Third-Party Risk Management 1

Millennium Management LLC

$175K — $250K *
Business Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of hands-on third-party risk management experience.
  • Bachelor's degree in Computer Science, Cybersecurity, or a related field or equivalent work experience.
  • Experience with vendor security risk assessments, familiar with frameworks like NIST CSF and SOC 2.
  • Strong analytical skills to interpret penetration test reports and data flow diagrams.
  • Excellent communication skills for articulating technical findings to stakeholders.
  • Ability to manage multiple assessments in a fast-paced environment.
  • Familiarity with the secure use and governance of AI tools and infrastructure.

Responsibilities

  • Conduct security risk assessments for vendors and subprocessor dependencies.
  • Evaluate business impact of vulnerabilities and recommend remediation measures.
  • Prepare comprehensive risk assessment reports and maintain accurate records.
  • Communicate findings to technical teams and senior leaders effectively.
  • Track remediation of identified security issues and ensure follow-up actions.
  • Collaborate with vendor management and legal teams to enforce security in contracts.
  • Monitor existing vendors for security incidents and assess corrective actions.

Benefits

  • Comprehensive health insurance plan.
  • Flexible work hours and potential remote work options.
  • Professional development opportunities.
  • Discretionary performance bonuses and competitive compensation package.
Full Job Description
Third-Party Risk Management 1

What You'll Do
  • Conduct security risk assessments for prospective and existing vendors, including questionnaire reviews, evidence validation, technical discussions, and identification of fourth-party and subprocessor dependencies.
  • Evaluate the materiality and business impact of findings, identify compensating controls, and recommend remediation or risk acceptance based on residual risk.
  • Prepare clear risk assessment reports and maintain accurate third-party risk inventory and assessment records.
  • Communicate findings, recommendations, and implementation requirements to technical teams, business stakeholders, and senior leaders.
  • Track remediation of identified security gaps and follow up on implementation requirements.
  • Partner with vendor management, procurement, legal, and business teams to embed security requirements into vendor contracts and onboarding processes.
  • Monitor existing vendors for security incidents and adverse news, engaging vendors to assess impact, root cause, and corrective actions.
  • Strengthen the third-party risk management program through improvements to methodology, questionnaires, monitoring, reporting, quality assurance, and automation.


What You Bring
  • Experience conducting vendor or third-party security risk assessments, including familiarity with NIST CSF, SOC 2, ISO 27001, CIS Controls, SIG, and CAIQ.
  • Ability to analyze penetration-test reports and architecture or data-flow diagrams to assess vulnerability severity, connectivity, trust boundaries, and associated security risks.
  • Strong critical thinking and risk judgment, with the ability to assess materiality, business impact, and compensating controls.
  • Excellent written and verbal communication skills, with the ability to translate technical issues into clear risk and business implications for stakeholders.
  • Ability to manage multiple assessments and deadlines effectively in a fast-paced, high-stakes environment.
  • Bachelor's degree or higher in Computer Science, Computer Engineering, Cybersecurity, Information Security, or a related field, or commensurate work experience.
  • Five or more years of hands-on third-party risk management experience: relevant security certifications, such as CTPRP, CTPRA, CISA, or CISSP, are preferred.
  • Experience with the secure use, deployment, and governance of AI models, tools, and supporting infrastructure, including GPUs and inferencing workloads; familiarity with on-premises and cloud infrastructure, TPRM platforms, reporting and automation tools, and Windows, Linux, and macOS environments is preferred.


Salary Range
Millennium offers a total compensation package which includes a base salary, discretionary performance bonus, and comprehensive benefits. The estimated base salary range for this position is $175,000 to $250,000, which is specific to New York and may change in the future. When finalizing an offer, we take into consideration an individual's experience level and the qualifications they bring to the role to formulate a competitive total compensation package

Similar Jobs

More Jobs at Millennium Management LLC

More Business Services Jobs

  • Vice President, Sales & Service
    $150K — $250K + $30K bonus + equity, medical, dental, vision, life, std/ltd *
    Southern Dock Products / DuraServ
    Memphis, TN 38109 (Shelby County)
  • Vice President, Sales & Service
    $150K — $250K + $30K bonus + equity, medical, dental, vision, life, std/ltd, auto allowance, *
    Just Rite Equipment / DuraServ
    South Windsor, CT 06074 (Capitol County)
  • Vice President, Service & Sales
    $200K — $500K++ $30K bonus + equity, medical, dental, vision, life, std/ltd, auto allowance, *
    Casco Dock & Door / DuraServ
    West Sacramento, CA 95691 (Yolo County)
  • Director of Business Development
    $130K — $150K *
    Warren Whitney
    Richmond, VA 23226 (Henrico County)
  • Risk Manager
    $130K — $140K *
    Cal State Long Beach
    Long Beach, CA 90802 (Los Angeles County)

Find similar Third-Party Risk Management 1 jobs: