Information Security Third-Party Risk Analyst

U.S. BankMinneapolis, MN
$98,175 - $115,500Hybrid

About The Position

This position is not eligible for visa sponsorship. Location expectations: This role requires working from a U.S. Bank location three (3) or more days per week. US Bank is seeking an Information Security Third-Party Risk Analyst to join our Information Security organization, supporting third-party risk management and vendor security oversight. This role is responsible for evaluating and managing information security risk across external vendors, ensuring appropriate controls are in place, and driving remediation of identified risks. This person will perform hands-on third-party security risk assessments, analyze vendor controls and security posture, and partner with internal stakeholders and external vendors to reduce risk exposure. They will play a key role in identifying control gaps, tracking remediation, supporting contract security reviews, and contributing to ongoing risk monitoring, reporting, and audit activities.

Requirements

  • 5+ years of experience in information security
  • 5+ years of experience in third-party risk management, vendor risk, or risk analysis
  • Hands-on experience conducting third-party/vendor information security risk assessments
  • Strong understanding of information security controls and risk concepts
  • Experience identifying control gaps and evaluating remediation actions
  • Experience with contract review or redlining related to security requirements
  • Ability to clearly communicate risk to both technical and non-technical stakeholders

Nice To Haves

  • Familiarity with security frameworks (e.g., NIST 800-53)
  • Experience reviewing SOC 2 Type II reports
  • Experience with continuous monitoring tools (e.g., BitSight, Archer)
  • Exposure to third-party security incident response and post-event analysis
  • Broader technical cybersecurity background
  • Exposure to emerging risks (e.g., AI, new technologies)

Responsibilities

  • Perform information security risk assessments on third-party vendors (new and existing)
  • Review and analyze vendor security questionnaires, control responses, and supporting documentation
  • Identify security gaps, control deficiencies, and non-compliance issues
  • Document and track risk findings and remediation efforts through resolution
  • Evaluate vendor remediation plans and compensating controls
  • Partner with business stakeholders and third parties to explain risks and recommend mitigation strategies
  • Support contract review and redlining with a focus on information security requirements
  • Conduct continuous monitoring of vendor security posture
  • Review and assess third-party security incidents and perform post-event analysis
  • Contribute to monthly and quarterly reporting, metrics, and trend analysis
  • Support audit activities, control testing, and quality assurance efforts
  • Collaborate across information security, risk, and compliance teams

Benefits

  • Healthcare (medical, dental, vision)
  • Basic term and optional term life insurance
  • Short-term and long-term disability
  • Pregnancy disability and parental leave
  • 401(k) and employer-funded retirement plan
  • Paid vacation (from two to five weeks depending on salary grade and tenure)
  • Up to 11 paid holiday opportunities
  • Adoption assistance
  • Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service