U.S. Bank

Information Security Third-Party Risk Analyst

U.S. Bank$98K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years experience in information security
  • 5+ years experience in third-party risk management or vendor risk
  • Hands-on experience conducting third-party/vendor risk assessments
  • Strong understanding of information security controls and risk concepts
  • Experience identifying control gaps and evaluating remediation actions
  • Experience with contract review or redlining related to security requirements
  • Ability to communicate risk clearly to technical and non-technical stakeholders

Responsibilities

  • Perform information security risk assessments on third-party vendors
  • Review and analyze vendor security questionnaires and control responses
  • Identify security gaps and non-compliance issues
  • Document and track risk findings and remediation efforts
  • Evaluate vendor remediation plans and compensating controls
  • Partner with stakeholders to explain risks and recommend mitigations
  • Conduct continuous monitoring of vendor security posture

Benefits

  • Healthcare (medical, dental, vision)
  • Basic term and optional term life insurance
  • Short-term and long-term disability
  • Pregnancy disability and parental leave
  • 401(k) and employer-funded retirement plan
  • Paid vacation (2 to 5 weeks based on tenure)
  • Up to 11 paid holidays
  • Adoption assistance
  • Sick and Safe Leave accruals of up to 80 hours per year
Full Job Description
Job Description

This position is not eligible for visa sponsorship.

Location expectations:
This role requires working from a U.S. Bank location three (3) or more days per week.

US Bank is seeking an Information Security Third-Party Risk Analyst to join our Information Security organization, supporting third-party risk management and vendor security oversight. This role is responsible for evaluating and managing information security risk across external vendors, ensuring appropriate controls are in place, and driving remediation of identified risks.

This person will perform hands-on third-party security risk assessments, analyze vendor controls and security posture, and partner with internal stakeholders and external vendors to reduce risk exposure. They will play a key role in identifying control gaps, tracking remediation, supporting contract security reviews, and contributing to ongoing risk monitoring, reporting, and audit activities.

Responsibilities:
  • Perform information security risk assessments on third-party vendors (new and existing)
  • Review and analyze vendor security questionnaires, control responses, and supporting documentation
  • Identify security gaps, control deficiencies, and non-compliance issues
  • Document and track risk findings and remediation efforts through resolution
  • Evaluate vendor remediation plans and compensating controls
  • Partner with business stakeholders and third parties to explain risks and recommend mitigation strategies
  • Support contract review and redlining with a focus on information security requirements
  • Conduct continuous monitoring of vendor security posture
  • Review and assess third-party security incidents and perform post-event analysis
  • Contribute to monthly and quarterly reporting, metrics, and trend analysis
  • Support audit activities, control testing, and quality assurance efforts
  • Collaborate across information security, risk, and compliance teams


Must-Have Skills:
  • 5+ years of experience in information security
  • 5+ years of experience in third-party risk management, vendor risk, or risk analysis
  • Hands-on experience conducting third-party/vendor information security risk assessments
  • Strong understanding of information security controls and risk concepts
  • Experience identifying control gaps and evaluating remediation actions
  • Experience with contract review or redlining related to security requirements
  • Ability to clearly communicate risk to both technical and non-technical stakeholders


Nice-to-Have Skills:
  • Familiarity with security frameworks (e.g., NIST 800-53)
  • Experience reviewing SOC 2 Type II reports
  • Experience with continuous monitoring tools (e.g., BitSight, Archer)
  • Exposure to third-party security incident response and post-event analysis
  • Broader technical cybersecurity background
  • Exposure to emerging risks (e.g., AI, new technologies)


Benefits:

Our approach to benefits and total rewards considers our team members' whole selves and what may be needed to thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following:
  • Healthcare (medical, dental, vision)
  • Basic term and optional term life insurance
  • Short-term and long-term disability
  • Pregnancy disability and parental leave
  • 401(k) and employer-funded retirement plan
  • Paid vacation (from two to five weeks depending on salary grade and tenure)
  • Up to 11 paid holiday opportunities
  • Adoption assistance
  • Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law


Review our full benefits available by employment status here.

The salary range reflects figures based on the primary location, which is listed first. The actual range for the role may differ based on the location of the role. In addition to salary, U.S. Bank offers a comprehensive benefits package, including incentive and recognition programs, equity stock purchase 401(k) contribution and pension (all benefits are subject to eligibility requirements). Pay Range: $98,175.00 - $115,500.00

Posting may be closed earlier due to high volume of applicants.

About U.S. Bank

U.S. Department of the Treasury is a government agency responsible for promoting economic prosperity and ensuring financial security. The department is responsible for a wide range of activities such as advising on economic and financial issues, encouraging sustainable economic growth, and fostering improved governance in financial institutions.

U.S. Bank Careers

Join the dynamic team at U.S. Bank, one of the nation's top banking institutions, where your career journey is as promising as the services we provide to our customers. At U.S. Bank, we are committed to fostering a culture of innovation, leadership, and diversity that is unmatched in the industry.

Explore Job Opportunities and Growth

At U.S. Bank, we offer a variety of job opportunities that cater to a range of skills and professional interests. Whether you are looking for a position in finance, technology, customer service, or management, U.S. Bank is hiring talented individuals who are eager to contribute to our mission and grow with us.

Internship Programs

Kickstart your career with U.S. Bank’s internship programs. These opportunities are designed for ambitious students who want to gain hands-on experience and develop essential skills in a real-world setting. Our internships provide a platform to engage with experienced professionals and explore potential career paths within the company.

Benefits and Employment Perks

Choosing a career at U.S. Bank means more than just employment. We offer comprehensive benefits designed to enhance your life and well-being. From health and wellness programs to retirement plans, we ensure our team members are supported both personally and professionally.

Our Commitment to Diversity and Inclusion

Diversity and inclusion are at the core of our values at U.S. Bank. We are dedicated to creating an environment where all employees feel valued and included. Our diversity training programs are part of our commitment to an inclusive workplace, where everyone can thrive.

Leadership and Professional Development

Leadership at U.S. Bank is about more than guiding teams – it's about inspiring them. We invest in leadership training and professional development programs that help our employees become the best in their fields. By fostering a culture of learning and growth, we prepare our team members to take on new challenges and leadership roles.

Networking and Innovation

Networking at U.S. Bank goes hand in hand with innovation. Our employees are encouraged to connect with colleagues and industry leaders through various networking events and professional groups. This collaborative environment fuels innovation and allows us to stay ahead in a competitive industry.

Join Our Team

Are you ready to take the next step in your career? Explore the open positions at U.S. Bank and find where your skills and passions align with our needs. Prepare your resume, sharpen your interview skills, and get ready to join a team where your career can flourish.

Stay Connected with U.S. Bank Careers

Keep up to date with the latest career tips, insider perspectives, and industry-leading insights from U.S. Bank. Personalize your subscription to receive job alerts and updates that match your career interests.

Search U.S. Bank Jobs

Discover the exciting and rewarding career opportunities waiting for you at U.S. Bank. Search and apply for jobs that match your skills and interests. Join us and be part of a team that values growth, leadership, and innovation.

READ CAREERS BLOG

Stay ahead in your career with U.S. Bank – where your growth is our priority.
Learn more about U.S. Bank
Size
68,796 employees
Market Cap
$66.2 billion
Industry
Net Income
$4.9 billion
5 Year Trend
+0.5%
NASDAQ

Similar Jobs

More Jobs at U.S. Bank

More Information Technology Jobs

Find similar Information Security Third-Party Risk Analyst jobs: