





Tier-1 brand and metro location, but niche senior cybersecurity vendor-risk role limits candidate pool.
Role requires deep third-party cyber risk and regulatory knowledge, so background fit sensitivity is high.
Explicit 10-year requirement plus preferred security certifications and domain expertise creates high shortlisting strictness.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Conduct cyber/information security assessments of third-party service providers using State Street’s risk management framework.
Review and analyze third-party security certification artifacts (e.g., SOC2, SIG, NIST, ISO 27001/2) to identify risks.
Document assessment results and provide expert recommendations to address identified security issues.
Minimum 10 years of experience in Cyber/Information Security, Third Party Cyber Security Assessment, or Cyber Security Assessments.
Knowledge of security and risk frameworks and regulations such as ISO 27001/27002, NIST, FRB/OCC Third Party Risk Management Guidelines, FFIEC Security Handbook, GDPR, DORA.
Bachelor’s or Master’s degree preferred in Cybersecurity, Law, Privacy, Enterprise or Operational Risk Management.
Ability to work strictly onsite.
Strong subject matter expertise in third-party information security risk management and assessment.
Experience communicating complex cyber security risks and technical details effectively to diverse technical and non-technical stakeholders.
Demonstrated capability to analyze and unwind complex cyber/information security issues with a well-rounded security and risk management background.