The Cybersecurity Analyst I/II/III supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ecosystem. The role includes vendor cybersecurity assessments, continuous cyber monitoring, Security Architecture Reviews (SARs), AI risk assessments, emerging third-party threat analysis, remediation support, and development of meaningful risk reporting and metrics. This role partners with Third-Party Management (TPM), Legal, Privacy, Enterprise Technology, Procurement, and Business Unit stakeholders to provide practical, risk-based cybersecurity guidance and strengthen third-party cyber resilience. The position may be filled at the I, II, or III level based on the selected candidate's relevant experience, hands-on technical depth, demonstrated judgment, level of accountability, complexity and scale of prior vendor ecosystems, and experience operating in regulated environments. Candidates with more advanced experience are encouraged to apply; title, level, responsibilities, and compensation may be adjusted accordingly.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Entry Level