Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Information Security Risk Analyst

$106k - $152k

FM Corporation

Job Description:

Established nearly two centuries ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineering expertise are solely dedicated to property risk management and the resilience of its policyholder-owners. These owners, who share the belief that the majority of property loss is preventable, represent many of the world’s largest organizations, including one of every four Fortune 500 companies. They work with FM to better understand the hazards that can impact their business continuity to make cost-effective risk management decisions, combining property loss prevention with insurance protection. 

Work Schedule  
This position requires on-site work one day per week at our Corporate Headquarters and flexibility to be on-site when needed based on the demands of the business 


Relocation is not offered for this position. 

Position Summary

FM is seeking a Senior Information Security Analyst with deep expertise in Third-Party Risk Management (TPRM), you will play a critical role in protecting FM by assessing how external vendors, SaaS platforms, and cloud solutions interact with our systems and data. This high-impact role where your expertise in cyber risk, vendor security, and cloud architecture will help shape business decisions, strengthen our security posture, and support innovation in a secure way. This includes reviewing both the vendor’s security control environment and the specific solution being implemented, with a focus on data handling, storage, and integration with internal systems. 

You will partner closely with business, technology, and procurement teams to identify risks and recommend practical, business-aligned mitigation strategies. 

You will lead end-to-end cybersecurity risk assessments of third-party vendors and solutions—going beyond standard due diligence to evaluate real-world risk across systems, data, and integrations. 

Key Responsibilities 

  • Lead end-to-end third-party solution risk assessments and vendor security reviews across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, and reassessments. 
  • Evaluate vendor security programs, control effectiveness, and governance, along with deep-dive assessment of the specific product being implemented including solution architecture, data flows, and integration points. 
  • Identify and communicate inherent and residual cyber risks related to data protection, privacy, IAM, privileged access, system connectivity, and external attack surface exposure. 
  • Review and interpret security documentation, including SOC 1/SOC 2 reports, ISO 27001 certifications, audit reports, architecture diagrams, data flow diagrams, and technical configurations. 
  • Recommend practical risk mitigation strategies, including compensating controls, secure design changes, and contractual safeguards to support risk-informed decisions. 
  • Partner with business, technology, procurement, and legal teams to support risk acceptance, exception management, and third-party risk governance. 
  • Contribute to the evolution of FM’s third-party risk management framework, methodology, and standards in alignment with NIST, ISO 27001, NYDFS, and other applicable regulatory expectations. 
Qualifications:
  • 5+ years of experience in cybersecurity, information security, or cyber risk, with a background in third-party risk management (TPRM), IT risk, audit, incident response, or access management. 
  • Experience assessing vendor security posture in cloud (SaaS/PaaS)and enterprise environments. 

Technical Expertise

  • Strong understanding of systems, networks, application architecture, cloud security, and secure system design across AWS, Azure, SaaS, PaaS, APIs, and enterprise integrations. 
  • Experience evaluating data flows, data classification, data protection, data governance, and secure data handling practices. 
  • Knowledge of IAM, SSO, federation, privileged access, cyber threats, vulnerabilities, and attack methodologies. 
  • Ability to interpret SOC 1, SOC 2, ISO certifications, and other third-party assurance artifacts to identify control gaps and residual risk. 

Risk & Analysis:

  • Ability to identify, assess, and clearly communicate complex cyber risks, trade-offs, and residual risk. 
  • Experience recommending practical, business-aligned risk based mitigation strategies, including compensating controls and secure design changes. 
  • Strong analytical judgment, attention to detail, and risk-based decision-making. 

Collaboration & Communication

  • Ability to translate technical findings into clear, business-relevant insights and recommendations. 
  • Strong stakeholder management and partnership across business, technology, procurement, and legal teams. 
  • Collaborative, solutions-focused mindset with strong influencing skills in a fast-paced assessment environment. 
  • High degree of professional skepticism and curiosity when evaluating vendor claims and evidence 
  • Ability to manage multiple priorities independently while maintaining quality and consistency of assessments 

Tools & Certifications:

  • Proficiency with Microsoft Office tools. 
  • Relevant certifications such as CISSP, CISA, CSA, CISM, Security+, GIAC, CEH, or similar are strongly desired. 

Education 

Bachelor's degree in information security, Computer Science, Information Technology, or a related field required. An equivalent of relevant work experience will also be considered. 

The hiring range for this position is $106,000- $152,000. The final salary offer will vary based on geographic location, individual education, skills, and experience. The position is eligible to participate in FM’s comprehensive Total Rewards program that includes an incentive plan, medical, dental and vision insurance, life and disability insurance, well-being programs, a 401(k) and pension plan, career development opportunities, tuition reimbursement, flexible work, and time off, including vacation and sick time. 

FM is an Equal Opportunity Employer and is committed to attracting, developing, and retaining a diverse workforce. 

#LI-NL1 

#FMG

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior Information Security Risk Analyst in Johnston, RI vacancy
  • FM is seeking a Senior Information Security Risk Analyst to lead enterprise-wide security risk assessments and strengthen our overall cyber posture. In this role, you will evaluate technology, processes, and vendors to identify threats, vulnerabilities, and control gaps... 
    Senior

    FM

    Johnston, RI
    8 days ago
  • FM seeks a Senior Information Security Risk Analyst to lead cyber and technology risk activities across the organization. You will perform detailed risk assessments on applications, infrastructure, and vendors, identify control gaps, and recommend pragmatic remediation... 
    Senior

    FM

    Johnston, RI
    8 days ago
  •  ...Centreville Bank is seeking a Vendor Management Analyst in Warwick, Rhode Island. This role supports the Third-Party Risk Management (TPRM) program by evaluating vendor risks, reviewing contracts, and maintaining documentation for compliance. Candidates should have a Bachelor... 
    Suggested

    Centreville Bank

    Warwick, RI
    2 days ago
  • AAA Northeast is seeking a Security Analyst II to support risk management, audits, and compliance programs, aligning with standards such as NIST and PCI-DSS, including vulnerability and threat intelligence management. This role partners with IT and business lines to implement... 
    Suggested

    AAA Northeast

    Providence, RI
    6 hours ago
  • FM is seeking a Senior Information Security Analyst specializing in Third-Party Risk Management (TPRM). You will lead end-to-end risk assessments of external vendors, SaaS platforms, and cloud solutions, focusing on data handling, storage, and integration with internal... 
    Senior

    FM Corporation

    Johnston, RI
    6 hours ago
  • The Vendor Management Analyst is responsible for supporting the Bank’s Third-Party Risk Management (TPRM) Program within the Information Security department. This role evaluates the risk of new...  ...Project Management, Finance, and senior leadership to ensure vendors meet... 
    Contract work
    For subcontractor

    Centreville Bank

    West Warwick, RI
    4 days ago
  • $28 per hour

    Description Physical Security Command Center (PSCC) is a 24x7 operation tasked with the navigation of elevated security activity normally...  ...colleagues and customers, possessing the ability to retain information and communicate facts forward with context intact.... 
    Hourly pay
    Work at office
    Local area
    Immediate start
    Remote work
    Monday to Friday
    Flexible hours
    Night shift

    Citizens

    Johnston, RI
    3 days ago
  • Citizens is seeking a dedicated team member for its 24x7 Physical Security Command Center. You will handle alarms, calls, and alerts, coordinate with branches and vendors, and dispatch emergency services as needed. The role emphasizes confidentiality, strong communication... 
    Night shift

    Citizens

    Johnston, RI
    3 days ago
  • Overall Summary: As a member of the Security Team, the Security Analysts are responsible for the management of the governance, risk, and compliance aspects of AAA Northeast. The...  ...related IT experience, preference for information security or risk management Skills Ability... 
    Shift work

    AAA Northeast

    Providence, RI
    6 hours ago
  • A financial institution in Johnston, RI is seeking a Senior Analyst for the Enterprise Technology & Security Risk team. This role leads the identification and management of technology-related risks, ensuring robust risk management practices. Responsibilities include monitoring... 
    Senior
    Remote work

    Citizens Bank

    Johnston, RI
    1 day ago
  • Citizens is seeking a Third Party Risk Sr Analyst to manage vendor issues, perform QA checks, and lead Third Party Vendor Assessment reviews. You will collaborate with senior leaders and vendors to assess risk, identify issues, and help create action plans to mitigate... 
    Senior

    Citizens

    Johnston, RI
    1 day ago
  • Citizens Bank in the United States is seeking a Senior Analyst to manage vendor issues, perform vendor assessments, and support risk governance across business units. You will review control environments and provide insights to leaders. The role requires collaboration... 
    Senior
    Remote job

    Citizens Bank

    Providence, RI
    1 day ago
  • Citizens Bank is seeking a Third Party Risk Sr Analyst responsible for managing vendor assessment reviews and ensuring adherence to company policies. This role involves close collaboration with business leaders to evaluate vendor risks effectively. Applicants should possess... 
    Senior
    Work at office
    Remote work

    Citizens Bank

    Providence, RI
    3 days ago
  • Description The Enterprise Technology & Security (ETS) Risk Senior Analyst leads the identification, assessment, and mitigation of technology-related...  ...to support a resilient control environment and informed risk decisions. The Senior Analyst applies deep knowledge... 
    Senior
    Local area
    Remote work
    Monday to Friday

    Citizens Bank

    Johnston, RI
    1 day ago
  • KeyBank is seeking a Sr. Risk Analyst within the Core Treasury Risk team to govern risk frameworks and oversee strategic risk initiatives. The role emphasizes influencing across the organization, building relationships, and delivering timely risk insights. The position... 
    Senior

    KeyBank

    Providence, RI
    4 days ago
  • $95k - $123k

    As the Third Party Risk Sr Analyst, you will manage vendor issues, complete...  ...includeCollaborating with senior management to influence key...  ...Applying experience in audit, security and regulatory frameworks...  ...identity or expression, genetic information, genetic characteristic,... 
    Senior
    Work at office
    Local area
    Monday to Friday
    Flexible hours

    Citizens Financial Group

    Johnston, RI
    19 hours ago
  • Palo Alto Networks is seeking a domain consultant for network security transformation. You will provide technical guidance on customers' network security and zero trust journeys, defining solutions that secure key business imperatives and positioning our leadership in... 
    Senior
    Remote job

    Palo Alto Networks

    Providence, RI
    2 days ago
  • $105k - $130k

     ...learn, and work. CampusGuard, a Nelnet company, provides information security and privacy consulting and compliance services primarily for...  ...scope verification, and incident response. Understanding of risk assessments and targeted risk analyses. Technical understanding... 
    Full time
    Temporary work
    Fixed term contract
    Local area
    Remote work
    Work from home
    Home office

    Nelnet

    Providence, RI
    3 days ago
  • Job Title : Senior Business Systems Analyst - AI-Orchestrated Workflows & Digital Workforce (Commercial Banking) Experience : 8+ Years Location...  ..., IT Operations, Application Development, and Information Security. Stratacent.com Global managed services firm assisting... 
    Senior

    Stratacent

    Johnston, RI
    2 days ago
  • Job Title: Senior Business Systems Analyst - Digital Client Servicing (Commercial Banking...  ...Voice servicing & secure communications WalkMe-based...  ...remediation Partner with Fraud & Risk teams to integrate...  ...Application Development, and Information Security. URL - Global managed... 
    Senior

    Stratacent

    Johnston, RI
    4 days ago
  •  ...Computer in Rhode Island is seeking a Senior GRC Manager to own our GRC program end-...  ...GDPR, HITRUST, SOC 2. You’ll manage the information security program, audits, and documentation, working...  ...and audit-ready evidence, prioritizing risk-based #J-18808-Ljbffr Harris Computer
    Senior
    Flexible hours

    Harris Computer

    Providence, RI
    6 hours ago
  • Centreville Bank is seeking a Vendor Management Analyst to support the Bank’s Third-Party Risk Management (TPRM) program within Information Security. The role evaluates vendor risk for new...  ..., Project Management, Finance, and senior leadership to ensure vendors meet... 

    Centreville Bank

    West Warwick, RI
    4 days ago
  • $71k - $125k

     ...nearest (. JOB BRIEF (PURPOSE) The first line Risk team within Commercial Bank is...  ...of this team, the Core Treasury Sr. Risk Analyst has responsibility to identifying and developing...  ...inquiry and investigation requests for information. Also, assist in the evaluation of audit... 
    Senior
    Work experience placement
    Work at office
    Flexible hours
    3 days per week

    KeyBank

    Providence, RI
    4 days ago
  •  ...Job Description Job Description Description: Position Summary: The Employee Benefits Risk Advisor is responsible for driving new business growth by developing and executing a strategic sales pipeline focused on employee benefits solutions. This individual is a... 
    Senior

    Starkweather & Shepley Insurance Brokerage Inc.

    Providence, RI
    19 days ago
  • $46.99k - $122.4k

     ...provide guidelines on how financial statements should be prepared to ensure quality and consistency. Analyzes complex financial information to provide insights to business units to support the decision‑making process. Applies in-depth knowledge of financial forecasting... 
    Senior
    Hourly pay
    Full time
    Temporary work
    Work experience placement
    Local area

    CVS Health

    Providence, RI
    2 days ago
  •  ...Citizens Bank is seeking a Senior Analyst for Third Party Risk to manage vendor issues, complete QA functions, and execute Third Party Vendor Assessment reviews. You will influence senior management, assess vendor control environments, and help develop action plans to... 

    Citizens Bank

    Johnston, RI
    11 hours ago
  • $85k

     ...Job Description The Senior Financial Analyst leads processes to include the development of planning...  ...communicate complex financial / operational information to various levels of the organization...  ...customer to which you are assigned. Security Notice For Applicants Ryder will only... 
    Senior
    Full time
    Remote work

    Ryder

    Providence, RI
    12 hours ago
  • Rhode Island Public Utilities Commission is seeking a Public Utilities Analyst V to perform complex audits and economic analyses of utility filings. You will evaluate rate structures, capital costs and revenue requirements, and provide strategic guidance to support Commission... 
    Senior

    RI Council 94

    Providence, RI
    6 hours ago
  • Stratacent is seeking a Third-Party Banking Risk Analyst to oversee risk governance of Commercial Third-Party Deposit Partners (CTPDPs). The role supports the Embedded Banking team by performing monthly, quarterly, and ad hoc oversight activities to identify, assess, elevate... 

    Stratacent

    Johnston, RI
    6 hours ago
  • Job Title: Third-Party Banking Risk Analyst Experience: 5+ Years Location: Hybrid - Boston MA (preferred)/ NYC/Johnston RI Job Description...  ..., Automation, IT Operations, Application Development, and Information Security. Global managed services firm assisting customers with... 

    Stratacent

    Johnston, RI
    6 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Information Security Risk Analyst. Be the first to apply!