Cybersecurity & Third Party Risk Analyst
Maryland Department of Information Technology
As the state’s IT leader, DoIT manages information technology and telecommunications services and provides critical support to state agencies, the Executive Office of the Governor, coordinating offices, and independent Executive Branch agencies. The agency provides cybersecurity, digital, data governance, AI enablement, infrastructure, and platform services to its partner agencies, ensuring the State of Maryland is more secure, productive, and accessible. Main Purpose The purpose of this position is to support the development of the Department of Information Technology’s (DoIT) Third-Party Risk Management (TPRM) program while providing cross‑functional support for enterprise cybersecurity risk assessments and the policy lifecycle. As the primary analyst for third‑party oversight, this role ensures that all vendors, contractors, and cloud service providers comply with the State of Maryland’s security standards. Additionally, this position serves as a GRC generalist, facilitating the Authority to Operate (ATO) process and ensuring that cybersecurity policies are implemented and maintained in alignment with NIST frameworks and state legislative mandates. Position Duties Third-Party Risk Management Program Support the development and implementation of a third‑party/vendor risk management framework that aligns with NIST 800-161 (Supply Chain Risk Management) and State of Maryland Cybersecurity & Privacy policy suite. Assess and manage security risks associated with cloud providers, contractors, and IT vendors. Establish vendor security assessments, contract security requirements, and ongoing compliance monitoring. Partner with procurement and legal teams to integrate cybersecurity requirements into contracts and vendor agreements. Oversee vendor audits, penetration testing, and compliance assessments to mitigate third‑party cybersecurity risks. Cybersecurity Risk Management & ATO Support Support execution of statewide cybersecurity risk assessments and threat modeling for Executive Branch agencies. Facilitate the ATO (Authority to Operate) process by reviewing System Security Plans (SSPs) and assessing control implementation against NIST 800-53. Support the development and maintenance of the Enterprise Risk Register and assist agencies in developing Plans of Action and Milestones (POA&Ms) to remediate gaps. Provide cross‑pollination support for continuous monitoring efforts to track the state’s real‑time risk posture. Policy Lifecycle & Governance Management Manage the full lifecycle of cybersecurity and privacy policies, from initial drafting and stakeholder review to formal approval and publication. Ensure all policies remain current with evolving federal and state regulations (e.g., IRS 1075, HIPAA, State Senate/House Bills). Map policy requirements to technical controls to ensure measurable compliance across the enterprise. Minimum Qualifications Experience: Four years of experience in Information security as it relates to policy creation regarding compliance, legislation, governance programs and/or supporting internal audits. Notes: 1. Candidates may substitute a bachelor’s degree in IT security management, IT management, information security, political science, business management, communications, or public administration with cybersecurity experience or a related field for up to two years of the required experience. Preferred Experience Public Sector cybersecurity experience: Direct experience working within local, state, or federal government environments, with direct knowledge of the government Authority to Operate (ATO) process and specialized compliance mandates (e.g., IRS 1075, HIPAA, or State legislative frameworks). Supply Chain/Third‑Party Specialization: Working experience evaluating vendor security postures using NIST 800-161 (Supply Chain Risk Management) and interpreting SOC 2 reports or vendor‑provided System Security Plans (SSPs). Professional Certifications: Possession of foundational or intermediate GRC‑related certifications such as CompTIA Security+, ISACA CISA (Certified Information Systems Auditor), or CRISC (Certified in Risk and Information Systems Control). #J-18808-Ljbffr Maryland Department of Information Technology
- ...Maryland Department of Information Technology is seeking an analyst for its Third-Party Risk Management program. This role involves developing... ...have four years of experience in information security, cybersecurity risk management, and policy development. The position entails...Suggested
- ...seeking a Delegated Authorizing Official Representative in Maryland. The role involves performing security risk assessments and ensuring the implementation of cybersecurity controls. You will interact with customers and corporate officers to achieve cybersecurity objectives....Suggested
- ...to-end managed IT services, including managed mobility, cloud, cybersecurity, network operations, and application development, DMI supports... ...DMI, LLC is looking for a Security Operations Center (SOC) Analyst with hands-on experience monitoring, detecting, and analyzing...SuggestedShift workNight shiftDay shiftAfternoon shift
$90.78k
...The Sr. Analyst - Supply Chain Risk Management (SCRM) Analyst supports enterprise and program stakeholders... ...Maximus, Maximus Federal, and third-party relationships meet U.S. federal and... ...suppliers (e.g., performance, financial, cybersecurity, and geopolitical indicators),...SuggestedContract workFor subcontractorWork at office$120k - $140k
...GRC Compliance Analyst / Assessor / Onsite in Annapolis Annapolis, Maryland Onsite... ...$140k This organization is a growing cybersecurity consulting firm founded in 2006, with a... ...experience in cybersecurity compliance, risk assessment, or IT audit ~ Strong hands...SuggestedFull time$54.22k - $79.02k
The EFT Risk Team monitors Risk for ACH and other payment channels. Managing the Risk helps keep customers and UMB from large losses.... ...is processed according to UMB’s Risk appetite. As the EFT Risk Analyst, you will assist with the ongoing administration and support of...Local areaRemote workMonday to FridayFlexible hours- ...Lead Business Analyst / Quality Assurance Anywhere Type:... ...client, an industry leader in cybersecurity and threat intelligence, seeks... ...analysis and identify risks for migration from Data Center... ...environments such as APIs, SSO, and third-party tools. ~ Ability to...Hourly payContract workLocal areaRemote work
$20 per hour
We are looking for a Risk Adjustment Analyst to join our team to train AI models. You will measure the progress of these AI chatbots, evaluate their logic, and solve problems to improve the quality of each model. In this role, you will need to be an expert in healthcare...Hourly payFull timePart timeFor contractorsRemote workFlexible hours- A sustainable investment firm is seeking an Analyst or Associate with strong financial modeling and analytics experience. This role in Annapolis involves building and auditing financial models for transaction closings and supporting sustainable investments. Qualifications...
$34.55 - $55.19 per hour
RISK ANALYST USMB WHAT IS THE OPPORTUNITY? This role will primarily be responsible for the execution of the first line of defense Risk Program, including the enhancement of internal controls and in performing internal controls monitoring and testing. In addition, will...Hourly pay- ...capabilities are focused on software engineering, cybersecurity, system engineering and IT services.... ...a Telecommunications Technical Analyst to join our team. You will operate,... ...Community (e.g. military services, Second and Third Party customers and vendors). Daily...Work at officeImmediate startFlexible hours
$93k - $100k
TekSynap is looking for a Watch Officer in Annapolis Junction, MD, to ensure the effectiveness of surveillance systems and comply with security standards. The candidate must possess an active TS/SCI + CI Poly clearance and meet various education and experience criteria....$104k - $130k
...positive outcome. Bonus Points If Experience working in the healthcare industry Experience and familiarity with MA, ACA and Medicaid Risk Adjustment models. Experience with other business intelligence backend and analytics applications Familiarity with or interest in...Work experience placement$60k
...without dual citizenship. This role is remote. The Risk, Quality, and Performance Analyst serves as the Risk, Quality, and Performance Analyst supporting... ...Coordinate with program management, operations, and cybersecurity teams to support service reviews, performance...Contract workRemote work- ...Key Access Control Analyst LOCATION Annapolis Junction, MD 20701 CLEARANCE... ...Security Analyst, IT Access Coordinator, Cybersecurity Analyst, Privileged Access Management Analyst... ..., Identity Governance Specialist, Risk and Access Management Analyst, Authentication...Temporary workFor contractorsImmediate startFlexible hours
- ...an accredited high school or possession of a high school equivalency certificate. Experience: Seven years of experience evaluating risk involved in granting single‑family, multifamily and commercial loans, government assistance programs, or construction management. Substitution...For contractors
$34.55 - $55.19 per hour
City National Bank is looking for a Risk Analyst to take responsibility for executing their Risk Program, primarily focusing on internal controls enhancement and compliance support. This role requires a strong background in audit and compliance within the banking sector...Hourly pay$7.5k
...impactful mission. This opportunity supports a team of Target Analyst Reporters, Collection Managers, Collection Targeting and Compliance... ...Headquartered in Columbia, MD., RealmOne supplies advanced cybersecurity, data science and software engineering services and products...Contract workWork experience placementImmediate startFlexible hours$61k - $101k
...requirements. Escalate confirmed or high-risk incidents to senior analysts or incident response teams when... ..., preferably experience in cybersecurity, information technology, or a related... ...your banking information to a third party purporting to need that information...Full timeTemporary workFlexible hours$7.5k
...impactful mission. This opportunity supports a team of Exploitation Analysts, Digital Network Exploitation Analysts, Target Digital... ...Headquartered in Columbia, MD., RealmOne supplies advanced cybersecurity, data science and software engineering services and products...Contract workWork experience placementImmediate startFlexible hours$7.5k
...opportunity supports an Enterprise IT contract with a team of SIGDEV Analysts, Systems Engineers, Junior Engineers, Telecommunication... ...Headquartered in Columbia, MD., RealmOne supplies advanced cybersecurity, data science and software engineering services and products...Contract workFor contractorsWork experience placementImmediate startFlexible hours$7.5k
...-end analytics and data science services within the REALM of cybersecurity. Your effort and expertise are crucial to the success and... ...Cryptanalytic Computer Scientists, Cryptologic Cyber Planners, Intrusion Analysts, Protocol Analysts, Signals Analysts and Reverse Engineers,...Contract workWork experience placementImmediate startFlexible hours$7.5k
...come join us! Job Description: The Jr. TechSIGINT Analyst shall have experience in ELINT, FISINT, PROFORMA, or COMEXT.... ...Headquartered in Columbia, MD., RealmOne supplies advanced cybersecurity, data science and software engineering services and products to...Work experience placementImmediate startFlexible hours- A healthcare technology company is seeking a Risk Adjustment Analyst to train AI models and evaluate their performance. You will provide healthcare-related problems to AI chatbots, ensuring their accuracy and quality. Applicants should be fluent in English and have a current...Remote jobHourly payFlexible hours
$50 - $60 per hour
A leading AI development firm is seeking a Risk Analyst to work remotely on flexible projects that contribute to training AI models for finance professionals. This role is tailored for those with advanced financial expertise, such as a Master’s or PhD. Responsibilities...Remote jobHourly payFlexible hours$58.51 - $88.6 per hour
A technology solutions company based in Maryland is seeking qualified candidates for a security clearance position in cybersecurity and network engineering. With options ranging from an Associate's to a Doctorate Degree and varying years of experience, applicants will enjoy...Hourly payFlexible hours$182k - $233k
Intelliforce-IT Solutions Group is seeking an Exploitation Analyst in Maryland focused on analytic insight and cybersecurity systems. You will conduct target analysis, support mission partners, and develop exploitation techniques. Candidates should have 12 years of relevant...$182k - $233k
A cybersecurity firm in Maryland is seeking an experienced Exploitation Analyst to conduct deep target analysis and support the exploitation of digital networks. This role requires a Top Secret Clearance, relevant experience, and U.S. citizenship. The position offers a...- ...job opportunities are posted here as they become available. IT Analyst - Advanced Military Technologies (DoD SkillBridge Fellowship)... ...network administration, hardware and software management, and cybersecurity operations. This role ensures reliable performance of...Full timeWork at office
$55k - $66k
...and expertise in their field. We are currently hiring an IT Analyst III to join our ATEC IT Support team. To join our team, apply... ...customer support requirements. Ensure rigorous application of cybersecurity policies, principles, and practices in the delivery of customer...Full timePart timeCurrently hiringWork at officeRemote workRelocation
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity & Third Party Risk Analyst. Be the first to apply!

