Jobs and Careers
PN

Senior Security Specialist - Third Party Security Assessments

PNC
Pittsburgh, United Statesfull_timeVerifiedPosted 13 Jul 2025
💰 $185,150/yr($80,000/yr$185,150/yr)

About the role

Position Overview

At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company’s success. As a Senior Security Specialist within PNC’s Technology organization, you will be based in Pittsburgh, PA; Cleveland, OH; Birmingham, AL or Dallas, TX. The position is primarily based in a PNC location. Responsibilities require time in the office or in the field on a regular basis. Some responsibilities may be performed remotely, at the manager’s discretion.

**PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position**

You will be part of a diversified financial services firm that reflects the needs, values and goals of our customers, employees, communities and shareholders. You will be instrumental in helping to maintain PNC’s reputation for excellence in protecting customer and business information assets. As a Senior Security Specialist within the Third Party Security Assurance (TPSA) team, you will be a member of PNC’s Policy, Governance, and Assessments department that is part of PNC’s overall Enterprise Information Security organization.

Job Profile:
The Security Specialist Sr in this role is primarily responsible for managing a portfolio of third party security assessments across a portfolio of third party suppliers. The role will require leadership and extensive coordination with internal third-party resources as well as with the external suppliers. In this role, you will be the expert on the team to help assist TPSA Assessors to conduct and thoroughly complete third party Security assessments, work with third party suppliers to validate that necessary security and technology controls are in place, and work with internal stakeholder to manage a portfolio of engagements. Specific responsibilities within this position will include:

• Serve as subject matter expert of third party risk identification across various security disciplines as part of the PNC Third Party Security assessment process.
• Conduct and lead Risk Office meetings with Enterprise Third Party Management (ETPM) and Lines of Business (LOBs) to manage a portfolio of third party engagements.
• Scope and determine level of assessments against a set of risk characteristics for a portfolio of third party engagements.
• Serve as an escalation point to address issues, delays, obstacles as needed to keep the assessment lifecycle on track.
• Submit and manage Findings discovered as a result of third party assessments for the assigned portfolio of engagements.
• Conduct peer reviews of the portfolio of assessments and communicate findings to ETPM/LOBs during the lifecycle of the assessments.
• Conduct assessments to completion within SLA when needed. Assessment management includes reviewing returned Due Diligence Questionnaires, creating unique agendas for remote interviews based on controls that need further assessment, conducting remote assessment interviews, creating remediations, etc.
• Advanced understanding of secure Cloud and Artificial Intelligence infrastructure.
• Experience editing third party sourcing contracts to protect security requirements.
• Educate and build awareness of third-party security requirements across the TPSA team and stakeholders.
• Identify and lead efforts to improve the overall third-party security assurance program.
• Assist with testing releases of the PNC TPSA platform.
• Consult on defining third party security policies and best practices.
• Deliver assessment results to LOB stakeholders.
• Special projects as assigned.


REQUIRED skills:
• Bachelor's Degree and at least 3 years of directly related experience.
Experience working in Third Party Risk Management preferred.
• Must have a solid understanding of security concepts and controls and industry frameworks including NIST, FFIEC, and CRI Profile.
• Strong understanding of mitigation methodologies and regulatory requirements pertaining to information security, privacy, and/or data security.
• Excellent project management skills, with the ability to work within de

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

PNC

View company profile →