





Specialized mid-level role, metro location, and popular senior analyst title create moderate applicant competition.
Role requires regulated-industry and vendor-security experience, making backgrounds less transferable across unrelated industries.
Explicit 6+ years requirement, domain experience and security certifications make filtering strict.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Manage and assess risks related to third-party technology vendors, ensuring compliance and security throughout partnership lifecycle.
Conduct risk assessments, due diligence, ongoing monitoring, risk scoring, and incident management for external technology services.
Support policy development, stakeholder engagement, audit preparation, and alignment with Group Cyber Strategy under Group CISO guidance.
Bachelor’s degree in IT, Cybersecurity, Computer Science, Risk Management, or related field.
6+ years experience in technology risk management, third-party security assessments, or audit/assurance roles, preferably in regulated industries.
Knowledge of IT infrastructure, cloud, SaaS, data protection, and relevant regulations (GDPR, HIPAA, SOX, PCI DSS, NIST, ISO 27001).
Professional certifications (e.g., CISA, CISM, CRISC, CISSP) are highly desirable but not mandatory.
Experienced in third-party technology risk in regulated sectors—financial services, healthcare, or similar.
Strong analytical skills with capability to manage complex risk assessments and produce actionable reports for senior stakeholders.
Able to collaborate cross-functionally and support cyber strategy execution with good communication and organizational skills.