Jobs and Careers
DI

Vulnerability Analyst ( Third Party Cybersecurity Risk Assessment )

Discover
Riverwoods, IL, United Statesfull_timeVerifiedPosted 27 Mar 2024
💰 $149,300/yr($88,500/yr$149,300/yr)

About the role

Discover. A brighter future.

With us, you’ll do meaningful work from Day 1. Our collaborative culture is built on three core behaviors: We Play to Win, We Get Better Every Day & We Succeed Together. And we mean it — we want you to grow and make a difference at one of the world's leading digital banking and payments companies. We value what makes you unique so that you have an opportunity to shine.

Come build your future, while being the reason millions of people find a brighter financial future with Discover.

Job Description:

At Discover, be part of a culture where diversity, teamwork, and collaboration reign. Join a company that is just as employee focused as it is on its customers and is consistently awarded for both. We’re all about people, and our employees are why Discover is a great place to work. Be the reason we help millions of consumers build a brighter financial future and achieve yours along the way with a rewarding career. 

Excellent opportunity to practice your third party cybersecurity risk assessment expertise and simultaneously grow as a leader. Your primary responsibility is to assess the cybersecurity risks associated with third-party vendors that interact with Discover. Your assessments will ensure that these vendors adhere to our cybersecurity standards, policies, and compliance regulations to protect the customers data and enterprise systems against potential vendor supply chain threats.

Responsibilities 

  • Conduct comprehensive cybersecurity risk assessments of third-party vendors, assessing their security controls, policies, standards, and infrastructure based on the business services they provide. Evaluate vendor compliance with relevant regulatory requirements, industry standards, and contractual obligations. Identify and prioritize potential cybersecurity risks associated with vendor relationships.

  • Analyze assessment findings to determine the level of risk posed by each vendor. Document detailed risk assessments reports and record GRC Issues for the identified vulnerabilities and recommendations for risk mitigation.

  • Communicate assessment results effectively to stakeholders, including senior management, procurement teams, and relevant departments.

  • Partner with the team leads to enhance the Subject Matter Expert (SME) program to perform comprehensive security assessments of third-party vendors.

  • Independently partner with the vendors, business owners, and Business Information Risk Officers (BISO) to manage the assessments with accuracy. 

  • Demonstrable ability to analyze ISO 27001, SOC 2, Shared Information Gathering (SIG), and familiarity with security frameworks such as NIST 800-53, CSF, financial services related regulatory guidance / laws such as GLBA, FFIEC and international regulations such as GDPR.

  • Manage the life cycle of cyber findings / Issues and liaison with stakeholders for permanent remediation.

  • Demonstrate excellent value-added communication and technical writing skills.

  • Advance knowledge / seek training in the field of information security management including the emerging threat actors’ techniques, tactics, and procedures (TTP).

  • Be a frequent value-added speaker in forums and achieve team commitments.

Minimum Qualifications

At a minimum, here is what we need from you: 

  • Bachelors – Computer Science, Information Security, Business or Analytics

  •  4+ years – Information Security, Cybersecurity, Computer Science, Data Analytics or related

  • In lieu of a degree 6+ Years – Information Security, Cybersecurity, Computer Science, Data Analytics or related

Internal applicants only: technical proficiency rating of competent on the Dreyfus cybersecurity scale

Preferred Qualifications:

If we had our say, we would also look for: 

  • Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Third-Party Risk Assessor (CTPRA), or Certified Information Security Manager (CISM) are desirable.

  • Strong understanding of cybersecurity principles, frameworks, and best practices (e.g., NIST Cybersecurity Framework, ISO 27001, GDPR).

  • Knowledge of Business Continuity Planning (BCP) / Resiliency principles.

  • Notable experience in assessment of technological information security threats and controls and vendor risk tiering.

  • Familiarity with Incident Response, penetration testing principles, Common Vulnerability Scoring System (CVSS), and MITRE.

  • Understanding of Agile methodology.

What are you waiting for? Apply today! 

And while you're waiting to hear from us, don't forget to check out the gr

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Discover

View company profile →