Third Party Security Lead

Old National BankEvansville, IN
$81,700 - $165,100

About The Position

The Third‑Party Security Lead is responsible for the design, execution, and continuous improvement of ONB’s third‑party cybersecurity and technology risk oversight, ensuring risks introduced through external vendors, partners, and applications are effectively identified, assessed, and mitigated across the lifecycle. This role will lead and oversee inherent risk assessments, cybersecurity due diligence, and application security reviews, including application security testing across both third‑party delivered solutions and internally managed systems and integrations, to evaluate end-to-end control effectiveness and shared responsibilities. The position oversees comprehensive control evaluations including due diligence questionnaires, documentation review, and control testing/validation across information security and technology risk domains, such as Identity and Access Management, Security Operations, Network Security, Cryptography, and Logging/Monitoring, while driving risk-based decisions, remediation activities, and formal risk acceptance where appropriate. The Third‑Party Security Lead partners closely with business units, procurement, legal, and technology stakeholders to ensure information security and technology risk requirements are embedded into third‑party engagements, assess vendor connectivity and integration risks (e.g., cloud, APIs, and network access), and validate that both vendor and ONB-controlled application components meet established standards and regulatory expectations. The role ensures effective governance over ongoing monitoring, issue management, and remediation, while supporting audit and regulatory activities. Additionally, this position advances risk assessment methodologies beyond traditional due diligence toward integrated third‑party and application security testing, continuous monitoring, and threat-informed assessments, strengthening ONB’s overall information security and technology security posture. This role will foster a strong risk-aware culture across the enterprise and influence behaviors to reduce risk.

Requirements

  • Bachelor’s degree in Computer Science, Technology, related field, or equivalent work experience required
  • 5+ years experience in cybersecurity, information security risk, or third-party/vendor risk management within financial services.
  • Minimum of 3+ years of experience leading or supporting a third-party security risk management and application assessment program.
  • Detailed understanding of information security frameworks such as ISO27XXX, NIST, CRI, and industry best practices
  • Involvement in adhering to security laws and regulations affecting financial institutions including, but not limited to, GLBA, SOX, HIPAA, FFIEC, etc.
  • Extensive knowledge of and experience with information security and technology risk management, control development, and control validation.
  • Knowledge of application, infrastructure, cloud, and network security concepts with the ability to evaluate technical architectures and identify security weaknesses in vendor and application integrations.
  • Experience in policy, standards, and procedure creation based on selected framework and implementation issues related to regulatory and other requirements.
  • Thorough understanding of how to analyze business applications, perform application security assessments, and recommend appropriate security controls.
  • Knowledge and experience with an enterprise GRC and IT Service Management system.
  • Knowledge of OCC Heightened Standards for risk assessment, incident response, and third-party risk management.
  • Achieved or in pursuit of a globally recognized information security certification such as CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), or equivalent preferred.

Nice To Haves

  • Achieved or in pursuit of a globally recognized information security certification such as CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), or equivalent preferred.

Responsibilities

  • Execution of Security Risk Assessments and Control Testing
  • Provide subject matter expertise within ONB’s ISTRM Program by assessing the impact of new vendors, technologies, processes, or partnerships including vendor-hosted solutions, SaaS platforms, and third-party integrations (e.g., APIs, cloud services, and network connectivity), and risk-based decision making.
  • Lead and oversee end-to-end risk assessments, control testing, and risk management review processes to analyze third-party, application, and organization risk and control effectiveness assisting vendors and team members in risk and control identification.
  • Evaluate the design and operating effectiveness of controls across key information security and technology risk domains, including Identity and Access Management (IAM), Security Operations, Network Security, Cryptography and key management, Security Assessment and Testing, and Logging, Monitoring, and Incident Response.
  • Translate technical findings into business risk statements for stakeholders and governance forums.
  • Escalate issues and recommendations to management, using a risk-based approach, for immediate attention as needed.
  • Validate remediation actions and ensure identified control gaps are effectively addressed.
  • Establish and enforce effective information security and technology risk management practices across the vendor and application lifecycle, including onboarding, periodic reviews, and trigger-based reassessments, ensuring consistency, quality, and defensibility of risk evaluations.
  • Identify applicable laws and regulations and validate adherence to required standards for vendors, business applications, infrastructure, processes, etc.
  • Due Diligence & Documentation Review
  • Review and analyze due diligence artifacts including security questionnaires, SOC reports, penetration test results, policies, standards, and control documentation.
  • Validate completeness and accuracy of vendor and team member responses and supporting evidence.
  • Perform gap analysis against internal standards, regulatory expectations, and industry frameworks (e.g., NIST, CRI, ISO 27001, FFIEC, GLBA).
  • Support pre-assessment readiness activities and guide vendors and team members through required documentation expectations.
  • Support the creation, maintenance, and continuous improvement of ONB’s ISTRM policies, program, procedures, standards, security documentation, regulatory documentation, etc.
  • Provide leadership and effort in the buildout, maintenance, and detailed mapping of global regulatory and industry frameworks to organizational control standards.
  • Organize and prepare metrics and dashboards for committee, council, and regulatory reporting, ensure smooth execution of meetings, present information as requested, and communicate and track outcomes of meetings.
  • Participate in departmental activities and assignments including meetings, updates, planning, reporting, and other responsibilities as needed.
  • Collaborate with internal and external stakeholders:
  • Partner with business owners, procurement, legal, and technology teams to support secure vendor and application onboarding and ongoing monitoring ensuring requirements are incorporated into their program, business processes, and projects.
  • Interface directly with third parties to clarify controls, request evidence, and discuss findings.
  • Support contract security requirements and risk acceptance decisions.
  • Collaborate with security engineering, SOC, and incident response teams to ensure alignment of monitoring and threat detection for vendor risks.
  • Partner with the first line of defense and risk offices on risk control assessments and provide guidance on development and enhancement of key controls and risk management.
  • Assess and respond to information security events and incidents. Assist in coordination with internal and external parties and assist in evaluation, communication and documentation of issues and incidents
  • Support and coordinate internal audits, collaborating with auditors to ensure adherence to standards
  • Develop, publicize, and support education and training initiatives for all team members to raise awareness of information security and risk management requirements.
  • Act as an information security and technology risk advocate to management, team members, and business/process owners.
  • Influence behaviors to reduce risk and foster a strong ISTRM culture throughout the enterprise.

Benefits

  • competitive compensation with our salary and incentive program
  • medical, dental, and vision insurance
  • 401K
  • continuing education opportunities
  • employee assistance program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service