About The Position

The Third-Party Risk Management (TPRM) Analyst serves as a core member of Momentive Software's Cybersecurity, Risk & Compliance organization. This role is responsible for maintaining and maturing Momentive's enterprise-wide third-party risk program, ensuring that all vendors, platforms, and service providers meet the Firm's cybersecurity, privacy, resiliency, and regulatory requirements. The Analyst partners closely with Client Success, Cybersecurity Engineering, TVM, Legal, Procurement, Product, and the CISO to evaluate vendor risk, maintain continuous oversight of third-party controls, and support Momentive's compliance obligations — including SOC 2 Type II and PCI DSS. The role also supports TVM notifications to clients who manage their own cybersecurity posture, ensuring clear, accurate, and timely communication of vulnerabilities and remediation expectations. This position requires strong analytical capability, deep familiarity with cybersecurity frameworks, and the ability to translate complex risk issues into actionable guidance for business and technical stakeholders.

Requirements

  • 5+ years of experience in cybersecurity, risk management, audit, or compliance.
  • Deep understanding of regulatory requirements including PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST.
  • Experience evaluating both legacy and modern cloud technologies (AWS, GCP, Azure).
  • Strong knowledge of APIs, application cybersecurity, encryption, endpoint, and network cybersecurity concepts.
  • Familiarity with SIEM, IDS, log management, vulnerability management, and threat intelligence.
  • Ability to assess vendor controls, map them to frameworks, and articulate risk to non-technical stakeholders.
  • Strong project management, multitasking, and organizational skills.
  • Excellent written and verbal communication skills.

Nice To Haves

  • Experience supporting SOC 2 Type II and PCI DSS audits.
  • Experience with EGRC/ITGRC platforms (e.g., Jira Service Manager GRC, Archer, OneTrust, LogicGate).
  • Certifications such as CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP.

Responsibilities

  • Maintain Momentive's global inventory of third-party providers, applications, and services from onboarding through termination.
  • Lead vendor cybersecurity assessments, coordinating with Cybersecurity Engineering, Legal, and business owners to evaluate risk and required controls.
  • Assess vendor maturity using NIST CSF, CIS, CMMC, GDPR, PCI DSS, SOC 2, and other frameworks.
  • Oversee vendor SLAs, RPO/RTO commitments, breach notification requirements, and cybersecurity insurance documentation.
  • Ensure thorough documentation of findings, recommendations, and remediation plans for all vendor assessments.
  • Serve as a liaison to internal and external auditors for vendor-related controls and evidence collection.
  • Provide evidence, documentation, and control validation related to third-party dependencies for Momentive's SOC 2 Type II and PCI DSS assessments.
  • Ensure vendor controls align with Momentive's ISMS, contractual obligations, and certification requirements.
  • Partner with the GRC team to maintain audit-ready documentation, including policies, standards, procedures, and risk treatment plans.
  • Track vendor exceptions and compensating controls, ensuring audit defensibility and continuous improvement.
  • Collaborate with the Threat & Vulnerability Management (TVM) team to support vulnerability notifications to clients who manage their own cybersecurity controls.
  • Ensure communications are accurate, timely, and aligned with Momentive's contractual commitments and industry best practices.
  • Provide consultative guidance to clients regarding risk impact, remediation expectations, and recommended cybersecurity practices.
  • Maintain documentation and metrics related to client notifications, follow-up actions, and closure.
  • Contribute to the continual improvement of Momentive's ISMS by aligning vendor risk processes with Firm policies, standards, and procedures.
  • Provide input on control selection, risk treatment plans, and metrics used to monitor the effectiveness of Momentive's cybersecurity controls.
  • Maintain situational awareness of emerging threats, regulatory changes, and industry trends affecting third-party risk.
  • Support DR/BCP planning as it relates to vendor dependencies and resiliency requirements.
  • Act as a key point of contact when business units identify vendor-related risk; coordinate with Legal, Cybersecurity, and leadership on risk reduction strategies.
  • Promote a positive, enterprise-wide cybersecurity culture through outreach, training, and awareness activities.
  • Provide exemplary service to internal and external stakeholders, demonstrating professionalism, empathy, and expertise.
  • Mentor team members and contribute to the development of internal training materials and documentation.

Benefits

  • Medical, Dental & Vision Benefits
  • 401(k) Savings Plan with Company Match
  • Flexible Planned Paid Time Off
  • Generous Sick Leave
  • Inclusive & Welcoming Environment
  • Purpose-Driven Culture
  • Work-Life Balance
  • Commitment to Community Involvement
  • Employer-Paid Parental Leave
  • Employer-Paid Short-Term Disability
  • Remote Work Flexibility
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service