Third Party Information Security Analyst

SUMITOMO MITSUI TRUST BANK, LIMITEDNew York, NY
$90,000 - $125,000Hybrid

About The Position

The Third Party Information Security Analyst supports the Bank’s Third Party Risk Management function by focusing on assessing and monitoring information security risks associated with 3rd, 4th, Nth parties. This role assists with vendor due diligence, security reviews, information security risk assessments, and ongoing monitoring activities to ensure these third party relationships align with the organization’s security requirements.

Requirements

  • 3+ Years of experience with risk assessment methodologies and techniques as well as Third Party Risk Management Lifecycle.
  • Prior experience working with and assessing information security-related documentation such as SOC 2 reports, ISO 27001 certification, etc.
  • Strong knowledge of information security and risk management frameworks, including NIST Cybersecurity Framework, ISO/IEC 27001, and the Cyber Risk Institute Profile.
  • Strong Microsoft Office skills
  • Strong verbal and written communication skills.
  • Strong analytical skills
  • Self-motivated with good time management skills.

Nice To Haves

  • Prior experience with financial industry structure and concepts a plus.
  • Prior experience working on a Third Party Risk Management (TPRM) platform, such as Prevalent.

Responsibilities

  • Conduct initial and continuous information security risk assessments of third (Nth) parties.
  • Review third party provided security documentation including SOC reports, ISO 27001 certifications, security questionnaires, and Business Continuity and Disaster Recovery documentation.
  • Document assessment findings and risk ratings in the Bank’s TPRM platform and maintain an up-to-date tracking sheet that provides management with clear visibility into the status, due date, and completion of each assessment and related follow-up actions.
  • For vendor due-diligence, with a focus on information security risks, coordinate with relevant Teams (Administration, Legal, etc.) for vendor onboarding and offboarding activities.
  • Perform on-going monitoring of information security-related incidents involving third-parties and coordinate with relevant stakeholders to facilitate requests for necessary information from the relevant third-parties and support the assessment of potential impact to the Bank.
  • Participate in internal audits and external examinations related to the information security risk domains of third party risk management.
  • Assist in maintaining information security-related TPRM policies and procedures.
  • Performs other duties and responsibilities as assigned by management.

Benefits

  • PAID TIME OFF
  • MEDICAL
  • HSA
  • VISION
  • DENTAL
  • FSA
  • 401(K)
  • PROFIT SHARING
  • LEGAL PLAN
  • CANCER INDEMNITY PLAN
  • DISABILITY INSURANCE
  • LIFE INSURANCE
  • EMPLOYEE ASSISTANCE PROGRAM
  • COMMUTER BENEFITS
  • BUSINESS TRAVEL ACCIDENT
  • PAID VOLUNTEER DAY
  • PAID MEMBERSHIPS
  • PAID SEMINARS
  • TUITION ASSISTANCE
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service