- Company Name
- KellyMitchell Group
- Job Title
- Senior Analyst, Third Party Risk Management
- Job Description
-
**Job Title**
Senior Analyst, Third Party Risk Management
**Role Summary**
Drive the assessment, monitoring, and mitigation of third‑party risk exposure through robust vendor risk management practices. Analyze vendor security posture, coordinate remediation, and enhance processes to support enterprise risk initiatives and compliance requirements.
**Expectations**
- Consistently deliver thorough risk assessments and reports on time.
- Maintain high accuracy in documenting findings and remediation status.
- Proactively identify and propose improvements to vendor risk workflows.
- Collaborate effectively with Information Security, Legal, Procurement, Compliance, and other stakeholders to align risk activities with organizational objectives.
**Key Responsibilities**
- Conduct day‑to‑day information security and third‑party risk assessments for existing and prospective vendors.
- Review SOC reports, penetration test results, security questionnaires, and other control attestations.
- Document, organize, and track remediation activities, findings, and risk decisions.
- Collect, analyze, and report vendor assessment data to support ongoing risk monitoring and leadership oversight.
- Identify opportunities for process improvement within the Vendor Risk Management Program and assist in implementing related controls and workflows.
- Partner cross‑functionally with Information Security, Legal, Procurement, Compliance, and other stakeholders to support broader enterprise risk initiatives.
- Monitor emerging technologies and risk trends (cloud, SaaS, mobile, AI‑enabled solutions) and assess their impact on vendor risk.
- Support additional risk management activities as required by the Risk and Security teams.
**Required Skills**
- ≥4 years of experience in risk management, information security, third‑party risk, audit, or compliance.
- 4+ years of hands‑on vendor risk assessment experience within procurement or governance programs.
- Proficiency with vendor risk management or GRC tools.
- Experience reviewing SOC reports, penetration test results, security questionnaires, and control attestations.
- Understanding of industry risk or regulatory frameworks (e.g., NIST, ISO 27001, SOC 2, GDPR).
- Ability to assess operational risks across multiple lines of business, legal entities, or jurisdictions.
- Strong relationship‑building and cross‑functional collaboration skills.
- Effective written and verbal communication.
**Required Education & Certifications**
- Bachelor’s degree in Information Security, Risk Management, Business Administration, or a related field (preferred).
- Professional certifications such as CISSP, CISA, CRISC, or equivalent strongly preferred.
---