Third Party Risk Management Senior Analyst
VeriskAbout the role
Company Description
We help the world see new possibilities and inspire change for better tomorrows. Our analytic solutions bridge content, data, and analytics to help business, people, and society become stronger, more resilient, and sustainable.
Job Description
Working as part of a team, the analyst will leverage various sources of data to classify and assess the security program and associated practices of Verisk Analytics suppliers, highlight risks and control gaps associated with the supplier's security program, categorize the potential risks based on severity, and identify potential mitigation strategies. The position is also responsible for translating the results of the analysis into business consumable format and delivering those results to business, legal, and procurement teams to guide risk decisions.
Additionally, the analyst will be responsible for identifying and tracking continuous monitoring activities to ensure the risks associated with active suppliers has not changed or exceeded risk tolerance thresholds.
The Analyst will also participate in cross-functional teams to address information security policy/risk or compliance issues. Analyst is expected to determine best practices, suggest how to improve current practices, and monitor those practices.
Key Responsibilities (include but are not limited to the following):
- Conducts information security assessments of suppliers (third party vendors and cloud services) including advising management on how to mitigate any identified risks
- Support the evolution and continuous improvement of vendor risk assessment processes including the development and maintenance of procedures, artifacts, and metrics to be used in the assessment of suppliers
- Keeps abreast of the latest security, privacy, and regulatory concerns and best practices impacting third party risk management
- Advises business on any changes requested by third parties to security and privacy provisions of our contracts
- Performs third party compliance risk tracking, trending, analysis, and executive reporting
- Responsible for information security preparedness, policies, practices, and identifying and mitigating information security risks resulting from third party applications, systems, and infrastructure
- Advises procurement and project teams on vendor assessment requirements and performs vendor risk assessments for new vendors or services
- Analyzes, designs, and implements business processes and requirements to ensure compliance with security policies and procedures
- Provides consultation and facilitation support services to Verisk in information security matters, compliance with the security policy, privacy, and other control mechanisms used by Verisk
- Performs complex analysis of major business issues and proactively searches for and recommends sustainable solutions utilizing established methodology and tools within information security areas
- Leads process improvement and solution discussions and presents outcomes in written and verbal format to senior management within information security areas
- Participates in cross-functional team initiatives and projects
Qualifications
Education and Experience:
• Bachelor's Degree in Computer Science, Information Systems, or other related field, or equivalent combination of work experience and education
• 3 to 5 years of relevant work experience (ex. information security, risk management and compliance)
• Industry recognized certifications within the domains of information security and privacy (e.g., CISSP, GIAC, CISM, CISA, CIPP, CTPRP, CCSP, etc.) considered a plus but not a requirement
Knowledge and Skills:
• Detailed knowledge applying risk management frameworks such as NIST, FISMA, or ISO 27000
• Subject matter expertise in SSAE 16, SOC 2, Shared Assessments, FedRAMP, and other vender risk assessment methodologies
• Comprehensive knowledge of third party lifecycle management and vendor risk management methodologies, including associated regulatory and industry guidance
• Broad knowledge of information security and privacy fundamentals
• Excellent oral and written communication, ability to convey technical and security related concepts to people at all levels of the organization
• Working knowledge of Governance, Risk, and Compliance (GRC) and IT Vendor Risk Management tools
• Proficient in the design and implementation of effective information security controls
• Ability to create new processes to improve security and compliance with minimal oversight
• Strong organizational and prioritization skills to handle multiple priorities
• Advanced analytical , problem solving, design, and implementation skills to facilitate resolution of technical compliance issues and support maintenance of an effective controls environment
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s