IT Risk and Compliance Analyst
Listed on 2026-09-25
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Business Analyst
Greenberg Traurig (GT), a global law firm, has an exciting full‑time employment opportunity for an IT Third Party and Compliance Analyst in the Technology Department of various office locations. We offer competitive compensation and an excellent benefits package.
Position SummaryThe IT Risk and Compliance Analyst will take a lead in the ongoing design, development, and management of the firms’ IT third party risk management program. The position will consist of developing, monitoring, and assessing risks regarding vendor and partner relationships. Take a lead in the ongoing design, development, and management of the firms’ Information Security Program. This position will consist of developing, monitoring, and enforcing information security practices and controls to ensure information and computing assets are kept secure from unauthorized access and inappropriate alteration.
Duties & Responsibilities- Complete vendor risk assessments submitted to GT by clients and prospective clients.
- Respond to client Requests for Proposals (RFPs) and questionnaires related to security.
- Perform information security due diligence on third party vendors to determine the effectiveness of their controls to protect the firm’s data, identify any discrepancies and provide recommendations to management.
- Assesses client needs against security concerns and resolves various risk issues.
- Develop, implement, assign, and monitor third party vendor assessments.
- Execute and document assessment activities following established processes and procedures.
- Perform third party reviews to assess vendor information security posture and practices.
- Improve existing questionnaire response process.
- Keep abreast of regulatory and compliance related information to enhance the third‑party due diligence program.
- Collaborate with team members to provide subject matter expertise with respect to the Firm’s third party risk management program and to create and update documents and presentations that can be used to inform internal employees, external auditors or internal auditors about the Firm’s third party risk management program.
- Contribute to the continuous improvement, including automation where possible, of all aspects of the third‑party risk management program based on expert knowledge, industry best practices, business objectives and risk tolerance, keeping the program relevant and in alignment with the business objectives.
- Lead third party risk threat notification to third party vendors by assessing vendor risk, impact and response to third (e.g., assessing Log4
Shell vendor impact and response communications) - Track vendor mitigation progress of identified threats and risks
- Develop, implement, monitor KPI, KRI for third party risk management program.
- Develop and update third party risk management program policies, procedures, and best practices.
- Actively participate in outside Third-Party Risk Management communities.
- Work with the security team to develop, manage and maintain the Firm’s Information Security Program, security awareness programs, insider threat programs, etc.
- Identify Information Security & Business Continuity risks to senior management & make recommendations for corrective actions/mitigation of risks.
- Works assess BCP/DR compliance status of third-party vendors and communicate their status/impact to the firm’s BCP/DR team.
- Perform other related duties as required / assigned.
- Proficiency with Governance, Risk, Compliance tools (e.g., VSAQ, CIS, VRMMM, SCA, SIG, risk exchanges)
- Working knowledge of security standards, frameworks and best practices (ISO 27001/27701, NIST 800-53, CSA, OWASP, CIS, HiTech)
- Understanding of information security (IS) concepts, IT, information security awareness and third-party risk…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).