Senior Analyst, Third-Party Security
$160k - $190kSimpson Thacher
Senior Analyst, Third-Party Security
The Senior Analyst, Third-Party Security will play a key role in supporting the Third-Party Security Team in both the development and execution of the firm's Third-party Security Program. This includes identifying, assessing, monitoring, and mitigating risks associated with vendors, suppliers, and service providers across the globe as well as supporting strategic program initiatives.
The ideal candidate is an experienced information security or IT risk management professional with a background in third-party assessment execution, IT Risk management or IT Audit. The candidate should possess strong analytical skills, attention to detail, and the ability to collaborate cross-functionally with legal, Vendor Management Office, and IT security teams. Strong communication and interpersonal skills are required to effectively engage with third parties and program stakeholders.
Essential Job Duties & Responsibilities
- Conduct information security due diligence including secure by design reviews, during vendor onboarding, at renewal, and periodic review cycles.
- Apply a risk-based approach to third party security assessments, including documenting compensating controls and risks acceptances where appropriate.
- Evaluate third-party architectures, including network connectivity (VPN, reverse proxy), data flows, encryption models, and access controls.
- Assess risks related to cloud environments (AWS/Azure/GCP), SaaS platforms, and API integrations.
- Analyze external risk intelligence sources (e.g., BitSight, SecurityScorecard) and correlate with internal findings.
- Review and challenge secure design, identity/access models (SSO, OAuth, SCIM), and data protection mechanisms.
- Enhance and maintain a comprehensive vendor inventory, including vendor profiling and inherent risk determination.
- Enhance and maintain a third-party risk register and track mitigation efforts for identified security risks.
- Develop and implement strategies to mitigate identified risks, working closely with third parties and internal stakeholders to address security gaps.
- Support a continuous monitoring program to assess third-party security posture and follow up on identified vulnerabilities and security risks.
- Partner with general counsel and vendor management to incorporate information security requirements into third-party contracts.
- Work with internal security teams to investigate and respond to third-party related security incidents.
- Support and enhance escalation procedures and remediation requirements related to third-party security breaches.
- Prepare and present third-party risk metrics, dashboards, trends, and highlighted risks to senior management and IT leadership.
- Contribute to the continuous improvement and scalability of the Firm's third-party security risk management program.
- Partner with the Third Party Security Senior Manager to build and enhance strategic objectives of the program.
Education
- Bachelor's degree or related experience required
- Professional certifications, such as CISSP, CRISC, CISM, CISA, ISO 27001 Lead Auditor/Implementor.
Skills and Experience
- 10+ years of progressive experience in information security, third-party risk management, IT risk, or cybersecurity assurance, with at least 3 years focused on third party risk management.
- Strong understanding of information security controls and frameworks (ISO 27001/27002, NIST CSF, CIS Controls, etc.)
- Proficient understanding of third-party security domains, including data protection, access controls, incident response and cloud security.
- Proven ability to perform third-party security risk assessments by reviewing security questionnaires, audit reports, policies and penetration test results to identify control gaps, formulate follow-up inquiries, and document remediation requirements.
- Deep knowledge of technology supplier ecosystems (software, cloud, IT labor, and infrastructure) and associated risk dynamics.
- Experience producing clear risk summaries, remediation recommendations, and executive level reporting
- Familiarity with information security and data protections requirements in third party contracts.
- Excellent communication skills: clear, structured, and persuasive with the ability to educate and inspire teams around risk and performance ownership.
- Proven ability to influence stakeholders without direct authority.
- Ability to work independently and collaboratively in a team environment
- Demonstrated ability to handle sensitive and/or confidential material and information with suitable discretion.
- Established track record in building and executing vendor risk frameworks, risk mitigation strategies, and regulatory-compliant vendor governance programs.
- Proven ability to articulate technical security considerations to non-technical stakeholders.
- Familiarity with information security considerations for vendors leveraging AI or providing AI centric solutions.
Salary Information
NY Only: The estimated base salary range for this position is $160,000 to $190,000 at the time of posting. The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible.
Simpson Thacher will not sponsor applicants for work visas for this position.
- ...Senior Analyst, Cybersecurity GRC, New York, NY The Senior Analyst, Cybersecurity GRCwill... ...-related client requests to assess security policies and procedures. The Senior Analyst... ...and applications, as well as support Third Party Risk Management (TPRM) and Governance and...SeniorWork experience placement
$100k - $120k
...Description Develop and implement third-party risk management frameworks to ensure compliance... ...detailed reports and presentations for senior management on risk assessment findings.... ...Senior Third Party Risk Management Analyst should have: A strong understanding...SeniorPermanent employmentLocal areaFlexible hours- ...Third-Party Risk Management Senior Analyst (MRA Remediation Support) - VP Level New York City, NY or Tampa, FL (Hybrid) 6-12 Months Contract Web Cam Interview $70-$75/Hr on W2 Third Party Risk is a global, first line team within the Markets Operational Risk & Control...SeniorContract work
- ...Radar Senior GRC Analyst Radar is the global leader in geolocation, with geofencing SDKs, maps APIs, and AI-enabled... ...a Senior GRC Analyst to help scale Radar's security and compliance programs, with a focus on third-party risk and modern SaaS governance. You'll...SeniorWork at officeRemote work
$105k - $120k
...maturation of the Credit Union’s Third-Party Risk Management (TPRM)... ...What you'll do • Regardless of seniority or role, uphold UNFCU’s... ...General Counsel, Information Security, Enterprise Risk Management,... ...designated alternate to the TPRM analyst in the vendor management...SeniorContract workWork at officeLocal area$85k - $120k
...CrowdStrike Holdings, Inc. is hiring for a remote Third Party Risk Management (TPRM) Analyst to lead security assessments and manage vendor risks. The role focuses on developing TPRM policies and collaborating with various teams to optimize workflows and mitigate risks...Remote work$88k - $93k
...A leading non-profit organization seeks a Senior Specialist, Information Security, Third Party Risk to ensure compliance with security policies across all third-party engagements. Responsibilities include risk assessments of vendors, producing detailed reports, and collaborating...SeniorRemote work- ...the operational standards, technical coordination, and security hygiene for the non-Epic, 3rd-party clinical systems in the portfolio. The role requires... ...and facilitating clear cross-team communication. The analyst will also provide training support, troubleshoot issues...SeniorLocal areaFlexible hours
$90k - $160k
...IT RISK & CONTROL SENIOR ANALYST WHAT IS THE OPPORTUNITY? The IT Risk Senior Analyst is... ...a complex technical environment. ITRM Security Senior Analyst will conduct fit for purpose... ...for auditors, regulators and external parties. This requires routinely performing...SeniorRemote work- ...Owning Strategic Initiatives across Third Party Partner (TPP) space: Identify, scope, and... ...a consultative Thought Partner: Engage senior stakeholders as a trusted advisor, bringing... ...continue to uphold our brand promise of trust, security, and service. As part of Team Amex,...SeniorWork at officeLocal areaFlexible hours
$60.8k - $93.6k
...Senior Analyst, Paid Media - CTV (Embedded Role, Entertainment Client) This is a unique opportunity to work as an embedded team member... ...in our freelancer/temporary employee medical plan through a third-party benefits administration system once certain criteria have...SeniorTemporary workFreelanceWork at officeLocal areaFlexible hours$102k - $110k
...Group (DIG), you will join a large community of accomplished analysts who partner with Product, Engineering, and Design teams across... ...financial information or for payment, and will not refer you to a third party to do so. You should never send money to anyone who suggests...SeniorLocal areaFlexible hours$60.8k - $93.6k
...Senior Analyst, Programmatic (Embedded Role, Entertainment Client) Starcom is the world's first standalone media agency, a storied... ...in our freelancer/temporary employee medical plan through a third-party benefits administration system once certain criteria have been...SeniorTemporary workFreelanceWork at officeLocal areaFlexible hours$60.8k - $93.6k
...pay range at any time. Temporary roles may be eligible to participate in our freelancer/temporary employee medical plan through a third-party benefits administration system once certain criteria have been met. Temporary roles may also qualify for participation in our 401...SeniorTemporary workFreelanceWork at officeLocal areaFlexible hours$90.9k - $122.7k
...grow and make your mark at Hines. Responsibilities The Senior Analyst, Sustainability Reporting, assists with organizing and... ...supporting the following business process areas or required third-party reporting frameworks: investment committee ESG project outcomes...SeniorWork at officeLocal areaRemote work1 day per week$97k - $189k
...The Information Security Risk Team at MongoDB is the operational engine of the internal and third-party risk programs. Situated within the Assurance, Risk, and Compliance... ...open to the risks we accept. As the Senior Information Risk Analyst, you will serve as the subject matter...SeniorLocal areaRemote workWorldwideFlexible hours$102k - $110k
...Department Overview The New York Times is looking for a Senior Analyst to join our Enterprise Analytics Team within the Data and... ...financial information or for payment, and will not refer you to a third party to do so. You should never send money to anyone who suggests...SeniorLocal areaFlexible hours$102k - $110k
...s worth paying for. About the Role We are looking for a Senior Data Analyst who is passionate about data and eager for the opportunity... ...financial information or for payment, and will not refer you to a third party to do so. You should never send money to anyone who...SeniorLocal areaFlexible hours- ...part of the journey, we are seeking a Senior Analyst, Embedded Data Controls to help operationalize... ...such as New Product Governance (NPG), Third-Party Lifecycle Management (TLM), Generative... ...to uphold our brand promise of trust, security, and service. As part of Team Amex,...SeniorWork at officeLocal areaFlexible hours
$50 - $56 per hour
...An international law firm is looking for a Senior Analyst, Cyber Risk to join their security group. The Firm has more than 1,300 lawyers and has offices... ...and support remediation tracking - Collaborate with third-party security, data privacy, and enterprise risk teams on...SeniorWork at office$102k - $110k
...or Department Overview The Times is looking for a creative senior data analyst who is passionate about data and eager for the opportunity... ...financial information or for payment, and will not refer you to a third party to do so. You should never send money to anyone who...SeniorLocal areaFlexible hours$110k - $125k
...Senior Data Analyst CertiK New York City, NY, US Job Type: Full-Time Function: Data... ...CertiK is a pioneer in blockchain security, leveraging best-in-class AI technology... ...process large datasets from APIs/databases/third-party platforms to enable real-time team...SeniorFull timeContract workWork experience placementLocal areaFlexible hours$101k - $110k
...Mission or Department Overview NYT Wirecutter is looking for a Senior Business Analyst to lead the analytical narrative across our teams,... ...financial information or for payment, and will not refer you to a third party to do so. You should never send money to anyone who...SeniorLocal areaRemote workFlexible hoursShift work- ...Operational Due Diligence Senior Analyst Every day, we seek to improve financial security for people. Joining our team means you will be a part of a passionate... ...information technology, background checks, and third-party service providers (e.g., administrator, prime...SeniorOdd jobWork at officeVisa sponsorship
- ...Cybersecurity Senior Risk Analyst 1 Labor Category - Analyst 2 Work Location: Hybrid: Work... ...feedback; Evaluate risk of third parties used by New York City agencies; Document... ...) ~ Certified Information Systems Security Professional (CISSP) ~ Certified in...SeniorWork at officeRemote workMonday to Friday
$130k - $160k
...Department Engineering Team & Role As a Senior GRC Analyst at Benepass, you will help operate and... ..., and employees. You will work across security policies, internal controls, audit... ...Risk: Support vendor security reviews, third-party risk assessments, remediation tracking...SeniorFull timeWork at officeRemote workWork from homeFlexible hours$76.2k - $151k
...not accept unsolicited candidates, referrals or resumes from any staffing agency, recruiting service, sourcing entity or any other third-party paid service at any time. Any referrals, resumes or candidates submitted to Crowe, or any employee or owner of Crowe without a...SeniorWork at officeLocal areaWorldwideFlexible hours$45 - $50 per hour
...Role :- Third Party Risk Analyst/Banking - Required Location: Hybrid/Midtown New York City 3 days a week.Hybrid 1 year+ - Rate... ...technology audit, governance, risk, and compliance, information security, or related field is preferred, and willingness to learn is...Work at officeLocal areaRelocationFlexible hours3 days per week$97k - $132k
...Third Party Risk Analyst At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused... ...to ensure our programs and business operations remain secure and resilient. This role requires a blend of analytical rigor...$80.55k - $115k
...Join to apply for the Third Party Risk Analyst : Advisory role at Jack Henry Join to apply for the Third... ...(TPRM) strategy. Partner with senior leadership to evaluate and enhance third... ...procurement, legal, compliance, information security, and other control functions to...Full timeWork at officeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Analyst, Third-Party Security. Be the first to apply!

