Senior Security Risk Management Analyst

Remote • Posted 9 hours ago • Updated 9 hours ago
Contract W2
6 Months
No Travel Required
Remote
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🎯 Assessing qualifications...

Job Details

Skills

  • ISO 27017 & 18)
  • FedRAMP
  • SOC 2 Trust Services Criteria
  • PCI DSS
  • NIST CSF.

Summary

Greetings from Aziro.
 
 
Job Title:          Senior Security Risk Management Analyst

Jib Id                26-00300

Location:         Remote

 
 

Responsibilities:

Lead and conduct comprehensive risk assessments of new and existing third-party vendors and service providers, focusing on cybersecurity, and regulatory compliance.

Evaluate third-party security questionnaires, audit reports (e.g., SOC 2, ISO 27001), and risk documentation.

Coordinate with vendors to request and verify security controls, remediation plans, and ongoing compliance.

Oversee facilitation of risk remediation efforts agreed upon with suppliers, ensuring timely resolution.

Collaborate during supplier contract development, reviewing deviations from security requirements and offering subject matter expertise on risk remediation.

Classify vendors according to risk tiers and maintain a comprehensive database of vendor risk profiles.

Participate in continuous security monitoring of existing suppliers to track changing risk profiles.

Partner with Procurement, Legal, Privacy, and InfoSec teams to improve supplier security management processes.

Identify opportunities to automate parts of the assessment process, thereby reducing manual work and enhancing efficiency.

Keep abreast of emerging risks, industry standards, and regulatory requirements affecting third-party vendors.

Contribute to broader cybersecurity risk management initiatives, including identifying, assessing, and tracking information security risks beyond the third-party domain.

Provide guidance and knowledge transfer to team members, supporting a collaborative team environment.

 

Preferred Qualifications:

Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Risk Management, or a related field.

6-8 years of professional experience in third-party risk assessment within cybersecurity or information risk management.

Understanding of relevant information security frameworks, including related regulatory compliance requirements, such as ISO 27001/2 (including ISO 27017 & 18), FedRAMP, SOC 2 Trust Services Criteria, PCI DSS, NIST CSF.

Solid understanding of risk assessment methodologies and best practices.

Ability to synthesize and communicate complex risk findings to both technical and non-technical audiences.

Detail-oriented, process-driven, and capable of managing multiple vendor assessments concurrently.

Experience with tools such as Coupa, OneTrust, JIRA and Coverbase is a plus.

Professional certifications in Information Security or Risk Management (e.g. CISA, CISM, CISSP, CRISC) is a plus.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10426227
  • Position Id: 9007343
  • Posted 9 hours ago

Company Info

About Aziro Technologies LLC

Aziro (formerly MSys Technologies and pronounced as "Ah-zee-roh") is an AI-native product engineering company driving innovation-led transformation for global enterprises, high-growth ISVs, and AI-first pioneers.

Contact the job poster
RR

Ragavendrar Raj

Recruiter @ Aziro Technologies LLC
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Yesterday

Easy Apply

Contract

Depends on Experience

Remote

Yesterday

Easy Apply

Contract

$70 - $80

Search all similar jobs