Jobs and Careers
VE

Principal Cybersecurity Analyst, Privacy and Third Party Risk Management

Vertex
United StatesRemotefull_timeVerifiedPosted 14 Jul 2025
💰 $200,400/yr($133,600/yr$200,400/yr)

About the role

Job Description

We are seeking a seasoned technical privacy specialist to join our Information Security and Cyber Resilience team. We engage proactively with our business colleagues to truly understand them and to deliver results for our company and for patients.  If you thrive in a fast-paced, hands-on, and team-oriented environment where you can have a big impact on the organization, we’d love to talk to you!

The individual in this position will primarily support the Data Technology and Engineering (DTE) Privacy Lead within the Cyber Risk Management and Governance team in representing the Privacy Office, translating policy and privacy standards into requirements within our technical environments. This role will act as a technical subject matter expert on all elements related to data privacy protection and risk mitigation, within the world of DTE, and will also participate in configuring integrations between privacy technologies and other information systems, as well as configuring and testing cookie consent on Vertex’s many online properties.

As part of this role, this individual will work with colleagues across DTE on building data protection and security principles into the implementation of new projects and initiatives as well as the development of compliant systems and processes. Sitting within the Information Security group, this role will help drive Vertex’s information security strategy and Target State Vision, with the necessary principles and capabilities to make Privacy by Design and Security by Design common practices. It’s a small and growing team where you’ll get experience working on a broad range of projects.

This position is a global role reporting to the Cyber Risk Management and Governance Director with a dotted line to the DTE Privacy Lead and will be based in Vertex’s global headquarters in Boston, Massachusetts. Fully remote and flex options are available to the right candidate.

The designation on this role is Hybrid - meaning three days a week onsite in our Boston office.
 

Key Responsibilities 

  • Partnering with DTE and business owners to provide advisory and consulting services around information security and data privacy to drive risk mitigation;
  • Assessing current software and systems, as well as partner and vendor services, for compliance with security and data protection principles and recommending changes and new technologies to help mitigate vulnerabilities and prevent potential future risks;
  • Defining and implementing risk-based solutions to ensure Privacy by Design and Security by Design are adequately embedded in technical projects and systems across the company;
  • Assisting the DTE Third Party Assessment team in the assessment and revision of vendor management processes to ensure that third parties are appropriately vetted prior to engagement;
  • Configuring, testing, and maintaining cookie consent technology on Vertex’s 100+ websites and apps;
  • Configuring integrations between privacy technologies and other technical systems; assisting other Information Security teams as necessary in appropriate integrations for Security and Data Protection;
  • Assisting the DTE Privacy Lead and Cyber Risk Management and Governance Director with training and awareness campaigns, particularly with a focus on system security and data protection initiatives;
  • Supporting the work of the Cyber Risk and Governance team in maintaining effective processes and controls across our computing environment;
  • Assisting the Privacy Office by responding to requests from data subjects to exercise their rights, as needed;
  • Providing forensics and technical assistance for any suspected personal data incidents, working with the DTE Privacy Lead and Privacy Office;
  • Participating in Information Security and Cyber Resilience team and Privacy Office team meetings;
  • Advising on data anonymization, pseudonymization and encryption techniques to develop systems that preserve and improve privacy protections; and
  • Working with the DTE Privacy Lead, the Privacy Office, and the Internal Audit function to conduct regular privacy assessments of operational processes, identifying, and mitigating risks across the company.

Qualifications

  • BS or MS degree in computer science, computer engineering, information systems, privacy engineering, information security or related field of study; or equivalent professional experience.
  • 5 years' experience in information security (preferably focusing on privacy/data protection) or a graduate degree or concentration in privacy engineering
  • 3 years' experience configuring integrations leveraging RESTful APIs, OAuth 2.0, and related tooling
  • IAPP privacy certifications (CIPT, AIGP, CIPP, or CIPM)
  • CISSP or similar security certificatio

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Vertex

View company profile →