Jobs and Careers
PN

Security Analyst - Third Party Security Assessments

PNC
Two PNC Plaza (PA374), United States, United Statesfull_timeVerifiedPosted 14 May 2025

About the role

Position Overview

At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company’s success. As a Security Analyst within PNC’s Technology organization, you will be based in Pittsburgh, PA; Cleveland, OH; Birmingham, AL or Dallas, TX.

The position is primarily based in a PNC location. Responsibilities require time in the office or in the field on a regular basis. Some responsibilities may be performed remotely, at the manager’s discretion.


**PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position**

This position is part of the Third Party Security Assurance (TPSA) team, where you will be a member of PNC’s Policy, Governance, and Assessments department that is part of PNC’s overall Enterprise Information Security organization.

The Security Analyst is primarily responsible for conducting third-party security risk assessments across the PNC portfolio of technology suppliers. The role will require extensive coordination with internal third-party resources as well as with the external suppliers. In this role, you will work with third party suppliers to validate that necessary security and technology controls are in place and operationally solid. Specific responsibilities within this position will include:

•Independently manage multiple assessments to completion within SLA. Assessment management includes reviewing returned Due Diligence Questionnaires, creating unique agendas for remote interviews based on controls that need further assessment, conducting remote assessment interviews, creating remediations, etc.
•Elevate issues, delays, obstacles as needed to keep the assessment lifecycle on track.
•Consult on defining third party security policies and best practices.
•Educate and build awareness of third-party security requirements.
•Continuously work to improve the overall third-party security assurance program.
•Assist with testing releases of the PNC TPSA platform.
•Special projects as assigned.

The ideal candidate will have the following qualifications:

REQUIRED skills:
• Bachelor's Degree and at least 3 years of directly related Third Party Risk Management experience preferred.
• Must have a solid understanding of security concepts and controls and industry frameworks including NIST, FFIEC, and CRI Profile.
• Strong understanding of mitigation methodologies and regulatory requirements pertaining to information security, privacy, and/or data security.
• Excellent project management skills, with the ability to work within deadlines, and flexibility to manage multiple, competing priorities.
• Ability to work independently with little direction and/or supervision.
• Superior communication skills with the ability to ask questions, escalate roadblocks early, and interact effectively at all levels within the organization.
• Analytical aptitude with an emphasis on investigative, methodical critical questioning and logical thinking.
• High-level interpersonal skills.
• Experience with supporting toolsets including Sharepoint, Jira, Confluence, and Tableau.
Key Responsibilities:
• Perform comprehensive audits of Third Party enterprise controls, cloud infrastructure, cloud-native applications, and Cloud API / Microservices to assess compliance with security requirements and standards.
• Review cloud configurations, access controls, and security policies and procedures to ensure compliance with industry regulations (GDPR, HIPAA, PCI-DSS, SOC 2).
• Conduct interviews with Third Party SMEs to validate evidence (or compensating controls) on security foundational controls, cloud operations, and security practices.
• Prepare detailed post-assessment reports that summarize the findings and compensating controls in place.
Technical Skills:
• Strong understanding of industry best practice technical and cloud controls, including knowledge of cloud platforms (AWS, Azure, Google Cloud).
• Knowledge of cloud security architecture, controls, and compliance frameworks (SOC 2, ISO 27001, NIST, GDPR, PCI

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

PNC

View company profile →