7 third party risk analyst jobs at 6 companies in Valhalla, NY

3w
Save
Mark Applied
Hide
Senior Analyst, Third-Party Risk Management (TPRM)
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yr RemoteFull Time
DoorDash
DoorDashNYSE: DASH: Technology enabling local on-demand delivery and commerce.
7+ YOERequires 7+ years in security-focused TPRM, a bachelor's or master's degree, risk assessment and remediation experience, cloud and AI vendor expertise, GRC framework experience, and excellent communication skills.
AWS, Azure, GCP, Covey
1w
Save
Mark Applied
Hide
Third Party Information Security Analyst
New York City, New York, United States
$90k-$125k/yr HybridFull Time
Sumitomo Mitsui Trust Bank (U.S.A.) Limited
Sumitomo Mitsui Trust Bank (U.S.A.) Limited: Japanese trust bank serving retail, corporate, institutional, and global clients through banking, trust, real-estate, and asset-management services.
3+ YOERequires 3+ years in risk assessment and third-party risk management, TPRM platform experience, security documentation assessment, knowledge of NIST, ISO 27001, and Cyber Risk Institute frameworks, plus strong Microsoft Office, communication, and analytical skills.
Microsoft Office, Prevalent, NIST Cybersecurity Framework, ISO/IEC 27001, Cyber Risk Institute Profile, SOC 2
1mo
Save
Mark Applied
Hide
Senior Analyst, Third-Party Risk Management (TPRM)
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yr RemoteFull Time
DoorDash
DoorDashNYSE: DASH: Technology enabling local on-demand delivery and commerce.
7+ YOE7+ years in security-focused TPRM, experience with vendor risk assessments, cloud/SaaS/AI security reviews, program building, audits, and remediation tracking; Bachelor's or Master's degree in related field.
CAIQ, SIG, SOC 2 Type 2, Penetration Test, NIST, ISO 27001, PCI-DSS, AWS, Azure, GCP, Covey Scout
2w
Save
Mark Applied
Hide
Security Analyst, Third-Party Ecosystem Risk Management
New York City or Seattle or Raleigh or San Francisco or Washington or London or Amsterdam or United States or Canada or United Kingdom or Europe
$119k-$176k/yr HybridFull Time
Plaid
Plaid: Fintech data network connecting consumers’ financial accounts to apps and services.
4+ YOERequires 4+ years in vendor risk management, third-party security assessments, risk lifecycle management, security frameworks, program maturation, documentation, communication, and AI-assisted tooling.
SOC 2, ISO 27001, NIST CSF, OneTrust, ProcessUnity, Whistic, SecurityScorecard
1mo
Save
Mark Applied
Hide
Cybersecurity Risk Analyst II
New York, New York, United States
$119k-$140k/yr OnsiteFull Time
CLEAR
CLEARNYSE: YOU: Provides biometric identity verification and expedited travel security services.
3+ YOE3-5+ years in cybersecurity risk management; experience with third-party risk, risk quantification (FAIR a plus), strong communication, partnering with engineering, and building risk metrics and dashboards.
FAIR
3mo
Save
Mark Applied
Hide
Senior Catastrophe Risk Analyst
Chicago or Jersey City or Marlton or Tampa
OnsiteFull Time
SageSure
SageSure: Private managing general underwriter providing catastrophe-exposed home, flood, and commercial insurance for homeowners and small businesses.
5+ YOESenior catastrophe risk analyst with advanced degree, 5+ years in catastrophe modeling or related field; strong coding (Python/SQL), GIS, and data analysis; experience with third-party models (RMS/Verisk/AIR); excellent communication and cross-functional collaboration.
Python, R, SQL, GIS, QGIS, ArcGIS, RMS, Verisk, AIR
1mo
Save
Mark Applied
Hide
Senior Vendor Risk Analyst - Remote
Draper or Eden Prairie or Washington or New York City
$73k-$130k/yr RemoteFull Time
UnitedHealth Group
UnitedHealth GroupNYSE: UNH: Provides health insurance and technology-enabled health care services.
5+ YOE5+ years assessing third-party/vendor risk, familiarity with vendor risk management frameworks, ability to analyze financial statements, knowledge of ISO 27001, SIG, SOC 2; eGRC Archer experience preferred.
eGRC Archer, ISO 27001, SIG, SOC 2