About The Position

The Senior Analyst Third Party Risk & Security, a member of the Information Security – Governance Risk and Compliance (GRC) team, focuses on monitoring operations relating to Third-Party Risk Management (TPRM) including managing risk assessments, and ensuring adherence to regulatory and internal security standards. The incumbent evaluates and monitors vendor security practices, conducting risk assessments, and cross-functional collaboration with business units and IT to ensure proficient cybersecurity posture. The incumbent assists in the oversight and maintenance of program standards and process documents related to TPRM.

Requirements

  • Bachelor’s degree or equivalent work experience required.
  • A minimum of 4 years of TPRM or risk-related experience required.
  • Knowledge of the 3rd party or vendor management lifecycle including related controls, processes and risk exposure (e.g., 3rd party identification, selection, management, termination), and applicable laws and regulations.
  • Strong knowledge and experience with operational risk management, covering the full lifecycle of activities, including risk identification, assessment, mitigation, prioritization, monitoring, and reporting.
  • Understanding of related regulatory requirements and expectations related to TPRM.
  • Strong organization, planning, and project management skills; ability to prioritize tasks for self and team to meet requirements and deadlines.
  • Ability to work with different functional groups and levels of employees to effectively and professionally achieve results.
  • Excellent written and verbal communication skills and ability to interact well with internal and external parties.
  • Ability to work individually and in team settings with cross-functional teams.
  • Strong computer skills, including Microsoft Office suite and Oracle.
  • In-depth knowledge of access, security, and risk assessment methods and technologies.
  • Knowledge of Information Security Standards (ISO 27001/27002, ITIL, etc.).
  • Knowledge of Data Privacy and Compliance Regulations (MA CMR 201, HIPPA, Red Flag, etc.).

Nice To Haves

  • 3-5 years of industry or related experience preferred.

Responsibilities

  • Oversee onboarding of new TPRM assessments, including assignment of third-party vendors to team members.
  • Initiate and review risk assessments of current and prospective third-party relationships in alignment with company, legal and industry regulations, and guidelines.
  • Partner and build relationships with internal business units to inventory third-party environments, including but not limited to systems, applications, storage, and services.
  • Manage and maintain the TPRM platform including integrations into internal processes including supply chain, vendor compliance etc.
  • Supports in regular reporting to Information Security and AI Steering Committee leadership.
  • Ensures inventory completeness for third-party vendors needing to be tracked through the TPRM process.
  • Partner with Cybersecurity Operations team on identifying and remediating third party vulnerabilities.
  • Other duties as assigned.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service