1,196 open roles
Third Party Risk Management (TPRM)
Job description
We are looking for a detail-oriented and strategic Information Security – Risk Analyst to support the assessment, remediation, and continuous monitoring of cyber risks posed by external vendors, partners, and service providers. This role plays a critical part in the third-party risk lifecycle, with a primary focus on driving effective risk treatment plans, collaborating with internal stakeholders and vendors to remediate control gaps and reduce exposure in the supply chain.
Key Responsibilities
- Analyze third-party security assessments to identify risk findings and determine appropriate treatment strategies (e.g., remediation, compensating controls, or acceptance).
- Collaborate with vendors, procurement, legal, and business stakeholders to document and manage risk treatment plans based on due diligence and ongoing monitoring results.
- Track and follow up on risk remediation activities, ensuring that treatment plans are executed within agreed timelines.
- Maintain a centralized register of third-party risk treatment activities and ensure all documentation is audit-ready.
- Recommend and support the implementation of compensating controls or alternative mitigation actions when direct remediation is not feasible.
- Escalate high-risk third-party issues and delays in remediation to leadership.
- Contribute to the enhancement of third-party risk management frameworks, processes, and tools, ensuring alignment with NIST CSF, ISO 27001, and regulatory requirements.
- Provide insights and reporting on risk trends, treatment status, and control effectiveness across the third-party portfolio.
- Support audit, regulatory, and internal assurance activities related to third-party cybersecurity risk.
Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related discipline.
- 3+ years of experience in IT or cybersecurity risk management, with specific experience in third-party or vendor risk.
- Strong knowledge of third-party risk management frameworks and control standards (e.g., NIST, ISO 27001, SIG, SOC 2, CSA).
- Hands-on experience reviewing third-party security assessments, risk questionnaires, and due diligence documentation.
- Familiarity with GRC or third-party risk platforms (e.g., Onspring, One. Trust, Archer, Service. Now, Prevalent, Bit. Sight, Panorays).
- Excellent communication and negotiation skills to work with internal and external stakeholders.
- Industry certifications (e.g., CRISC, CTPRP, CISA, CISSP) are a plus.
Description copied from UST's careers page. Read the full posting before you apply.
More jobs at UST
Cyberproof Strategic Alliances & Partner Director
UST· Aliso Viejo, United States of America· $120k – $180kSystemC Engineer
UST· Bangalore, IndiaLead I - Data Engineering
UST· Trivandrum, IndiaSolution Architect (Java OR Python Application Architecture & GitHub Copilot)
UST· Bangalore, India; Kochi, India; Trivandrum, India; Hyderabad, India; Pune, India; Chennai, India; Noida, India; Gurgaon, India; Coimbatore, India; Kolkata, India; Ahmedabad, IndiaMLOps Engineer
UST· Chicago, United States of America· $72k – $108k