More jobs:
Information Security Third-Party Risk Analyst
Job in
Cincinnati, Hamilton County, Ohio, 45208, USA
Listed on 2026-06-02
Listing for:
U.S. Bank
Full Time
position Listed on 2026-06-02
Job specializations:
-
IT/Tech
Cybersecurity, Information Security, Data Security
Job Description & How to Apply Below
U.S. Bank is seeking an Information Security Third‑Party Risk Analyst to support third‑party risk management and vendor security oversight. This role evaluates and manages information security risks across external vendors, ensuring appropriate controls are in place and driving remediation of identified risks.
Responsibilities- Perform information security risk assessments on third‑party vendors (new and existing).
- Review and analyze vendor security questionnaires, control responses, and supporting documentation.
- Identify security gaps, control deficiencies, and non‑compliance issues.
- Document and track risk findings and remediation efforts through resolution.
- Evaluate vendor remediation plans and compensating controls.
- Partner with business stakeholders and third parties to explain risks and recommend mitigation strategies.
- Support contract review and redlining with a focus on information security requirements.
- Conduct continuous monitoring of vendor security posture.
- Review and assess third‑party security incidents and perform post‑event analysis.
- Contribute to monthly and quarterly reporting, metrics, and trend analysis.
- Support audit activities, control testing, and quality assurance efforts.
- Collaborate across information security, risk, and compliance teams.
- 5+ years of experience in information security.
- 5+ years of experience in third‑party risk management, vendor risk, or risk analysis.
- Hands‑on experience conducting third‑party/vendor information security risk assessments.
- Strong understanding of information security controls and risk concepts.
- Experience identifying control gaps and evaluating remediation actions.
- Experience with contract review or redlining related to security requirements.
- Ability to clearly communicate risk to both technical and non‑technical stakeholders.
- Familiarity with security frameworks (e.g., NIST 800‑53).
- Experience reviewing SOC2 Type2I reports.
- Experience with continuous monitoring tools (e.g., Bit Sight, Archer).
- Exposure to third‑party security incident response and post‑event analysis.
- Broader technical cybersecurity background.
- Exposure to emerging risks (e.g., AI, new technologies).
- Healthcare – medical, dental, vision.
- Basic term and optional term life insurance.
- Short‑term and long‑term disability.
- Pregnancy disability and parental leave.
- 401(k) and employer‑funded retirement plan.
- Paid vacation (two to five weeks depending on salary grade and tenure).
- Up to 11 paid holiday opportunities.
- Adoption assistance.
- Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law.
- Other benefits available by employment status.
U.S. Bank is an equal‑opportunity employer. We consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, and other factors protected under applicable law.
U.S. Bank participates in the U.S. Department of Homeland Security E‑Verify program in all U.S. facilities and certain territories.
#J-18808-LjbffrTo View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×