Senior Analyst, Third-Party Security
$160k - $190kSimpson Thacher & Bartlett LLP
Senior Analyst, Third-Party Security The Senior Analyst, Third‑Party Security will play a key role in supporting the Third‑Party Security Team in both the development and execution of the firm’s Third‑party Security Program. This includes identifying, assessing, monitoring, and mitigating risks associated with vendors, suppliers, and service providers across the globe as well as supporting strategic program initiatives. The ideal candidate is an experienced information security or IT risk management professional with a background in third‑party assessment execution, IT Risk management or IT Audit. The candidate should possess strong analytical skills, attention to detail, and the ability to collaborate cross‑functionally with legal, Vendor Management Office, and IT security teams. Strong communication and interpersonal skills are required to effectively engage with third parties and program stakeholders. Responsibilities Conduct information security due diligence including secure by design reviews, during vendor onboarding, at renewal, and periodic review cycles. Apply a risk‑based approach to third party security assessments, including documenting compensating controls and risks acceptances where appropriate. Evaluate third‑party architectures, including network connectivity (VPN, reverse proxy), data flows, encryption models, and access controls. Assess risks related to cloud environments (AWS/Azure/GCP), SaaS platforms, and API integrations. Analyze external risk intelligence sources (e.g., BitSight, SecurityScorecard) and correlate with internal findings. Review and challenge secure design, identity/access models (SSO, OAuth, SCIM), and data protection mechanisms. Enhance and maintain a comprehensive vendor inventory, including vendor profiling and inherent risk determination. Enhance and maintain a third‑party risk register and track mitigation efforts for identified security risks. Develop and implement strategies to mitigate identified risks, working closely with third parties and internal stakeholders to address security gaps. Support a continuous monitoring program to assess third‑party security posture and follow up on identified vulnerabilities and security risks. Partner with general counsel and vendor management to incorporate information security requirements into third‑party contracts. Work with internal security teams to investigate and respond to third‑party related security incidents. Support and enhance escalation procedures and remediation requirements related to third‑party security breaches. Prepare and present third‑party risk metrics, dashboards, trends, and highlighted risks to senior management and IT leadership. Contribute to the continuous improvement and scalability of the Firm’s third‑party security risk management program. Partner with the Third Party Security Senior Manager to build and enhance strategic objectives of the program. Education Bachelor’s degree or related experience required. Skills & Experience 10+ years of progressive experience in information security, third‑party risk management, IT risk, or cybersecurity assurance, with at least 3 years focused on third‑party risk management. Strong understanding of information security controls and frameworks (ISO 27001/27002, NIST CSF, CIS Controls, etc.). Proficient understanding of third‑party security domains, including data protection, access controls, incident response and cloud security. Proven ability to perform third‑party security risk assessments by reviewing security questionnaires, audit reports, policies and penetration test results to identify control gaps, formulate follow‑up inquiries, and document remediation requirements. Deep knowledge of technology supplier ecosystems (software, cloud, IT labor, and infrastructure) and associated risk dynamics. Experience producing clear risk summaries, remediation recommendations, and executive level reporting. Familiarity with information security and data protections requirements in third‑party contracts. Excellent communication skills: clear, structured, persuasive with the ability to educate and inspire teams around risk and performance ownership. Proven ability to influence stakeholders without direct authority. Ability to work independently and collaboratively in a team environment. Demonstrated ability to handle sensitive and/or confidential material and information with suitable discretion. Preferred Established track record in building and executing vendor risk frameworks, risk mitigation strategies, and regulatory‑compliant vendor governance programs. Proven ability to articulate technical security considerations to non‑technical stakeholders. Familiarity with information security considerations for vendors leveraging AI or providing AI‑centric solutions. CISSP, CRISC, CISM, CISA, ISO 27001 Lead Auditor/Implementor certification. Salary NY Only: The estimated base salary range for this position is $160,000 to $190,000 at the time of posting. The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible. Simpson Thacher will not sponsor applicants for work visas for this position. Equal Opportunity Simpson Thacher & Bartlett is committed to a collegial work environment in which all individuals are treated with respect and dignity. The Firm prohibits discrimination or harassment based upon race, color, religion, gender, gender identity or expression, age, national origin, citizenship status, disability, marital or partnership status, sexual orientation, veteran’s status or any other legally protected status. This Policy pertains to every aspect of an individual’s relationship with the Firm, including but not limited to recruitment, hiring, compensation, benefits, training and development, promotion, transfer, discipline, termination, and all other privileges, terms and conditions of employment. #J-18808-Ljbffr Simpson Thacher & Bartlett LLP
- Radar is hiring a Senior GRC Analyst in New York City to enhance security and compliance programs, focusing on third-party risk and SaaS governance. You will work with various teams to evaluate vendors, shape security strategies, and improve workflows, reporting to the...Senior
$80.5k - $159.3k
...career where you can help shape the future of our industry.Job Description:Third Party Senior StaffJob Summary:The position will be primarily responsible for assessing the information security posture of key clients’ third parties and coordinating the overall execution...SeniorLocal areaWorldwide- ...Senior Analyst, Cybersecurity GRC, New York, NY The Senior Analyst, Cybersecurity GRC will... ...compliance-related client requests to assess security policies and procedures. The Senior... ...and applications, as well as support Third Party Risk Management (TPRM) and Governance and...SeniorWork experience placement
$105k - $120k
United Nations Federal Credit Union seeks a skilled contributor to enhance its Third-Party Risk Management (TPRM) program. The role involves assessing and mitigating risks, ensuring compliance with regulations, and collaborating with various internal teams to support procurement...SeniorWork at office$105k - $120k
...maturation of the Credit Union’s Third-Party Risk Management (TPRM)... ...geographic location. • Regardless of seniority or role, uphold UNFCU’s... ...Counsel, Information Security, Enterprise Risk Management,... ...designated alternate to the TPRM analyst in the vendor management...SeniorContract workWork at office- ...Radar Senior GRC Analyst Radar is the global leader in geolocation, with geofencing SDKs, maps APIs, and AI-enabled... ...a Senior GRC Analyst to help scale Radar's security and compliance programs, with a focus on third-party risk and modern SaaS governance. You'll...SeniorWork at officeRemote work
- Radar Labs, Inc. is seeking a Senior GRC Analyst to enhance their security and compliance programs with a focus on third-party risk. This role involves collaborating with multiple teams, evaluating modern SaaS and AI tools, and improving risk management workflows. The...SeniorFlexible hours
$90k - $160k
...IT RISK & CONTROL SENIOR ANALYST WHAT IS THE OPPORTUNITY? The IT Risk Senior Analyst is... ...a complex technical environment. ITRM Security Senior Analyst will conduct fit for purpose... ...for auditors, regulators and external parties. This requires routinely performing...SeniorRemote work- ...Owning Strategic Initiatives across Third Party Partner (TPP) space: Identify, scope, and... ...a consultative Thought Partner: Engage senior stakeholders as a trusted advisor, bringing... ...continue to uphold our brand promise of trust, security, and service. As part of Team Amex,...SeniorWork at officeLocal areaFlexible hours
$60.8k - $93.6k
...Senior Analyst, Paid Media - CTV (Embedded Role, Entertainment Client) This is a unique opportunity to work as an embedded team member... ...in our freelancer/temporary employee medical plan through a third-party benefits administration system once certain criteria have...SeniorTemporary workFreelanceWork at officeLocal areaFlexible hours$60.8k - $93.6k
...pay range at any time. Temporary roles may be eligible to participate in our freelancer/temporary employee medical plan through a third-party benefits administration system once certain criteria have been met. Temporary roles may also qualify for participation in our 401...SeniorTemporary workFreelanceWork at officeLocal areaFlexible hours$60.8k - $93.6k
...Senior Analyst, Programmatic (Embedded Role, Entertainment Client) This is a unique opportunity to work as an embedded team member... ...in our freelancer/temporary employee medical plan through a third-party benefits administration system once certain criteria have been...SeniorTemporary workFreelanceWork at officeLocal areaFlexible hours$90.9k - $122.7k
...grow and make your mark at Hines. Responsibilities The Senior Analyst, Sustainability Reporting, assists with organizing and... ...supporting the following business process areas or required third-party reporting frameworks: investment committee ESG project outcomes...SeniorWork at officeLocal areaRemote work1 day per week$60.8k - $93.6k
...and career development opportunities. What You'll Do: As a Senior Analyst, Programmatic, you will own the strategic planning and... ...in our freelancer/temporary employee medical plan through a third‑party benefits administration system once certain criteria have been...SeniorTemporary workFreelanceWork at officeLocal areaFlexible hours$102k - $110k
...Department Overview The New York Times is looking for a Senior Analyst to join our Enterprise Analytics Team within the Data and Insights... ...information or for payment, and will not refer you to a third party to do so. You should never send money to anyone who suggests...SeniorLocal areaFlexible hours$102k - $110k
...Department Overview The Times is looking for a creative senior data analyst who is passionate about data and eager for the opportunity... ...financial information or for payment, and will not refer you to a third party to do so. You should never send money to anyone who...SeniorLocal areaFlexible hours- Commercial real estate finance platform seeking a Senior Analyst to support HUD multifamily underwriting, analyze property-level financials... ...new construction, bridge loans, and refinancing. Review third-party reports such as appraisals, market studies, environmental reports...Senior
$102k - $110k
...worth paying for. About the Role We are looking for a Senior Data Analyst who is passionate about data and eager for the opportunity... ...financial information or for payment, and will not refer you to a third party to do so. You should never send money to anyone who...SeniorLocal areaFlexible hours- ...part of the journey, we are seeking a Senior Analyst, Embedded Data Controls to help operationalize... ...such as New Product Governance (NPG), Third-Party Lifecycle Management (TLM), Generative... ...to uphold our brand promise of trust, security, and service. As part of Team Amex,...SeniorWork at officeLocal areaFlexible hours
$110k - $125k
...Columbia University and Yale University, CertiK is a leading Web3 security company focused on securing blockchain protocols, smart... ...maintain ETL pipelines & process large datasets from APIs/databases/third-party platforms to enable real-time team analytics and automate data...SeniorFull timeContract workWork experience placementLocal areaFlexible hours- ...Cybersecurity Senior Risk Analyst 1 Labor Category - Analyst 2 Work Location: Hybrid: Work... ...feedback; Evaluate risk of third parties used by New York City agencies; Document... ...) ~ Certified Information Systems Security Professional (CISSP) ~ Certified in...SeniorWork at officeRemote workMonday to Friday
- ...Job Description Be Part Of A High-Performing Team: Join a security-focused team within a regulated financial services technology... ...governance. Define governance requirements for internal systems and third-party relationships that interact with insider risk data....Senior
$175k - $285k
...Senior/Principal Product Manager, AI New York City (Hybrid) About SecurityScorecard... ...in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and... ...,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber...SeniorTemporary workImmediate start$76.2k - $151k
...not accept unsolicited candidates, referrals or resumes from any staffing agency, recruiting service, sourcing entity or any other third-party paid service at any time. Any referrals, resumes or candidates submitted to Crowe, or any employee or owner of Crowe without a...SeniorWork at officeLocal areaWorldwideFlexible hours$150k - $175k
...A Career with Point72's Third-Party Risk Team The Third-Party Risk Management Team at Point72 is responsible for overseeing the firm... ...stakeholders, including Compliance, Legal, Information Security, and Procurement, facilitating clear communication and efficient...Work experience placement$97k - $132k
...Third Party Risk Analyst At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused... ...to ensure our programs and business operations remain secure and resilient. This role requires a blend of analytical rigor...$101k - $110k
...Mission or Department Overview NYT Wirecutter is looking for a Senior Business Analyst to lead the analytical narrative across our teams,... ...financial information or for payment, and will not refer you to a third party to do so. You should never send money to anyone who...SeniorLocal areaRemote workFlexible hoursShift work$130k - $160k
...Department Engineering Team & Role As a Senior GRC Analyst at Benepass, you will help operate and... ..., and employees. You will work across security policies, internal controls, audit... ...Risk: Support vendor security reviews, third-party risk assessments, remediation tracking...SeniorFull timeWork at officeRemote workWork from homeFlexible hours- Overview Remote Senior Governance, Risk and Compliance Analyst - Governance Remote. Come join the company that is reinventing cloud security and empowering businesses to thrive in the cloud... ...and questionnaires. Assist with third party risk management reviews,...SeniorRemote job
- ...Third-Party Risk Management Consultant We're seeking a hands-on Third-Party Risk Management (TPRM) Consultant to help execute and improve vendor risk processes within a regulated financial services environment. This role goes beyond advisory—you'll actively perform...Contract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Analyst, Third-Party Security. Be the first to apply!
- analyst asset management New York, NY
- origination analyst New York, NY
- design analyst New York, NY
- category analyst New York, NY
- junior analyst New York, NY
- crime analyst New York, NY
- law enforcement response team analyst New York, NY
- meditech analyst New York, NY
- facility analyst New York, NY
- proposal analyst New York, NY


