We are seeking a Security Analyst with a focus on supply chain or third-party risk management to join the team. The Security Analyst will assist in managing third party risk in accordance with the Third-Party Risk Management Policy and Third-Party Security Standard, primarily in identification and analysis of risks and proposing risk treatments appropriate to the risk severity and overarching business objectives.
RESPONSIBILITIES
- Evaluating evidence such as assessments, reports, questionnaires, etc.
- Identifying and proposing risk treatment methods that mitigate risk while facilitating the overarching business objective
- Writing assessment reports containing risk-based and context-specific evaluations and
- Other duties as assigned
Security Analyst must have the following knowledge, skills and abilities:
- Excellent communication skills (verbal and written)
- Fluency in English and Spanish
- Strong analytical skills
- Ability to understand use cases and business objectives
- Ability to communicate with diverse stakeholders including business and technical leaders
- Experience evaluating risks and writing risk statements
- Familiarity with common productivity tools including Microsoft Office365 and Jira
- Familiarity with security industry frameworks (NIST CSF, ISO 27001, etc.)
- Familiarity with regulatory requirements and compliance reporting/audits (AICPA reports such as SOC 1/2/3, Federal Trade Commissions Safeguards Rule, PCI-DSS v4.0, etc.)
- Understanding of security tools, techniques, and best practices including asset preservation, asset configuration, data protection at rest, data protection in transit, physical security, secure development, and continuity of operations
- Ability to adapt to a fast-paced high-volume environment
- High attention to detail and strong organizational skills
- Willingness and ability to learn new skills and methodologies
REQUIREMENTS
- Bachelor’s Degree in related field
- 3-5 combined years of experience in Technology and/or Security Governance, Risk, and Compliance
- Security industry certification (CompTIA, SANS, ISACA, ISC2, Microsoft, AWS, etc.)
#LI-REMOTE
#LI-GK1