery, cloud/SaaS security, secure software development, and data protection.
- Provides first level engineering design functions and trouble resolution.
- Communicate directly with vendors to clarify questionnaire responses, request supporting evidence, validate remediation status, and coordinate risk mitigation activities.
- Support internal and external audit and compliance activities, including HIPAA, HITRUST, NIST, PCI DSS, SOC 2, and other healthcare or cybersecurity-related assessments.
- Provides trouble resolution and serves as point of technical escalation on complex problems.
- Leads or plans implementations for access management and network security technologies.
- Develops testing plans to ensure quality of implementation.
- Leads the investigation and reporting of data security events and incidents.
- Provides system and network architecture support for information and network security technologies.
- Provides technical support to business and technology associates in risk assessments and implementation of appropriate information security procedures, standards and technologies.
- Maintains security incident response plans.
- Represents major upgrades and business system replacements in change control.
- Oversees Enterprise mix of vendor services.
- Recommends changes and updates to strategy.
- May act a key contact for setting vendor strategy.
- Designs & engineers repetitive technical solutions based on business requirements and defined technology standards.
- Mentor junior analysts by providing guidance on assessment quality, evidence review, control interpretation, risk documentation, and stakeholder communication.
- Contribute to continuous improvement of third-party cybersecurity risk management standards, procedures, workflows, assessment templates, risk scoring methodology, dashboards, and reporting.
Minimum Requirements:
- Requires BS/BA degree in Information Technology or related field of study and a minimum of 5 years experience in systems support, system administration, system engineering, system security, access management, network security, network communications, computer networking, telecommunications, systems development and management, hardware, software, and/or data; or any combination of education and experience, which would provide an equivalent background.
Preferred Skills, Capabilities and Experiences:
- Requires experience in planning and designing highly complex systems.
- Experience with multiple technical and business disciplines strongly preferred.
- Security Certifications: CISSP or other technical security certifications (e.g. Systems Security Certified Practitioner, Certification and Accreditation Professional) strongly preferred.
- Bachelor's degree in cybersecurity, information systems, computer science, risk management, business, or a related field; or equivalent combination of education, training, and work experience.
- 5+ years of experience in cybersecurity, third-party risk management, IT risk, GRC, IT audit, regulatory compliance, vendor risk management, or a related field.
- Experience with common cybersecurity frameworks, standards, and assurance reports, such as NIST CSF, NIST SP 800-53, NIST SP 800-161, ISO 27001/27002, SOC 2, CIS Controls, Shared Assessments SIG, CSA CAIQ, or CSA CCM.
- Experience with ServiceNow GRC/IRM, Vendor Security Risk Management, or similar third-party risk management workflows.
- Experience performing third-party cybersecurity assessments in healthcare, insurance, financial services, or another regulated industry.
- Familiarity with HIPAA, HITRUST, NIST, PCI DSS, SOC 2, ISO 27001, cloud security, and privacy/data protection control expectations.
- Experience with security rating or vendor monitoring tools such as BitSight, SecurityScorecard, RiskRecon, UpGuard, Black Kite, OneTrust, Archer, ProcessUnity, or similar platforms.
- Relevant certification such as CISA, CRISC, CISSP, CISM, Security+, CCSK, CCSP, ISO 27001 Lead Auditor/Implementer, AWS Certified Cloud Practitioner, or PCI DSS-related experience.
Job Level:
Non-Management ExemptWorkshift:
Job Family:
IFT > IT Security & CompliancePlease be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.
Who We Are
Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.
How We Work
At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.
We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.
Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.
The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.
Elevance Health is an Equal Employment Opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws. Applicants who require accommodation to participate in the job application process should submit the following form: Accessibility Accommodation Request Form and a member of the team will be in contact. Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws, including, but not limited to, the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act.
Prospective employees required to be screened under Florida law should review the education and awareness resources at HB531 | Florida Agency for Health Care Administration.
NOTE: Workday keeps job postings active through 11:59:59 PM on the day before the listed end date. Example: If the end date is 3/13, the posting will automatically come down on 3/12 at 11:59:59 PM. In other words - the job is posted until 3/13, not through 3/13.
What Elevance Health employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Elevance Health
Sourced by ZipRecruiter
Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. A Fortune 20 company with a longstanding history in the healthcare industry, we are looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve. You will thrive in a complex and collaborative environment where you take action and ownership to solve problems and lead change. Do you want to be part of a larger purpose and an evolving, high-performance culture that empowers you to make an impact?
Industry
Health care and social assistance
Company size
10,000+ Employees
Headquarters location
Indianapolis, IN, US
Year founded
2004