FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Third-Party Risk Management Analyst
Momentive Software. Maintain Momentive's global inventory of third-party providers, applications, and services from onboarding through termination .
Tech Stack
Tools & technologiesAWSAzureCloudCyber SecurityGoogle Cloud Platform
About the role
Key responsibilities & impact- Maintain Momentive's global inventory of third-party providers, applications, and services from onboarding through termination
- Lead vendor cybersecurity assessments and coordinate with Cybersecurity Engineering, Legal, and business owners
- Assess vendor maturity using NIST CSF, CIS, CMMC, GDPR, PCI DSS, SOC 2, and other frameworks
- Oversee vendor SLAs, RPO/RTO commitments, breach notification requirements, and cybersecurity insurance documentation
- Document findings, recommendations, and remediation plans for vendor assessments
- Liaise with internal and external auditors on vendor-related controls and evidence collection
- Provide evidence, documentation, and control validation for SOC 2 Type II and PCI DSS assessments
- Maintain audit-ready documentation, including policies, standards, procedures, and risk treatment plans
- Track vendor exceptions and compensating controls
- Support vulnerability notifications to clients who manage their own cybersecurity controls
- Provide consultative guidance to clients on risk impact, remediation expectations, and cybersecurity practices
- Maintain documentation and metrics for client notifications, follow-up actions, and closure
- Improve the ISMS by aligning vendor risk processes with company policies, standards, and procedures
- Provide input on control selection, risk treatment plans, and cybersecurity control effectiveness metrics
- Monitor emerging threats, regulatory changes, and industry trends affecting third-party risk
- Support disaster recovery/business continuity planning related to vendor dependencies and resiliency
- Coordinate with Legal, Cybersecurity, and leadership on vendor-related risk reduction strategies
- Promote enterprise-wide cybersecurity culture through outreach, training, and awareness activities
- Support internal and external stakeholders with professional, consultative service
- Mentor team members and contribute to internal training materials and documentation
Requirements
What you’ll need- 5+ years of experience in cybersecurity, risk management, audit, or compliance
- Deep understanding of PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST
- Experience evaluating legacy and modern cloud technologies, including AWS, GCP, and Azure
- Strong knowledge of APIs, application cybersecurity, encryption, endpoint, and network cybersecurity concepts
- Familiarity with SIEM, IDS, log management, vulnerability management, and threat intelligence
- Ability to assess vendor controls, map them to frameworks, and articulate risk to non-technical stakeholders
- Strong project management, multitasking, and organizational skills
- Excellent written and verbal communication skills
- Experience supporting SOC 2 Type II and PCI DSS audits preferred
- Experience with EGRC/ITGRC platforms such as Jira Service Manager GRC, Archer, OneTrust, and LogicGate preferred
- Certifications such as CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP preferred
- Eligibility to work in the United States without sponsorship
- Minimum age of 18
Benefits
Comp & perks- Medical, Dental & Vision Benefits
- 401(k) Savings Plan with Company Match
- Flexible Planned Paid Time Off
- Generous Sick Leave
- Inclusive & Welcoming Environment
- Purpose-Driven Culture
- Work-Life Balance
- Commitment to Community Involvement
- Employer-Paid Parental Leave
- Employer-Paid Short-Term Disability
- Remote Work Flexibility