Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Momentive Software

Senior Third-Party Risk Management Analyst

Momentive Software

. Maintain Momentive's global inventory of third-party providers, applications, and services from onboarding through termination .

Posted 10/7/2026full-timeRemote • United StatesSeniorWebsite

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityGoogle Cloud Platform

About the role

Key responsibilities & impact
  • Maintain Momentive's global inventory of third-party providers, applications, and services from onboarding through termination
  • Lead vendor cybersecurity assessments and coordinate with Cybersecurity Engineering, Legal, and business owners
  • Assess vendor maturity using NIST CSF, CIS, CMMC, GDPR, PCI DSS, SOC 2, and other frameworks
  • Oversee vendor SLAs, RPO/RTO commitments, breach notification requirements, and cybersecurity insurance documentation
  • Document findings, recommendations, and remediation plans for vendor assessments
  • Liaise with internal and external auditors on vendor-related controls and evidence collection
  • Provide evidence, documentation, and control validation for SOC 2 Type II and PCI DSS assessments
  • Maintain audit-ready documentation, including policies, standards, procedures, and risk treatment plans
  • Track vendor exceptions and compensating controls
  • Support vulnerability notifications to clients who manage their own cybersecurity controls
  • Provide consultative guidance to clients on risk impact, remediation expectations, and cybersecurity practices
  • Maintain documentation and metrics for client notifications, follow-up actions, and closure
  • Improve the ISMS by aligning vendor risk processes with company policies, standards, and procedures
  • Provide input on control selection, risk treatment plans, and cybersecurity control effectiveness metrics
  • Monitor emerging threats, regulatory changes, and industry trends affecting third-party risk
  • Support disaster recovery/business continuity planning related to vendor dependencies and resiliency
  • Coordinate with Legal, Cybersecurity, and leadership on vendor-related risk reduction strategies
  • Promote enterprise-wide cybersecurity culture through outreach, training, and awareness activities
  • Support internal and external stakeholders with professional, consultative service
  • Mentor team members and contribute to internal training materials and documentation

Requirements

What you’ll need
  • 5+ years of experience in cybersecurity, risk management, audit, or compliance
  • Deep understanding of PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST
  • Experience evaluating legacy and modern cloud technologies, including AWS, GCP, and Azure
  • Strong knowledge of APIs, application cybersecurity, encryption, endpoint, and network cybersecurity concepts
  • Familiarity with SIEM, IDS, log management, vulnerability management, and threat intelligence
  • Ability to assess vendor controls, map them to frameworks, and articulate risk to non-technical stakeholders
  • Strong project management, multitasking, and organizational skills
  • Excellent written and verbal communication skills
  • Experience supporting SOC 2 Type II and PCI DSS audits preferred
  • Experience with EGRC/ITGRC platforms such as Jira Service Manager GRC, Archer, OneTrust, and LogicGate preferred
  • Certifications such as CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP preferred
  • Eligibility to work in the United States without sponsorship
  • Minimum age of 18

Benefits

Comp & perks
  • Medical, Dental & Vision Benefits
  • 401(k) Savings Plan with Company Match
  • Flexible Planned Paid Time Off
  • Generous Sick Leave
  • Inclusive & Welcoming Environment
  • Purpose-Driven Culture
  • Work-Life Balance
  • Commitment to Community Involvement
  • Employer-Paid Parental Leave
  • Employer-Paid Short-Term Disability
  • Remote Work Flexibility