Information Security Third-Party Risk Analyst
$98.18k - $115.5kU.S. Bank
At U.S. Bank, we’re on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at—all from Day One.
Job Description
This position is not eligible for visa sponsorship.
Location expectations:
This role requires working from a U.S. Bank location three (3) or more days per week.
US Bank is seeking an Information Security Third-Party Risk Analyst to join our Information Security organization, supporting third-party risk management and vendor security oversight. This role is responsible for evaluating and managing information security risk across external vendors, ensuring appropriate controls are in place, and driving remediation of identified risks.
This person will perform hands-on third-party security risk assessments, analyze vendor controls and security posture, and partner with internal stakeholders and external vendors to reduce risk exposure. They will play a key role in identifying control gaps, tracking remediation, supporting contract security reviews, and contributing to ongoing risk monitoring, reporting, and audit activities.
Responsibilities:
Perform information security risk assessments on third-party vendors (new and existing)
Review and analyze vendor security questionnaires, control responses, and supporting documentation
Identify security gaps, control deficiencies, and non-compliance issues
Document and track risk findings and remediation efforts through resolution
Evaluate vendor remediation plans and compensating controls
Partner with business stakeholders and third parties to explain risks and recommend mitigation strategies
Support contract review and redlining with a focus on information security requirements
Conduct continuous monitoring of vendor security posture
Review and assess third-party security incidents and perform post-event analysis
Contribute to monthly and quarterly reporting, metrics, and trend analysis
Support audit activities, control testing, and quality assurance efforts
Collaborate across information security, risk, and compliance teams
Must-Have Skills:
5+ years of experience in information security
5+ years of experience in third-party risk management, vendor risk, or risk analysis
Hands-on experience conducting third-party/vendor information security risk assessments
Strong understanding of information security controls and risk concepts
Experience identifying control gaps and evaluating remediation actions
Experience with contract review or redlining related to security requirements
Ability to clearly communicate risk to both technical and non-technical stakeholders
Nice-to-Have Skills:
Familiarity with security frameworks (e.g., NIST 800-53)
Experience reviewing SOC 2 Type II reports
Experience with continuous monitoring tools (e.g., BitSight, Archer)
Exposure to third-party security incident response and post-event analysis
Broader technical cybersecurity background
Exposure to emerging risks (e.g., AI, new technologies)
If there’s anything we can do to accommodate a disability during any portion of the application or hiring process, please refer to our disability accommodations for applicants ( .
Benefits:
Our approach to benefits and total rewards considers our team members’ whole selves and what may be needed to thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following:
Healthcare (medical, dental, vision)
Basic term and optional term life insurance
Short-term and long-term disability
Pregnancy disability and parental leave
401(k) and employer-funded retirement plan
Paid vacation (from two to five weeks depending on salary grade and tenure)
Up to 11 paid holiday opportunities
Adoption assistance
Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law
Review our full benefits available by employment status here ( .
U.S. Bank is an equal opportunity employer. We consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, and other factors protected under applicable law.
E-Verify
U.S. Bank participates in the U.S. Department of Homeland Security E-Verify program in all facilities located in the United States and certain U.S. territories. The E-Verify program is an Internet-based employment eligibility verification system operated by the U.S. Citizenship and Immigration Services. Learn more about the E-Verify program ( .
The salary range reflects figures based on the primary location, which is listed first. The actual range for the role may differ based on the location of the role. In addition to salary, U.S. Bank offers a comprehensive benefits package, including incentive and recognition programs, equity stock purchase 401(k) contribution and pension (all benefits are subject to eligibility requirements). Pay Range: $98,175.00 - $115,500.00
U.S. Bank will consider qualified applicants with arrest or conviction records for employment. U.S. Bank conducts background checks consistent with applicable local laws, including the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act as well as the San Francisco Fair Chance Ordinance. U.S. Bank is subject to, and conducts background checks consistent with the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA). In addition, certain positions may also be subject to the requirements of FINRA, NMLS registration, Reg Z, Reg G, OFAC, the NFA, the FCPA, the Bank Secrecy Act, the SAFE Act, and/or federal guidelines applicable to an agreement, such as those related to ethics, safety, or operational procedures.
Applicants must be able to comply with U.S. Bank policies and procedures including the Code of Ethics and Business Conduct and related workplace conduct and safety policies.
Posting may be closed earlier due to high volume of applicants.
$98.18k - $115.5k
...Information Security Third-Party Risk Analyst At U.S. Bank, we're on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes...SuggestedContract workTemporary workLocal area3 days per week- Fifth Third in Cincinnati, OH is seeking a Senior Analyst, Sourcing to support outsourcing strategies and manage onboarding for third party relationships. You will ensure that risks associated with these relationships are documented and assessed properly. The ideal candidate...Suggested
- Fifth Third Bank in Cincinnati, OH is seeking a Specialist for Third Party Oversight. This role involves managing third party relationships and supporting the development of outsourcing strategies. The ideal candidate has at least 4 years of experience in project management...Suggested
- ...are seeking an experienced Principal Third Party Risk Management (TPRM) Consultant to lead and... ...and GRC services within the cyber security consultancy. This is a senior leadership... ...or related domains. CISA (Certified Information Systems Auditor) strongly preferred....Suggested
$80k - $150k
...Road, Brooklyn Ohio About the Job The Operational Risk Analyst V- Third Party Management resides within Key's Operational Risk... ...external audits/examinations risk management requests for information, assist in the evaluation of audit/examination findings and...SuggestedWork at officeFlexible hoursShift work- ...Make banking a Fifth Third better® We connect great... ...of Business (LOB) third party relationships. Works with... ...partners to ensure the risk associated with a Third... ...and disseminate information as appropriate to Third... ...solving skills. Senior Analyst, Third Party Oversight...Permanent employmentContract workWork at office
- ...Job Title: ITS Third Party Governance Assurance Analyst II Duration: 3 Months Contract... ...(VMO) and third-party risk management capabilities.... ...across IT, procurement, security, legal, compliance, and operations... ...in-depth knowledge of information technology, cybersecurity...Contract workWork at officeShift work
- ...Job Description: The Third Party Operations Assistant, will be responsible for the end... ...updates on Orderbook progress and identifying risks or opportunities What Do You Need To... ...knowledge of systems that house product information (i.e. PLM) Strong ability to handle...Work from homeHome officeMonday to FridayFlexible hours
- ...Title: Information Security Analyst Department: Information Technology Candidates must reside... ...supporting key components of MCPC's security, risk, and compliance program. This role... ...management, access governance, and third-party risk management. The Information...
- Title: Cyber Risk Analyst Location: Columbus, OH (Hybrid: On-site twice a week) Contract Type: W2 (Must be... ...Framework (CSF) and Factor Analysis of Information Risk (FAIR). The analyst will work closely with security teams and stakeholders across the organization...Contract workInternshipWork at officeLocal area2 days per week
- Western & Southern Financial Group in Cincinnati is seeking a professional in information security to provide support for corporate initiatives and projects. The role encompasses risk assessments, security guidance, and policy development to ensure compliance with industry...
$65k - $75k
...IT Risk Advisory Associate We are currently seeking professionals at the associate... ...engagements, (b) HIPAA Compliance, (c) Information Technology General Control audits (financial... ...in information systems, accounting, IT, security, or other relevant field. CISA, CPA,...Work at officeWork from homeFlexible hours$94.1k - $164.8k
...Job Summary: The Information Security GRC Analyst III managed day to day, short and long term information security risks and ensures activities are within risk tolerance and in... ...risks Review and report on vendor/third party risk to support vendor risk management...Temporary workWork experience placementWork at office- ...Make banking a Fifth Third better® We connect great people to great opportunities. Are... ...banking at Fifth Third Bank. Name: Business Analyst III Assist in defining application and... .... Responsible and accountable for risk by openly exchanging ideas and opinions,...
- ...contributions and the opportunity to secure annual grants for the... ...Head of Technology and AI Risk, the Senior Analyst is responsible for... ...Technology, Security, and Third-Party Risk, and Legal and Compliance... ...condition, genetic information, marital status, sexual orientation...Temporary workLocal areaFlexible hours
- Cincinnati Insurance Company is hiring an IT Vendor Analyst in Fairfield, OH, responsible for analyzing security risks associated with vendors. The role includes investigating incidents, managing third-party requests, and creating documentation. Applicants should have strong...
- Gilder Search Group is seeking an Information Security Analyst in Cleveland, Ohio. This role is responsible for executing and supporting security, risk, and compliance initiatives. Key responsibilities include conducting internal audits, managing vendor risk, and monitoring...
$87.8k - $160.9k
...opportunity The objective of our consulting risk services is to provide clients with a... ...role involves working closely with IT, security teams, and business units to ensure that... ...leader to assist clients in employing proper information systems, resources, and controls to...Contract workSummer holidayWork at officeFlexible hours$87.8k - $160.9k
...build a better working world. Digital Risk - Senior Consultant - Power & Utilities... ...leader to assist clients in employing proper information systems, resources, and controls to... ...performing information technology control and security engagements. Skills and attributes for...Contract workSummer holidayFlexible hours$95k - $105k
...) governance and compliance program. Works closely with Information Security, Legal, Risk Management, and business stakeholders to help ensure AI... ...data privacy, security, bias/fairness, explainability, third-party/vendor risk, and regulatory impacts) and follow up on remediation...Work experience placementRemote workWork from home- ...Acquisition Senior Analyst Support the execution of the Company's Acquisition of Senior... ..., underwriting, contract negotiation, third party inspections, due diligence, closing and... ...methods. Ability to manage expectations, inform stakeholders, and excel under tight...Contract workLocal areaAfternoon shift
$185k - $237.5k
...operation of Circle’s Product Risk Management function. The goal... ...management, risk assessment, third-party risk management, and training... ...including compliance, legal, security, finance and 3rd parties.... ...Product Operations and Risk Analyst 10+ years working in risk management...Flexible hours- ...As a Senior Analyst, your job is to move beyond resolving individual... ...memo workflows, ensuring our third-party partners and internal teams... ...Do: 1. Strategic Dispute & Risk Mitigation * Design and optimise... ...to negotiate settlements and secure waivers. 2. Stakeholder...
- ...position works closely with clients, internal development teams, and third-party vendors to translate business needs into scalable system... ...flagging gaps ~ Identify system capabilities, constraints, and risks early in the design process. ~ Serve as a primary technical...Temporary workLocal area
- ...client is seeking a Senior Compensation Analyst to join their team. Conduct... ...positions for appropriate salary grades, lead third-party compensation surveys, stay updated on industry... ...in compensation. Proficiency in information systems, particularly with a preference...Hourly payRelocation
- ...Duties and Responsibilities: Daily sub-merchant risk reviews and investigations Review concurrence requests from... ...with internal risk and compliance partners Support internal Third-Party governance and due diligence requirements for BIN Sponsorship Vendors...Remote work
- Closing Analyst Department: Closing Employment Type: Full Time... ...closely with internal teams, third-party vendors, title agents, and warehouse... ...and other parties informed of potential issues or delays... ...Ginnie Mae mortgage backed securities program Highly developed analytical...Full time
- ...Business Process Analyst Serves as a liaison between the campus community, business... ...business unit(s) and the enterprise or third-party systems used by the units. Analyze business... ...between business units supported and information technology staff in upgrades and new...Shift work
- ...Your Future with Us Our IT department is currently seeking an IT Vendor Analyst. The primary role of the IT Vendor Analyst is to support Third Party Risk Managers with analyzing information security risks associated with the company’s vendors. This role also helps Third...Remote jobFlexible hours
- ...Business Analyst I 96005 North Canton OH - North Canton, OH 4... ...Overview Position Type: Information Technology Job Shift: 8hr Travel... ...assumptions, dependencies, risks and constraints. Creates... ...employees and representatives of third parties. 3. Contribute to...Local areaRelocationShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Third-Party Risk Analyst. Be the first to apply!

