Vendor Security Analyst

Hogan Lovells

$120K — $146K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in information security risk identification and assessment.
  • Familiarity with Standardized Information Gathering (SIG) questionnaires.
  • Experience with penetration testing and vulnerability testing.
  • Knowledge of SOC 1 and 2, Type 2 reports.
  • ISO 27001 certification experience preferred.
  • Bachelor's degree in a related field preferred.
  • Understanding of systems, networks, and security architecture best practices.

Responsibilities

  • Evaluate third-party risk and manage vendor relationships.
  • Assess vendor responses to security questionnaires.
  • Recommend strategies to mitigate vendor risk.
  • Maintain a repository of vendor risk artifacts and manage certification compliance.
  • Conduct on-site audits of high-risk vendors focusing on security controls.
  • Support the firm's Responsible Business initiatives and community commitments.
  • Take on additional responsibilities as business needs evolve.

Benefits

  • Medical, dental, and vision insurance.
  • 401(k) retirement plan.
  • Paid time off including vacation and holidays.
Full Job Description
The Vendor Security Analyst performs evaluation of third party and vendor engagements to identify and manage vendor risk which may include completion of risk assessments. They will also conduct the technical security reviews of our suppliers and partners. This role reports to the Head of Information Risk.

KEY RESPONSIBILITIES

  • Evaluate third party risk and steer vendor relationships
  • Evaluate vendor responses to security questionnaires
  • Make recommendations on ways to mitigate vendor risk
  • Maintain vendor risk repository of artifacts including regular third party vendor certifications and assign risk scores to firm suppliers and partners
  • Conduct onsite audits of high risk vendors reviewing security and controls
  • Actively support and engage in the firm's Responsible Business initiatives, contributing to our commitments to our people, clients, communities, and the environment.
  • Provide support on emerging priorities and undertake additional responsibilities as needed to meet evolving business requirements.


QUALIFICATIONS

EDUCATION & EXPERIENCE

  • Strong and demonstration information security risk identification (including Cloud services), assessment, and risk ranking experience
  • Working experience with the following documents used in a risk assessment preferred:
  • SIG (Standardized Information Gathering) questionnaire
  • Penetration test
  • Vulnerability test
  • SOC (Service Organization Control) 1 and 2, Type 2
  • ISO 27001
  • Bachelor's degree preferred.


SKILLS & ABILITIES

  • Possess a sufficient understanding of technical concepts including systems, networks, and security architecture best practices in order to effectively evaluate risk and assess the effectiveness of controls
  • Confident to make independent decisions
  • Ability to explain technical concepts in layman terms
  • Ability to interact effectively and influence external vendors
  • Keen attention to detail and accuracy in order to analyze documents
  • Broad knowledge of risk management, vulnerability management, and third party risk


WORK SCHEDULES/HOURS EXPECTATION

Core hours are generally Monday through Friday, 9:00 a.m. to 5:30 p.m., including an unpaid meal period. This position is based on a standard 37.5-hour workweek. Additional or adjusted hours may be required to meet business needs and must be worked in accordance with applicable overtime requirements and firm policies.

In Washington, D.C., the expected base salary range for this role is $120,500 to $146,200 per year.

This range reflects a good-faith estimate of pay at the time of posting; the actual compensation offered may vary depending on factors such as the candidate's qualifications. This position is eligible for additional forms of compensation, which may include annual discretionary bonuses. Employees in this role are also eligible for benefits offered by the firm, subject to applicable plan terms and conditions, which currently include medical, dental, and vision insurance; a 401(k)-retirement plan; and paid time off. Please review this link for more information regarding employee benefits in the United States.

This job description sets forth the responsibilities of this position and may be changed from time to time as shall be determined.

Similar Jobs

More Jobs at Hogan Lovells

More Information Technology Jobs

Find similar Vendor Security Analyst jobs: