Jobs and Careers
FE

Third Party Risk Analyst

Federal Reserve System
United Statesfull_timeVerifiedPosted 21 Feb 2024

About the role

Company

Federal Reserve Bank of Boston

Third Party Risk Analyst

This job is eligible for a hybrid schedule with some onsite work expected. The individual is excepted to reside in the 1st District (or the 5th District) unless you were given an exception.

The Third-Party Risk Management Analyst position will be a member of the Third-Party Risk Management organization within National IT. This Analyst will be a part of a team responsible for assessing the information security practices and posture of new and existing third parties for the Federal Reserve System. This role will have additional TPRM responsibilities supporting the identification, assessment, and mitigation of risks related to National IT’s managed third-party relationships.

This position will leverage various sources of data to assess the security program and associated risk management practices of the Federal Reserve’s suppliers, highlight risks, and control gaps associated with the supplier’s security program, categorize the potential risks based on severity, and identify potential mitigation strategies.  The position is also responsible for translating the results of the analysis into a business consumable format and delivering those results to business, legal, and procurement teams to advise risk decisions.

Additionally, the analyst will be responsible for identifying, performing, and tracking continuous monitoring activities to ensure that risks associated with active suppliers are appropriately managed and mitigated.

This position will participate in cross-functional teams to address information security policy, vendor risk management, or compliance issues.  This position will determine best practices, suggest how to improve current practices, and monitor those practices.

Key Responsibilities (including, but not limited to the following):

  • Conduct comprehensive third-party cyber security assessments utilizing a NIST-based framework; evaluate the security posture of third parties to identify vulnerabilities, gaps, and areas of non-compliance; and identify and recommend security controls, best practices, and risk mitigation strategies in alignment with industry standards and regulatory requirements.

  • Generate detailed reports that provide in-depth analysis of assessment findings, including identified risks, control deficiencies, and recommended remediation actions for vendor engagements.

  • Engage with customers and stakeholders to communicate assessment results, address security concerns, and collaborate on potential remediation actions for vendor engagements.

  • Work as part of a cross-functional team to perform assessments on new and existing vendors to understand any potential threats to the Federal Reserve System, advising Federal Reserve stakeholders on any mitigations needed to reduce potential threats.

  • Review and interpret results of vendor audit reports and attestations (such as SOC2 reports); identify deficiencies and areas for remediation and advise appropriate stakeholders on findings.  May conduct or coordinate periodic vendor audits, in collaboration with Vendor Managers, Internal Audit, and other internal teams as needed.

  • Provide coordination and reporting for third-party risk activities including vendor outreach related to cybersecurity breaches and zero-day vulnerabilities.

  • Leads process improvement and long-term information security solution discussions and presents outcomes in written and verbal format to senior management.

  • Key participant in project development surrounding new processes and the integration of new processes with existing ones. Assists in developing communications of these changes to impacted stakeholders.
     

Education and Experience:

  • Bachelor’s degree in computer science, information systems, or other related fields, or equivalent combination of work experience and education

  • Should possess or be able to achieve Industry recognized certifications within the domains of information security (e.g., CISSP, GIAC, CISM, CISA, CTPRP, CCSP, etc.)

  • 3 years of experience performing cyber security assessments, with a specific focus on third-party assessments and utilizing a NIST-based framework (e.g., NIST 800-53, NIST CSF).

  • Experience with compliance and security audits, and risk mitigation plans.  Experience developing and completing vendor risk assessments for enterprise-level vendor relationships.  Understanding of various risk and security certifications and attestations (SOC2, ISO 27001, etc.).  Familiarity with third party risk and governance concepts.
     

Knowledge and Skills:

  • In-depth understanding of cyber security principles, concepts, and best practices, including risk assessment me

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Federal Reserve System

View company profile →