Third Party Risk Sr Analyst - Cybersecurity

Citizens Bank

$95K — $123K *
Finance & Insurance
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in Third Party Vendor Assessments
  • Strong understanding of Cyber Security controls
  • Experience with audit and regulatory frameworks including ISO 27001, GLBA, SOX, PCI, HIPAA, and FFIEC
  • Ability to communicate complex security risks to business partners
  • Demonstrated leadership skills in mentoring junior analysts

Responsibilities

  • Manage vendor issues and perform quality assurance for vendor assessments
  • Collaborate with senior management to inform key business decisions
  • Assess vendors' control effectiveness and gather evidence of compliance
  • Contribute to Governance Risk and Compliance program enhancements
  • Conduct thorough risk assessments and develop risk metrics and visualizations
  • Support regulatory exam preparations and remediation efforts
  • Produce comprehensive reports detailing vendor risks for diverse audiences

Benefits

  • Comprehensive medical, dental, and vision coverage
  • Competitive retirement benefits
  • Flexible work arrangements with 1 remote day per week
  • Education reimbursement for career growth
  • Generous paid time off policies that exceed local requirements
  • Wellness programs to support employee health
Full Job Description
Job Description

As the Third Party Risk Sr Analyst, you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships with both business leaders and vendors, while providing robust and challenging insight on business risk and on the adequacy and effectiveness of the test control processes in place. The role holder delivers assessment review and provides opinion on the quality of the vendor control environment as is needed to meet Citizens policies including identifying issues and subsequently assisting the business to agree to any appropriate action plans to mitigate the risk. The Third-Party Vendor Assessment function adds value by providing specific business function assurance on vendors, in relation to customer, financial or reputational risk and bringing momentum to action plans to address risk and leveraging findings and best practice on a bank wide scale.

Primary responsibilities include
  • Collaborating with senior management to influence key decisions.
  • Evaluating third party vendors' control infrastructure effectiveness and obtaining evidence of controls.
  • Applying experience in audit, security and regulatory frameworks including ISO 27001, GLBA, SOX, PCI, HIPPA, States Privacy Regulation and FFIEC.
  • Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or enhancements and tool and technology implementations as applicable.
  • Leading current risk assessments, continual risk assessments, and risk metrics and visualizations.
  • Performing quality assurance on vendor assessment and remediation activities.
  • Working directly with key business leaders to facilitate risk analysis and risk management processes, identifying acceptable levels of risk and establish roles and responsibilities with regards to risk management.
  • Maintaining and monitoring enterprise risk exception process to identify areas of noncompliance.
  • Supporting and participating in regulatory exam preparation and execution as well as remediation where applicable.
  • Coaching and mentoring junior analysts and clearly articulating Third Party Vendor Assessment program goals and objectives to the wider audience.
  • Producing Third Party Vendor Assessment reports that clearly articulate risks in order to speak to a varied audience.
  • Translating security risk and communicating effectively to business partners within the organization.
  • The ability to travel within the United States is required.


Qualifications, Education, Certifications and/or Other Professional Credentials
  • Required Qualifications
    • Previous experience completing Third Party Vendor Assessments.
    • Understanding of Cyber Security controls.


Hours & Work Schedule
  • Hours per Week: 40
  • Work Schedule: Monday - Friday / 4 days in office, 1 day remote
    Pay Transparency
    The salary range for this position is $95,000-$123,000 per year, plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to, the budget, work location, and relevant skills and experience. We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens' paid time off policy exceeds the mandatory, paid sick or paid time-away policy of every local and state jurisdiction in the United States. For an overview of our benefits, visit https://jobs.citizensbank.com/benefits .

Work Authorization:
This role is not eligible for new employer sponsored or current H-1 B visa holders. Applicants, including current OPT, L and other visa holders, must be authorized to work in the U.S. without the need for new employer sponsorship for themselves or their spouses now and in the future.

#LI-CITIZENS2

Similar Jobs

More Jobs at Citizens Bank

More Finance & Insurance Jobs

Find similar Third Party Risk Sr Analyst - Cybersecurity jobs: