A

Senior Analyst, Third-Party Risk Management (TPRM)

Job Description - Senior Analyst, Third-Party Risk Management (TPRM)

Description

The Team


The Senior Analyst Third Party Risk & Security, a member of the Information Security – Governance Risk and Compliance (GRC) team, focuses on monitoring operations relating to Third-Party Risk Management (TPRM) including managing risk assessments, and ensuring adherence to regulatory and internal security standards. The incumbent evaluates and monitors vendor security practices, conducting risk assessments, and cross-functional collaboration with business units and IT to ensure proficient cybersecurity posture. The incumbent assists in the oversight and maintenance of program standards and process documents related to TPRM.


 



Responsibilities

What You Can Offer Us



  • Oversee onboarding of new TPRM assessments, including assignment of third-party vendors to team members.

  • Initiate and review risk assessments of current and prospective third-party relationships in alignment with company, legal and industry regulations, and guidelines.

  • Partner and build relationships with internal business units to inventory third-party environments, including but not limited to systems, applications, storage, and services.

  • Manage and maintain the TPRM platform including integrations into internal processes including supply chain, vendor compliance etc.

  • Supports in regular reporting to Information Security and AI Steering Committee leadership.

  • Ensures inventory completeness for third-party vendors needing to be tracked through the TPRM process.

  • Partner with Cybersecurity Operations team on identifying and remediating third party vulnerabilities.

  • Other duties as assigned.



Qualifications

What You Need to Succeed



  • Bachelor’s degree or equivalent work experience required.

  • A minimum of 4 years of TPRM or risk-related experience required; 3-5 years of industry or related experience preferred.

  • Knowledge of the 3rd party or vendor management lifecycle including related controls, processes and risk exposure (e.g., 3rd party identification, selection, management, termination), and applicable laws and regulations.

  • Strong knowledge and experience with operational risk management, covering the full lifecycle of activities, including risk identification, assessment, mitigation, prioritization, monitoring, and reporting.

  • Understanding of related regulatory requirements and expectations related to TPRM.

  • Strong organization, planning, and project management skills; ability to prioritize tasks for self and team to meet requirements and deadlines.

  • Ability to work with different functional groups and levels of employees to effectively and professionally achieve results.

  • Excellent written and verbal communication skills and ability to interact well with internal and external parties. 

  • Ability to work individually and in team settings with cross-functional teams.

  • Strong computer skills, including Microsoft Office suite and Oracle.

  • In-depth knowledge of access, security, and risk assessment methods and technologies.

  • Knowledge of Information Security Standards (ISO 27001/27002, ITIL, etc.).

  • Knowledge of Data Privacy and Compliance Regulations (MA CMR 201, HIPPA, Red Flag, etc.).



Original job Senior Analyst, Third-Party Risk Management (TPRM) posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

Similar Senior Analyst, Third-Party Risk Management Jobs in the US

GrabJobs is the no1 job portal in the US, connecting you to thousands of jobs fast! Find the best jobs in the US, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.