Senior Information Security Risk Analyst
Core
Lead end-to-end third-party solution risk assessments and vendor security reviews across the vendor lifecycle, evaluating security programs, control effectiveness, and governance for SaaS platforms and cloud solutions.
Role type
Senior IC information security risk analyst (third-party risk)
Builds
Risk-informed decisions on vendor onboarding, ongoing monitoring, and reassessments to protect business data and systems.
Domain
Insurance industry + cybersecurity/third-party risk management
Required skills
vendor security posture evaluation, cloud security assessment (AWS, Azure, SaaS, PaaS), data flow and classification analysis, IAM/SSO/federation knowledge, interpretation of SOC 1/SOC 2/ISO certifications, risk-based decision-making, mitigation strategy recommendation, stakeholder partnership
Preferred skills
third-party risk management experience, IT risk/audit/incident response exposure, professional skepticism, independent priority management
Technologies
AWS, Azure, Cloud, IAM, SSO, PaaS, APIs
Responsibilities
Lead end-to-end third-party solution risk assessments and vendor security reviews across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, and reassessments. Evaluate vendor security programs, control effectiveness, and governance, as well as the specific solution being implemented, including architecture, data flows, and integration points. Identify and communicate inherent and residual cyber risks related to data protection, privacy, IAM, privileged access, system connectivity, and external attack surface exposure. Review and interpret security documentation such as SOC 1/SOC 2 reports, ISO 27001 certifications, audit reports, architecture diagrams, data flow diagrams, and technical configurations. Recommend practical risk mitigation strategies, including compensating controls, secure design changes, and contractual safeguards to support risk-informed decisions. Partner with business, technology, procurement, and legal teams to support risk acceptance, exception management, and third-party risk governance.
Seniority
Senior, hands-on IC