Jobs and Careers
FI

Information Security Third Party Risk Management Analyst

First Quality
Home Office (NY), United StatesRemotefull_timeVerifiedPosted 21 May 2024
💰 $120,000/yr($100,000/yr – $120,000/yr)

About the role

First Quality was founded in 1989 and has grown to be a global privately held company with over 4,000 employees. Its corporate offices are located in Great Neck, New York, with manufacturing facilities and offices in Pennsylvania, South Carolina, Georgia, and Canada. First Quality is a diversified family of companies manufacturing consumer products ranging from Absorbent Hygiene (adult incontinence, feminine care, and baby care), Tissue (bath and towel), and Industrial (print and packaging materials), serving institutional and retail markets throughout the world. First Quality focuses on private label and branded product lines.

We are seeking an Information Security Third Party Risk Management Analyst for our First Quality Enterprises working remotely preferably from the Eastern half of the US. This position is responsible for managing the daily operations of the Information Security Third Party Risk Management (TPRM) program within the Information Security Governance, Risk and Compliance (IS GRC) team. This position has several principal responsibilities as outlined below. This position reports to the Manager of Information Security GRC. 

The Information Security Third Party Risk Management Program Analyst will be tasked with running the day-to-day third-party assessments by working alongside the Third Party Risk Lead and Manager of Information Security GRC. The Analyst will be responsible for the day-to-day vetting operations of the Third-Party Risk Management Program which includes risk assessments for vendor applications, software, systems, contractors and consultants. This role will be responsible for ensuring sound security practices are built in throughout the third parties' lifecycle.  

   

Primary responsibilities include:

  • Directly responsible for performing security due diligence risk assessments on new and existing third parties against First Quality policies as well as leading industry practices  
  • Identify third party risks, appropriate risk levels, and recommend remediation or mitigation strategies to the business 
  • Present issues to the business and 3rd parties and obtain corrective action plans 
  • Track and follow up on corrective action plans and review evidence for closure 
  • Work with business and project teams to ensure security controls are built into IT functional specifications using leading industry practices  
  • Review documentation associated with third party risk assessments to identify non-conformances 
  • Establish and maintain Key Performance Indicators (KPIs)and Key Risk Indicators (KRIs) for the Third-Party Risk Management Program and initiatives  
  • Periodically reach out to vendors hosting our data regarding current threats to ensure they are taking necessary steps to reduce exposure and risk 
  • Perform maintenance and configuration changes, as necessary, in the Third-Party Risk Management platform 
  • Update procedure documentation to incorporate process changes 
  • Drive relevant stakeholder participation in evaluation of risk and control effectiveness 
  • Maintain expertise on security trends through training, research, and development to mitigate potential security exposures 
  • Liaise with key functional teams such as HR, IT, OT, Digital Strategy, Finance, Enterprise Risk, Quality, Office of General Counsel and relevant business stakeholders to perform third party security reviews on their new and existing vendors and identify risks that require remediation  

The ideal candidate should possess the following:

  • 5 years’ experience working directly in an Information Security, Information Technology or Operational Technology department with involvement in the Third-Party Risk Management Program 
  • Experience working with any Third-Party Risk Management platform is preferred  
  • Experience securing or assessing SCADA/OT systems and vendor solutions is a plus 
  • Working knowledge of security technologies and controls in the following areas: Operational Technology/SCADA systems, cloud computing, mobile device management, identity and access management, emerging technologies 
  • Working knowledge of the following types of assessment reports: Standard Information Gathering (SIG), SOC 1 and 2 reports, CAIQ 
  • Working knowledge of the following frameworks and regulations: ISO 27001/2, NIST 800-53, NIST CSF, Standard of Good Practice, HIPAA HiTrust 
  • Bachelor's degree in management information systems, computer science, cyber security or equivalent 
  • Ability to work independently and under the guidance of a direct supervisor 
  • Ability to prioritize and multitask and a work approach that supports flexibility and adaptability is paramount 
  • Excellent written and oral communications skills; ability to lead discussions, present ideas to audiences of all

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

First Quality

View company profile →