Information Security Analyst (Vendor)

at  Vivo

San Mateo, California, USA -

Start DateExpiry DateSalaryPosted OnExperienceSkillsTelecommuteSponsor Visa
Immediate08 Nov, 2024Not Specified10 Aug, 20246 year(s) or aboveInformation Security Standards,Thinking Skills,Information Systems,Ml,Assessment Methodologies,Computer Science,Communication SkillsNoNo
Add to Wishlist Apply All Jobs
Required Visa Status:
CitizenGC
US CitizenStudent Visa
H1BCPT
OPTH4 Spouse of H1B
GC Green Card
Employment Type:
Full TimePart Time
PermanentIndependent - 1099
Contract – W2C2H Independent
C2H W2Contract – Corp 2 Corp
Contract to Hire – Corp 2 Corp

Description:

Our client in the autonomous driving vehicle space is looking for an Information Security Governance Third-Party Risk Analyst who will assess third-party risk as part of vendor evaluations. Additionally, the analyst will conduct periodic assessments based on the sensitivity of the vendor, data in scope, or prior security incidents. This position requires a strong understanding of information security frameworks, risk management practices, and excellent analytical skills.

Responsibilities:

  • Perform comprehensive third-party risk assessments at the point of engagement.
  • Evaluate vendors’ information security controls, operational practices, and data privacy measures.
  • Conduct periodic assessments of third-party vendors based on the sensitivity of the vendor.
  • Assess the data involved or any prior security incidents.
  • Ensure continuous monitoring and reassessment of vendor risk profiles.
  • Identify, analyze, and prioritize risks associated with third-party vendors.
  • Work with vendors and internal stakeholders to develop and implement risk mitigation strategies.
  • Ensure compliance with relevant information security standards and regulatory requirements (e.g., NIST CSF, GDPR, ISO/IEC 27001).
  • Provide clear and high-quality risk reports with guidance and recommendations to senior business owners.
  • Develop and maintain strong working relationships with business areas, IT teams, and vendors.
  • Advise on security requirements and best practices.
  • Perform data analyses and generate reports on third-party risk.
  • Track and communicate overall program performance.
  • Ensure timely completion of program milestones.
  • Support contractual reviews for new and existing suppliers.
  • Ensure security requirements are met in supplier contracts.
  • Participate in the development and optimization of vendor risk management processes and procedures.

Requirements:

  • 6+ years of experience in conducting security control assessments or audits.
  • 2+ years of experience in developing or managing security awareness programs.
  • 6+ years experience with information security standards and privacy laws (e.g., ISO 27001, NIST, HIPAA).
  • Strong knowledge of GRC frameworks and tools.
  • Proficiency in third party risk assessment methodologies and tools.
  • Conceptual understanding of the following technologies:
  • LLMs (Large Language Models), AI (artificial intelligence), ML (machine learning)
  • Excellent analytical and critical thinking skills.
  • Strong written and verbal communication skills.
  • Ability to work collaboratively in a dynamic, fast-paced environment.

Education:

  • Bachelor s degree in Computer Science, Information Systems, Business, or a related field, or equivalent relevant experience.

Certifications (nice to have):

  • Professional certifications such as CISA, CISM, CRISC, CISSP.

Responsibilities:

  • Perform comprehensive third-party risk assessments at the point of engagement.
  • Evaluate vendors’ information security controls, operational practices, and data privacy measures.
  • Conduct periodic assessments of third-party vendors based on the sensitivity of the vendor.
  • Assess the data involved or any prior security incidents.
  • Ensure continuous monitoring and reassessment of vendor risk profiles.
  • Identify, analyze, and prioritize risks associated with third-party vendors.
  • Work with vendors and internal stakeholders to develop and implement risk mitigation strategies.
  • Ensure compliance with relevant information security standards and regulatory requirements (e.g., NIST CSF, GDPR, ISO/IEC 27001).
  • Provide clear and high-quality risk reports with guidance and recommendations to senior business owners.
  • Develop and maintain strong working relationships with business areas, IT teams, and vendors.
  • Advise on security requirements and best practices.
  • Perform data analyses and generate reports on third-party risk.
  • Track and communicate overall program performance.
  • Ensure timely completion of program milestones.
  • Support contractual reviews for new and existing suppliers.
  • Ensure security requirements are met in supplier contracts.
  • Participate in the development and optimization of vendor risk management processes and procedures


REQUIREMENT SUMMARY

Min:6.0Max:11.0 year(s)

Information Technology/IT

IT Software - Network Administration / Security

Systems Administration

Graduate

Computer Science, Business, Information Systems

Proficient

1

San Mateo, CA, USA