Sr. Third Party Cybersecurity GRC Analyst
Listed on 2026-07-26
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Sr. Third Party Cybersecurity GRC Analyst
Security Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst)
Information Security Risk Management
Hybrid 1:
This role requires associates to be in-office 1 - 2 days per week in the Indianapolis, IN or Atlanta, GA office, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace.
The Security Analyst Sr. is responsible for independently assessing, documenting, and monitoring cybersecurity risks associated with third-party vendors, service providers, and business partners. This role evaluates vendor security controls, reviews assurance evidence, identifies control gaps, supports remediation and risk acceptance decisions, and provides subject matter expertise throughout the vendor lifecycle.
How you will make an impact:
- Support internal and external audit and compliance activities, including HIPAA, HITRUST, NIST, PCI DSS, SOC 2, and other healthcare or cybersecurity-related assessments.
- Lead cybersecurity risk assessments and due diligence reviews for third-party vendors, service providers, SaaS platforms, cloud providers, and other external business partners, including high-risk and critical vendors.
- Evaluate vendor security documentation, including SOC reports, ISO certifications, HITRUST certifications, penetration test summaries, security questionnaires, policies, data flow diagrams, and remediation evidence.
- Communicate directly with vendors to clarify questionnaire responses, request supporting evidence, validate remediation status, and coordinate risk mitigation activities.
- Provides trouble resolution on complex problems and leads implementations for system and network security technologies.
- Develops testing plans to ensure quality of implementation; coordinates and prepares the reporting of data security events and incidents; provides system and network architecture support for information and network security technologies
- Provides technical support to business and technology associates in risk assessments and implementation of appropriate information security procedures, standards and technologies
- Represents major upgrades and reconfigurations in change control
- Design & analyze mix of vendor services meeting business and information security requirements
- Determine and perform complex configuration changes to meet business and information security requirements
- Serve as the technical escalation for results of preventative maintenance routines
- Participate in metrics development, trend analysis, quality reviews, and program maturity initiatives to strengthen Elevance Health's third-party cybersecurity risk management program.
- Represents infrastructure security support in significant projects and performs the most complex operations and administration tasks
- Respond to level 3 & 4 change and problem requests without supervision
- Lead level 1 & 2 incident recoveries and root cause analysis.
Minimum Requirements:
- Requires a bachelor's degree or equivalent combination of education and experience that would provide the knowledge to perform such work.
- Experience must include a minimum of 3 years experience in a support & operations or design & engineering role in any of the following areas: access management or network security technologies, servers, networks, Network communications, telecommunications, operating systems, middleware, disaster recovery, collaboration technologies, hardware/software support or other infrastructure services role; or any combination of education and experience, which would provide an equivalent background.
- Requires experience providing top-tier support for 3 or more of the information security technology areas:
1) Access Control,
2) Application Security,
3) Business Continuity and Disaster Recovery Planning,
4) Cryptography,
5) Information Security and Risk Management
6) Legal, Regulations,
7) Compliance and Investigations,
8) Operations Security,
9) Physical (Environmental) Security, 10) Security Architecture and Design, 11) Telecommunications and Network…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).