Senior Analyst, Information Security & IT Vendor Risk Management
QTS Data CentersAbout the role
Who We Are:
It's pretty exciting, to find yourself standing in a pivotal moment in time. It’s even more exciting to be out front leading it. At QTS, our world-class data centers are supporting our customers most strategic growth initiatives, positioning us at the forefront of today’s dynamic digital transformation.
As AI and cloud drive the demand for increased speed, capacity and capability, QTS has emerged as the global digital infrastructure leader, committed to connecting the world for good. Driven by purpose and fueled by a spirit of innovation, QTS designs, builds and operates some of the world’s most advanced, forward-thinking data centers. QTS is a portfolio company of Blackstone.
QTS is Powered by People. People who play a vital role in our company’s culture, innovation and growth. People who are committed to contributing to the communities where we operate and work. People who are knowledgeable, resourceful and mission driven. Together, we do great things.
Who You Are:
The Senior Analyst, Information Security & IT Vendor Risk Management, will provide subject matter expertise in third-party security risk oversight, owning the platform used to manage IT vendors and executing key functions within the QTS Third-Party Risk Management (TPRM) program.
This role ensures consistent application of security and compliance requirements across the vendor ecosystem, performs in-depth risk assessments, supports remediation of vendor-related cyber incidents or breaches, and drives continuous improvement in alignment with enterprise security strategy.
This position reports to the Sr. Manager of TPRM and partners closely with Information Security, IT, Procurement, Legal, and Compliance stakeholders.
This position is available in any of these three QTS locations: Overland Park, KS; Suwanee, GA; or Ashburn, VA.
What You Will Do:
Own and administer the TPRM/Vendor Risk Management (VRM) platform used for vendor onboarding, due diligence, periodic assessments, issue management, ongoing monitoring, and off-boarding.
Lead security-focused risk assessments of IT and cloud vendors, analyzing controls for infrastructure, applications, privacy, and business continuity.
Support third-party incidents and breach remediation by coordinating with vendors and internal stakeholders to identify & validate impact, document response, and track corrective actions.
Monitor vendor performance and control effectiveness against recognized security frameworks (NIST, ISO 27001, SOC 2, HITRUST, CMMC, PCI DSS) and regulatory requirements (GDPR, HIPAA, etc.).
Create and maintain the risk register, maintain the vendor inventory and issue tracking with accurate, up-to-date information within the VRM platform.
Provide executive reporting on vendor risk posture, program metrics, incident & remediation status.
Partner with stakeholders to update standards, procedures, and controls, maturing the TPRM program to meet evolving cyber and regulatory requirements.
Liaise with internal and external auditors to manage IT security and compliance reviews tied to vendor controls.
Deliver training and awareness to stakeholders to strengthen risk management culture across business functions.
Stay updated on the latest security trends and threat intelligence.
What You Need To Be Successful:
Bachelor’s degree required.
Minimum of 5 years of experience in IT security risk management, third-party/vendor risk management, or related fields.
Previous vendor management experience required
Understanding of security risks across IT operations, including application development, cloud infrastructure, and disaster recovery.
Proficient in applying security and compliance frameworks such as NIST, ISO 27001, SOC 2, PCI DSS, HITRUST, GDPR, CMMC, and HIPAA.
Experience managing or administering vendor risk management (VRM/TPRM) or governance, risk, and compliance (GRC) platforms.
Skilled in evaluating SOC 2 reports, penetration test results, security questionnaires, and vendor security documentation.
Proven ability to assess risk and identify vulnerabilities through detailed risk reviews.
Demonstrated experience supporting third-party cyber incidents and breach response efforts.
Knowledge, Skills & Abilities
Strong analytical and problem-solving skills with a focus on identifying security gaps and remediating vendor risks.
Highly organized, detail-oriented, and capable of managing multiple vendor reviews simultaneously.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s