Jobs and Careers
GA

Senior Security Engineer - Third Party Risk Management

Gartner
United Statesfull_timeVerifiedPosted 23 Sept 2024
💰 $149,000/yr($100,000/yr$149,000/yr)

About the role

Hiring near our US Centers of Excellence.

Hybrid, flexible environment

Irving, TX

Gartner offers a hybrid, flexible environment, with remote work  that allows associates great flexibility to work from home, and opportunities to connect with colleagues for moments that matter on-site. Candidates that apply should be located within a reasonable proximity to one of Gartner’s Centers of Excellence office locations.

About Gartner IT:

Join a world-class team of skilled engineers who build creative digital solutions to support our colleagues and clients.  We make a broad organizational impact by delivering cutting-edge technology solutions that power Gartner.  Gartner IT values its culture of nonstop innovation, an outcome-driven approach to success, and the notion that great ideas can come from anyone on the team.  
 

About the role:

The Senior Security Engineer is a key member of the Third Party Risk Management Team within the Governance and Risk Management Pillar (GRM) at Gartner. The engineer is responsible for identifying, assessing, and mitigating cyber security risks associated with an organization's reliance on external vendors, suppliers, and other third parties.

What you will do:

  • Vendor Due Diligence: Conduct thorough due diligence on potential third-party vendors to assess their cyber security maturity, operational capabilities, and compliance with legal and regulatory requirements. 

  • Risk Rating: Develop or improve the risk rating system to categorize third parties based on the level of risk they pose to the organization. 

  • Ongoing Monitoring: Continuously monitor third-party performance and risk profiles, updating risk assessments as necessary. 

  • Contractual Safeguards: Work with legal and procurement teams to ensure that contracts with third parties include necessary InfoSec clauses, such as Encryption standards, access controls, breach notification etc.

  • Develop and implement processes for identifying, reporting, and managing incidents related to third-party risks, including critical data breaches, security incidents and service disruptions. 

  • Regulatory Compliance: Ensure that third-party relationships comply with relevant regulatory requirements and industry standards, such as GDPR, HIPAA, and ISO 27001. 

  • Audit and Reporting: Coordinate third-party audits and assessments, and prepare KPI/KRIs for senior management and regulatory authorities as needed. 

  • Cross-Functional Teams: Collaborate with various departments, including IT, legal, compliance, and procurement, to ensure a cohesive approach to third-party risk management. 

  • Stakeholder Communication: Act as the primary point of contact for internal and external stakeholders on matters related to third-party risk management. 

  • Vendor Relationships: Foster strong relationships with key third-party vendors to ensure mutual understanding of risk management expectations and requirements. 

What you will need:

  • Bachelor's or master's degree in computer science, information systems, cybersecurity or a related field.

  • 4-5 years of experience in risk management, vendor management, or a related field. 

  • Industry Knowledge: In-depth understanding of relevant regulations, industry standards, and best practices in third-party risk management. 

  • Risk Assessment Tools: Proficiency in using risk assessment and management tools, such as MetricStream, OneTrust, or similar platforms. 

  • Data Analysis: Strong analytical skills and the ability to interpret complex data to identify trends and potential risks. 

  • IT Proficiency: Knowledge of information technology systems and cybersecurity practices related to third-party risk management. 

  • The ideal candidate will maintain one or more of the following certifications: Certified Information Systems Auditor (CISA), Certified Risk Manager (CRM), ISO27001 or Certified in Risk and Information Systems Control (CRISC) is preferred

What you will get:

  • Competitive Compensation Package

  • Ongoing mentorship and apprenticeship; Leadership courses, development programs, technical courses, certifi

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Gartner

View company profile →