Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. Third Party Cybersecurity GRC Analyst

Elevance Health

Anticipated End Date:
2026-06-12

Position Title:
Sr. Third Party Cybersecurity GRC Analyst

Job Description:

Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst )

Information Security Risk Management

Hybrid 1: This role requires associates to be in-office 1 - 2 days per week in the Indianaplis, IN or Atlanta, GA office, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace.
  • Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.
The Security Analyst Sr. is responsible for independently assessing, documenting, and monitoring cybersecurity risks associated with third-party vendors, service providers, and business partners. This role evaluates vendor security controls, reviews assurance evidence, identifies control gaps, supports remediation and risk acceptance decisions, and provides subject matter expertise throughout the vendor lifecycle.

How you will make an impact:
  • Support internal and external audit and compliance activities, including HIPAA, HITRUST, NIST, PCI DSS, SOC 2, and other healthcare or cybersecurity-related assessments.
  • Lead cybersecurity risk assessments and due diligence reviews for third-party vendors, service providers, SaaS platforms, cloud providers, and other external business partners, including high-risk and critical vendors.
  • Evaluate vendor security documentation, including SOC reports, ISO certifications, HITRUST certifications, penetration test summaries, security questionnaires, policies, data flow diagrams, and remediation evidence.
  • Communicate directly with vendors to clarify questionnaire responses, request supporting evidence, validate remediation status, and coordinate risk mitigation activities.
  • Provides trouble resolution on complex problems and leads implementations for system and network security technologies.
  • Develops testing plans to ensure quality of implementation; coordinates and prepares the reporting of data security events and incidents; provides system and network architecture support for information and network security technologies
  • Provides technical support to business and technology associates in risk assessments and implementation of appropriate information security procedures, standards and technologies
  • Represents major upgrades and reconfigurations in change control
  • Design & analyze mix of vendor services meeting business and information security requirements
  • Determine and perform complex configuration changes to meet business and information security requirements
  • Serve as the technical escalation for results of preventative maintenance routines
  • Participate in metrics development, trend analysis, quality reviews, and program maturity initiatives to strengthen Elevance Health's third-party cybersecurity risk management program.
  • Represents infrastructure security support in significant projects and performs the most complex operations and administration tasks
  • Respond to level 3 & 4 change and problem requests without supervision
  • Lead level 1 & 2 incident recoveries and root cause analysis.
Minimum Requirements:
  • Requires a bachelor's degree or equivalent combination of education and experience that would provide the knowledge to perform such work.
  • Experience must include a minimum of 3 years experience in a support & operations or design & engineering role in any of the following areas: access management or network security technologies, servers, networks, Network communications, telecommunications, operating systems, middleware, disaster recovery, collaboration technologies, hardware/software support or other infrastructure services role; or any combination of education and experience, which would provide an equivalent background.
  • Requires experience providing top-tier support for 3 or more of the information security technology areas: 1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) Security Architecture and Design, 11) Telecommunications and Network Security.
Preferred Skills, Capabilties, and Experiences
  • Technical security certifications (e.g. Systems Security Certified Practitioner) strongly preferred. BA/BS degree in Information System and Computer Science or related field of study strongly preferred.
  • 3-5+ years of experience in cybersecurity, third-party risk management, IT risk, GRC, IT audit, regulatory compliance, vendor risk management, or a related field.
  • Familiarity with common cybersecurity frameworks, standards, and assurance reports, such as NIST CSF, NIST SP 800-53, NIST SP 800-161, ISO 27001/27002, SOC 2, CIS Controls, Shared Assessments SIG, CSA CAIQ, or CSA CCM.
  • Experience with ServiceNow GRC/IRM, Vendor Security Risk Management, or similar third-party risk management workflows.
  • Experience performing third-party cybersecurity assessments in healthcare, insurance, financial services, or another regulated industry.
  • Familiarity with HIPAA, HITRUST, NIST, PCI DSS, SOC 2, ISO 27001, cloud security, and privacy/data protection control expectations.
  • Experience reviewing SOC 2 Type II reports, ISO 27001 certificates, HITRUST reports, PCI Attestations of Compliance, penetration test summaries, vendor security questionnaires, data flow diagrams, and technical remediation evidence.
  • Relevant certification such as CISA, CRISC, CISSP, CISM, Security+, CCSK, CCSP, ISO 27001 Lead Auditor/Implementer, AWS Certified Cloud Practitioner, or PCI DSS-related experience

Job Level:
Non-Management Exempt

Workshift:

Job Family:
IFT > IT Security & Compliance

Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.

Who We Are

Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.

How We Work

At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.

We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.

Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.

The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.

Elevance Health is an Equal Employment Opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws. Applicants who require accommodation to participate in the job application process should submit the following form: Accessibility Accommodation Request Form and a member of the team will be in contact. Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws, including, but not limited to, the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act.

Prospective employees required to be screened under Florida law should review the education and awareness resources at HB531 | Florida Agency for Health Care Administration.

NOTE: Workday keeps job postings active through 11:59:59 PM on the day before the listed end date. Example: If the end date is 3/13, the posting will automatically come down on 3/12 at 11:59:59 PM. In other words - the job is posted until 3/13, not through 3/13.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Sr. Third Party Cybersecurity GRC Analyst in Atlanta, GA vacancy
  • Gilder Search Group is looking for a Sr. GRC Analyst focusing on Third-Party & Human Risk Management in Atlanta, Georgia. This role involves risk analysis, compliance assessments, vendor management, and developing security awareness training. The ideal candidate has 6-8... 
    Senior

    Gilder Search Group

    Atlanta, GA
    1 day ago
  •  ...what business risk that introduces. The analyst also drives process improvements,...  ...focusing on security risks introduced by third-party suppliers, SaaS platforms, and publicly...  ...training Eight years of experience in Cybersecurity or related work Broad knowledge of general... 
    Senior
    Work experience placement
    Work at office

    SunTrust Investment Services, Inc.

    Atlanta, GA
    13 hours ago
  •  ...what business risk that introduces. The analyst also drives process improvements,...  ...focusing on security risks introduced by third‑party suppliers, SaaS platforms, and publicly...  ...demonstrated progressive experience in Cybersecurity, with emphasis on data loss prevention,... 
    Senior
    Full time
    Part time
    Work experience placement
    Work at office

    Cooper Lighting Solutions

    Atlanta, GA
    13 hours ago
  •  ...Sr. GRC Analyst, Third-Party & Human Risk Management Clayco is a full-service, turnkey real estate development, master planning, architecture...  ...) Plans, coordinates, and executes activities for Cybersecurity month Partners with Employee Relations, Legal, and Marketing... 
    Senior
    For contractors
    Immediate start
    Flexible hours

    Clayco

    Atlanta, GA
    18 days ago
  •  ...Solutions is seeking a Technical Risk Assessment Analyst in Atlanta, GA. This on-site role involves evaluating risks from third-party suppliers and managing vendor connectivity...  ...a Bachelor's degree and over 7 years in Cybersecurity, focusing on risk management and threat... 
    Senior

    Cooper Lighting Solutions

    Atlanta, GA
    13 hours ago
  •  ...J Cybersecurity & GRC Analyst We are CirrusLabs. Our vision is to become the world's most sought-after niche digital transformation company...  ...Archer Supporting modules like: IT & Security Risk Third-Party Risk Audit Management Regulatory Compliance ~... 

    CirrusLabs

    Atlanta, GA
    12 days ago
  • $90.78k

     ...The Sr. Analyst - Supply Chain Risk Management (SCRM) Analyst supports...  ..., Maximus Federal, and third-party relationships meet U.S. federal...  ...g., performance, financial, cybersecurity, and geopolitical indicators...  ...889). ~ Experience using GRC/TPRM tooling to manage supplier... 
    Senior
    Contract work
    For subcontractor
    Work at office

    MAXIMUS

    Atlanta, GA
    3 days ago
  • Sr Compensation AnalystSkip to main contentWe and third parties use cookies and similar technologies on this website to improve your online experience, analyse our...  ...to manage your cookie settings.#Sr Compensation Analyst page is loaded## Sr Compensation AnalystApplylocations... 
    Senior
    Full time
    Part time
    Work at office
    Flexible hours

    Invesco Real Estate

    Atlanta, GA
    13 hours ago
  • $50k - $80k

     ...Analytics group is looking for a new Real Estate Valuation Senior Analyst to join our team. This is a hybrid model position and will be...  ...calls, drafting engagement letters between clients and third‑party appraisers. Appraisal: Analysts learn the process and why we... 
    Senior
    Work at office
    Local area
    Remote work
    Flexible hours

    Altus Group

    Atlanta, GA
    2 days ago
  • $190.9k - $254.6k

    Finance Senior Manager - Third Party Risk Strategy Job ID: 108735 Atlanta Connecticut - Darien Denver London Miramar...  ..., and relevant regulatory guidance) ~ Experience with TPRM/GRC platforms and driving digital enablement, including workflow design... 
    Senior
    Hourly pay
    Apprenticeship
    Work at office

    McKinsey & Company

    Atlanta, GA
    1 day ago
  • $76.2k - $151k

     ...not accept unsolicited candidates, referrals or resumes from any staffing agency, recruiting service, sourcing entity or any other third-party paid service at any time. Any referrals, resumes or candidates submitted to Crowe, or any employee or owner of Crowe without a... 
    Senior
    Work at office
    Local area
    Worldwide
    Flexible hours

    Crowe

    Atlanta, GA
    3 days ago
  • $140.6k - $186.36k

     ...future generations. Role Summary The Cybersecurity Analyst - Risk Management is a mid-career...  ...team and partners closely with the Cyber Third-Party Risk Management (TPRM) lead, security...  ...and risk management tooling, including GRC, IRM, or dedicated risk platforms. ~... 
    Full time
    Contract work
    Temporary work
    Part time
    Local area
    Shift work

    Rivian

    Atlanta, GA
    2 days ago
  • $104k - $165k

     ...Come join a #1 team and do some good! Responsibilities The IT GRC Analyst will work on a team of certified Payment Card Industry...  ...identified compliance issues with business partner, stakeholders and third-party service providers. Intermediate knowledge of PCI DSS... 
    H1b
    Work at office
    Immediate start
    Work from home

    State Farm

    Atlanta, GA
    3 days ago
  • $100k - $110k

     ...Job Description Job Description Mallory Alexander International Logistics, a global third-party logistics (3PL) provider, is seeking a Logistics Professional to join our growing team. We are looking for an innovative, analytical teammate, a Global Trade Compliance... 
    Work at office

    Mallory Alexander International Logistics

    Atlanta, GA
    6 days ago
  • Neier Inc. is seeking a Senior GRC Analyst based in Atlanta, GA. The role involves working with cutting-edge GRC technologies in the banking sector, contributing to compliance and risk management strategies. The ideal candidate has over 5 years of experience in GRC within... 
    Senior
    Long term contract

    Neier Inc.

    Atlanta, GA
    3 days ago
  • $76.4k - $138.6k

     ...and build client trust. Opportunity As an Offensive Security Analyst on the Vulnerability Management team, you will play a supporting...  ...will include aiding in the assessment and validation of third‑party risk assessments and ensuring that EY’s security standards are... 
    Summer holiday
    Flexible hours

    EY

    Atlanta, GA
    2 days ago
  •  ...6-12 Position Title: Cybersecurity ServiceNow Application Senior...  ...The Information Security Sr. Advisor is responsible for...  ...cybersecurity risk, compliance, third-party risk, and PCI assessment processes...  ...application development, GRC/IRM systems, IT risk management... 
    Senior
    Temporary work
    Work at office
    Local area
    2 days per week
    1 day per week

    Elevance Health

    Atlanta, GA
    2 days ago
  • $98k - $120.7k

     ...allow our clients to thrive. What You'll Do As a Senior Analyst - Cyber Security Incident Response (CS3) at BCG, you will be a...  ...What You'll Bring Bachelor's degree (or equivalent) in Cybersecurity, Computer Science, Information Security, or related field Minimum... 
    Senior
    Work at office
    Local area
    Shift work

    Boston Consulting Group

    Atlanta, GA
    4 days ago
  • Senior GRC Analyst - QTechUS Location: Atlanta, GA (Onsite) | Type: W2 Contract | Industry: Banking & Financial Services About QTechUS: Leading provider of innovative IT solutions for the banking and financial services sector, delivering cutting‑edge GRC and compliance... 
    Senior
    Long term contract
    Contract work
    Local area
    Immediate start

    Neier Inc.

    Atlanta, GA
    3 days ago
  •  ...Senior Analyst, Cybersecurity GRC, Atlanta, GA The Senior Analyst, Cybersecurity GRC will administer the completion of compliance-related...  ...for managed systems and applications, as well as support Third Party Risk Management (TPRM) and Governance and Risk functions... 
    Senior
    Full time
    Work experience placement

    NextStep

    Atlanta, GA
    7 hours ago
  • $75.75k - $110k

    Inside Higher Ed is seeking a Cybersecurity Analyst to protect their information systems and data from cyber threats. The role will involve monitoring security incidents, conducting risk assessments, and implementing various security measures to ensure compliance. The ideal... 
    Senior
    Full time

    Inside Higher Ed

    Atlanta, GA
    13 hours ago
  • $123.3k - $150.6k

     ...risk-based IT audits across areas such as cybersecurity, infrastructure, enterprise systems, and...  ...with SAP IT general controls, GRC tools, and ERP environments. ~ Working...  ...COBIT, ISO 27001, and cybersecurity and third-party risk concepts. ~ Strong project management... 
    Full time
    Worldwide
    Flexible hours

    Dolby

    Atlanta, GA
    2 days ago
  • $140.8k - $186.5k

     ...remediation is owned and tracked. Partner with Cybersecurity, Incident Response, and IT Operations to...  ..., runbooks, and architectures. Third-Party & Platform Resilience Lead...  ...exposure to cybersecurity, IT risk, or GRC preferred. ~ Strong understanding of IT... 
    Full time
    Contract work
    Temporary work
    Part time
    Local area
    Shift work

    Rivian

    Atlanta, GA
    2 days ago
  • Identity And Access Management Lead We are seeking an experienced Identity and Access Management (IAM) Lead to drive internal IAM initiatives with a strong emphasis on execution, role engineering, access governance and cross-functional collaboration. This role will ...
    Senior
    Work experience placement

    SunTrust Investment Services, Inc.

    Atlanta, GA
    6 days ago
  •  ...Our Client is a diversified logistics service provider specialized in Truck Brokerage, Ocean & Air Freight Management Services, Third Party Logistics, International Freight Forwarding, and Customs House Brokerage for importers and exporters in the United States including... 
    Senior

    The Monson Group

    Atlanta, GA
    13 hours ago
  • $74.1k - $147.8k

     ...intelligent automation systems with AI agents and autonomous workflows, including data model design, connector configuration, and third-party service integration ~ History of evaluating and selecting optimal low-code platforms for specific use cases, based on technical... 
    Senior
    Local area
    Remote work
    Worldwide
    Flexible hours

    Crowe

    Atlanta, GA
    2 days ago
  • $60k - $80k

     ...US 20 days ago Requisition ID: 1347 Salary Range: $60,000.00 To $80,000.00 Annually Tellworks Logistics is a rapidly growing third-party logistics company recognized for its speed, flexibility, and hands‑on operational model. We are seeking a Compliance Officer to lead... 
    Immediate start

    Tellworks-Logistics

    Atlanta, GA
    3 days ago
  •  ...of the Universal team! Logistics Insight Corporation (LINC), a subsidiary of Universal Logistics Holdings, Inc., is a leading third party logistics provider (3PL) that offers a broad scope of services throughout the entire supply chain. LINC's experienced management... 
    Senior
    Work at office
    Immediate start
    Shift work

    Universal Logistics Holdings

    Conley, GA
    4 days ago
  •  ...Helpdesk Analyst Provide technical assistance to computer users. Answer questions and resolve computer problems for users in person...  ...mail, and operating systems. Coordinate and work with third party support vendors in providing assistance to computer users for... 
    Local area

    TriOptus LLC

    Atlanta, GA
    5 days ago
  •  ...Job Title: Systems Analyst Job Location: Atlanta, GA Job Duration: 7-8 Months (possibility of extension) Job Summary:...  ...electronic mail, and operating systems. Coordinate and work with third party support vendors in providing assistance to computer users for... 

    Integrated Resources

    Atlanta, GA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. Third Party Cybersecurity GRC Analyst. Be the first to apply!