Lead Third-Party Cyber Risk Analyst

Posted 4 Days Ago
Be an Early Applicant
Frisco, TX
Hybrid
104K-167K Annually
Senior level
Fintech • Financial Services
Together, we fight to ensure a more secure future for millions more Americans.
The Role
The Lead Third-Party Cyber Risk Analyst will manage third-party risk assessments within the cybersecurity program, identify and document information security risks, and collaborate with internal teams and external partners to implement remediation actions. Key responsibilities include risk assessment facilitation, stakeholder communication, and enhancement of vendor management processes.
Summary Generated by Built In

Lead Third-Party Cyber Risk Analyst

 

TIAA is seeking a Lead Third-Party Cyber Risk Analyst to support their Enterprise Cybersecurity program. This role will conduct and evaluate third party risk assessments covering cyber security, identify information security risks, document issues, identify remediation action plans, and collaborate with internal partners and third parties to mitigate the issues. This is a lead role within the team and will be assigned special projects within Cybersecurity or Third-Party Cyber Risk Management as well as provide Quality Assurance of assessments within the team.

 

This role will be a key member of our Governance & Risk organization within our Cybersecurity organization. The ideal candidate will have experience within the Cyber Security field, with a focus on Governance, Risk & Compliance. In addition, possess an in-depth understanding of Third-Party Cyber Risk Management practices and experience providing guidance to internal partners. This role requires strong communications skills, both oral and written, with excellent interpersonal, team and organizational skills. The ideal candidate must be able to execute small projects by understanding a problem statement, identifying solutions, and completing the work as part of our Agile team.

 

This role works under limited supervision and will also support the overall program and process execution of the vendor risk management team and to drive improvements to minimize risk exposure to the organization.


Key Responsibilities and Duties

  • Exhibits a deep understanding of Third-Party Cyber Risk Management practices and provides guidance to internal partners as required.
  • Complete Third-Party Cyber Risk assessments to identify risks and validate implemented security controls to mitigate those risks.
  • Develop and maintain effective relationships with both internal/external stakeholders.
  • Collaborate with internal teams and third-party resources to communicate gaps identified through the assessment and provides recommendations to close the gaps.
  • Document and create issues in the Issue Management system and collaborate with external partners to drive remediation of the risks.
  • Demonstrate effective communication skills to collaborate with representatives of the Lines- of-Business, technology areas, risk partners, and vendors in performing their role.
  • Demonstrates ability to identify issues, develop plans to resolve, and understands how to escalate when needed.
  • Collaborate with technology and risk partners to create remediation action plans to mitigate cybersecurity risks and govern action plans through until completion.
  • Apply critical thinking to situations where incomplete / imperfect information is available.
  • Facilitate implementation of the Cyber organization’s global strategies and initiatives to enhance Information Technology plans, operations, and procedures.
  • Collaborate across extended teams to identify optimization opportunities and drive efficiencies within the vendor engagement and vendor due diligence processes.
  • Maintain and enhance documented policies and procedures.

Educational Requirements

  • University (Degree) Preferred

Work Experience

  • 5+ Years Required; 7+ Years Preferred

Physical Requirements

  • Physical Requirements: Sedentary Work


Career Level
8IC

Qualifications:

Required:

  • Minimum of 5+ years’ experience working in a similar Third-Party Cyber Risk Management role. Possess direct experience with risk assessment methodologies, risk mitigation strategies, and risk reporting.
  • Minimum of 5+ years’ experience interfacing and communicating (both verbal and written) with both technical and non-technical stakeholders on articulating risks, mitigation plans, and compliance requirements.
  • Possess the ability to break down strategic problems, analyze data, develop a remediation approach, communicate recommendations, and drive work effort to successful completion.
  • Knowledge of the NIST Risk Management Framework (RMF) and security controls. Must understand the risk management process, risk mitigation, and risk tracking.

Preferred:

  • Minimum of 7+ years of experience working in a similar role.
  • Knowledge of new/emerging practices within cybersecurity and controls.
  • Possess technical background and knowledge to help identify tools and technologies that can support our Third-Party Risk Management program.
  • Experience collaborating with Agile teams leveraging industry standard tools and processes.
  • Possess Cyber Security certifications.

#LI-VR1

Related Skills

Accountability, Adaptability, Business Continuity Planning, Cloud Computing Security, Collaboration, Communication, Compliance, Consultative Communication, Cybersecurity, Detail-Oriented, General Risk Management, Network Security, Prioritizes Effectively

Anticipated Posting End Date:

2025-01-18

Base Pay Range: $104,100/yr. - $167,100/yr.

Actual base salary may vary based upon, but not limited to, relevant experience, time in role, base salary of internal peers, prior performance, business sector, and geographic location. In addition to base salary, the competitive compensation package may include, depending on the role, participation in an incentive program linked to performance (for example, annual discretionary incentive programs, non-annual sales incentive plans, or other non-annual incentive plans). 

_____________________________________________________________________________________________________

Company Overview

Every worker deserves a secure retirement. For more than 100 years, TIAA has delivered it for millions of people. Founded to help educators retire with dignity, today weʼre a market-leading retirement company fueled by world-class asset management. But weʼre not just another legacy financial services firm. Weʼre fighting harder than ever before for our clients and the many Americans who need us.

Benefits and Total Rewards

The organization is committed to making financial well-being possible for its clients, and is equally committed to the well-being of our associates. That’s why we offer a comprehensive Total Rewards package designed to make a positive difference in the lives of our associates and their loved ones. Our benefits include a superior retirement program and highly competitive health, wellness and work life offerings that can help you achieve and maintain your best possible physical, emotional and financial well-being. To learn more about your benefits, please review our Benefits Summary.

Equal Opportunity

We are an Equal Opportunity/Affirmative Action Employer. We consider all qualified applicants for employment regardless of age, race, color, national origin, sex, religion, veteran status, disability, sexual orientation, gender identity, or any other protected status.

Read more about the Equal Opportunity Law here.

Accessibility Support

TIAA offers support for those who need assistance with our online application process to provide an equal employment opportunity to all job seekers, including individuals with disabilities. 

If you are a U.S. applicant and desire a reasonable accommodation to complete a job application please use one of the below options to contact our accessibility support team: 

Phone: (800) 842-2755

Email: [email protected]

Privacy Notices

For Applicants of TIAA, Nuveen and Affiliates residing in US (other than California), click here.

For Applicants of TIAA, Nuveen and Affiliates residing in California, please click here.

For Applicants of Nuveen residing in Europe and APAC, please click here.

The Company
Charlotte, NC
0 Employees
Hybrid Workplace
Year Founded: 1918

What We Do

Every worker deserves a secure retirement. For more than 100 years, weʼve delivered it for millions of people—and weʼre not done yet. Founded to help educators retire with dignity, today weʼre a market-leading retirement company fueled by world-class asset management.

But weʼre not just another legacy financial services firm. Weʼre fighting harder than ever before for our clients and the many Americans who need us.

And weʼre hiring. When you work at TIAA, youʼre making a difference in the lives of our clients. Weʼre always on the lookout for great people to become part of our coalition of champions and are committed to providing equal opportunity across all employment practices as we believe our employees have a right to a diverse and inclusive workplace. Join our team today in the fight to help more people to and through retirement.

Why Work With Us

TIAA provides financial security for millions and offers our employees opportunities to grow in a culture that embraces diversity, innovation, and high performance.

Similar Jobs

Capital One Logo Capital One

Information Security Office (ISO) Product Security Risk Manager - Principal Associate

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
Plano, TX, USA
55000 Employees

PwC Logo PwC

Cybersecurity, Privacy and Forensics - Analytics - Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
Dallas, TX, USA
364000 Employees
84K-202K Annually

PwC Logo PwC

Cybersecurity, Privacy and Forensics - Corporate and Threat Intelligence - Experienced Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
Dallas, TX, USA
364000 Employees
75K-118K Annually

Similar Companies Hiring

Bectran, Inc Thumbnail
Software • Machine Learning • Information Technology • Fintech • Automation • Artificial Intelligence
Schaumburg, IL
51 Employees
Energy CX Thumbnail
Utilities • Professional Services • Greentech • Financial Services • Energy • Consulting • Business Intelligence
Chicago, IL
55 Employees
MassMutual India Thumbnail
Insurance • Information Technology • Fintech • Financial Services • Big Data
Hyderabad, Telangana

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account