IT Third Party Risk and Compliance Analyst

Posted 12 Days Ago
Be an Early Applicant
Warsaw Center, TX
In-Office
Junior
Legal Tech
The Role
The Analyst will manage the IT third-party risk program by assessing vendor security controls, developing assessments, and collaborating on security matters while monitoring compliance.
Summary Generated by Built In

Greenberg Traurig (GT), a global law firm with locations across the world in 15 countries, has an exciting employment opportunity for you. We offer competitive compensation and an excellent benefits package, along with the opportunity to work within an innovative and collaborative environment.

Join our Technology department​ as a IT Third Party Risk and Compliance Analyst located in our Warsaw Center of Excellence office (remote).

Position Summary:

The IT Third Party Risk and Compliance Analyst will lead the design, development, and management of the firms’ IT third party risk management program.  The position will consist of gathering, analyzing, and interpreting security control evidence from third parties. Candidate should be available outside normal working hours to participate in emergency events such as security incidents, breaches, investigations, etc.

Duties & Responsibilities:

  • Uses SIG questionnaire, performs due diligence on third party vendors to determine the effectiveness of their controls to protect the firm’s data, identifies any discrepancies and provides recommendations to management

  • Develops, implements, assigns, and monitors third party vendor assessments

  • Monitors third party vendor security posture using third party services (e.g., security scorecard, BitSight, risk recon, etc.)

  • Executes and documents assessment activities following established processes and procedures

  • Improves existing SIG questionnaire review/response process

  • Keeps abreast of regulatory and compliance related information to enhance the third-party due diligence program

  • Collaborates with team members to provide subject matter expertise with respect to the Firm’s third-party risk management program and creates and updates documents and presentations that can be used to inform internal employees, external auditors or internal auditors about the program

  • Contributes to the continuous improvement, including automation where possible, of all aspects of the third-party risk management program based on expert knowledge, industry best practices, business objectives and risk tolerance, keeping the program relevant and in alignment with the business objectives

  • Leads third party risk/threat notification to third party vendors by assessing vendor risk, impact and response to risks/threats (e.g., assessing Log4Shell vendor impact and response communications)

  • Tracks vendor mitigation progress of identified threats and risks

  • Develops, implements, monitors KPI, KRI for third party risk management program

  • Develops and updates third party risk management program policies, procedures, and best practices

  • Actively participates in outside Third-Party Risk Management communities

  • Works with the security team to develop, manage and maintain the Firm’s Information Security Program, security awareness programs, insider threat programs, etc.

  • Identifies Information Security & Business Continuity risks to senior management & makes recommendations for corrective actions/mitigation of risks

  • Assesses BCP/DR compliance status of third-party vendors and communicates their status/impact to the firm’s BCP/DR team

  • Assists IT Compliance team with completing vendor risk assessments submitted to GT by clients and prospective clients; responds to client Requests for Proposals (RFPs) and questionnaires related to security

Skills & Competencies:

  • Understanding of information security (IS) concepts, IT, information security awareness and third-party risk management processes, methodologies, and practices

  • Demonstrate strong customer service skills to ensure a smooth data And evidence collection experience for both our customers and our internal business unit partners

  • As a specialist on complex technical and business matters, work is highly independent

  • Explain and articulate technical concepts to non-technical stakeholders, and follow basic troubleshooting steps to work through issues

  • Strong interpersonal skills, capable of interacting at all levels of the organization from analyst level to C-suite

  • Demonstrate basic project management and documentation skills to manage multiple parallel work streams

  • Work well under pressure with tight deadlines to deliver superior service to our clients and stakeholders

  • Ability to write reports, briefs or create presentations resulting from third party vendor assessments

  • Ability to perform and document a gap analysis as part of third-party vendor assessments

  • Familiar with contractual clauses, best practices that may be enforced to achieve third-party vendor compliance (right to audit, minimum security requirements, SLAs, 3rd party assessments, etc.).

Qualifications & Prior Experience:

  • Bachelor’s degree in Information Technology, Information Systems, Information Security, Business Administration, or Risk Management or equivalent experience

  • 1-3 years of experience in implementing and/or supporting IT risk management processes.

  • 1-3 years of experience in responding to vendor IT risk assessments  

  • Industry certifications preferred (e.g. TPRA, CTPRP, CTPRA, CEH, CISA, CISM) or will obtain

  • Proficiency with standard information gathering tools (e.g., DDQ, SIG, etc.)

  • Working knowledge of security exchanges (e.g. ProcessUnity, OneTrust, UpGuard, CyberGRX, Prevalent, Archer, LogicManager, etc.)

  • Working knowledge of security standards, frameworks, best practices and key laws (ISO 27001/27701/27017/42001, NIST, CIS, GDPR, HIPAA )

  • Experience working with IT audits, findings, and tracking and remediating to resolution.

  • Working knowledge of cloud technologies (any of these, Azure, AWS, Alibaba, GCP, IBM cloud) and software delivery models (SaaS, PaaS, IaaS)

  • Proficiency with Windows-based software and Microsoft Office suite

  • Working knowledge of A.I. fundamentals (e.g. AI-900 certification)

  • Working knowledge of A.I. technologies (Gen AI), CoPilot, ChatGPT, etc.

Other

  • Be a Polish citizen living in Poland or a foreign national living in Poland with the right to work in Poland without a work permit.

Top Skills

Alibaba
Archer
AWS
Azure
Bitsight
Cis
Cybergrx
GCP
Gdpr
Hipaa
Ibm Cloud
Iso 27001
Iso 27017
Iso 27701
Iso 42001
Logicmanager
Nist
Onetrust
Prevalent
Processunity
Risk Recon
Security Scorecard
Sig Questionnaire
Upguard
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
4,877 Employees
Year Founded: 1967

What We Do

Greenberg Traurig, LLP has more than 2650 attorneys in 45 locations in the United States, Europe and the Middle East, Latin America, and Asia. The firm is a 2022 BTI “Highly Recommended Law Firm” for superior client service and is consistently among the top firms on the Am Law Global 100 and NLJ 250. Greenberg Traurig is Mansfield Rule 6.0 Certified Plus by The Diversity Lab. The firm is recognized for powering its U.S. offices with 100% renewable energy as certified by the Center for Resource Solutions Green-e® Energy program and is a member of the U.S. EPA’s Green Power Partnership Program. The firm is known for its philanthropic giving, innovation, diversity, and pro bono. Web: www.gtlaw.com.

Similar Jobs

Hybrid
Houston, TX, USA
213000 Employees

ServiceNow Logo ServiceNow

Architect

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Austin, TX, USA
27000 Employees

Wells Fargo Logo Wells Fargo

Transaction Branch Support Analyst

Fintech • Financial Services
Hybrid
5 Locations
213000 Employees
87K-154K Annually
Hybrid
San Antonio, TX, USA
213000 Employees

Similar Companies Hiring

Atticus Thumbnail
Social Impact • Legal Tech • Insurance
Los Angeles, CA
210 Employees
Hebbia AI Thumbnail
Software • Natural Language Processing • Machine Learning • Legal Tech • Generative AI • Financial Services • Artificial Intelligence
New York, NY
90 Employees
Fulcrum GT Thumbnail
Software • Legal Tech • Cloud
Hoffman Estates, Illinois
501 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account