Senior Third-Party Risk Management Analyst

Posted 2 Hours Ago
Be an Early Applicant
Hiring Remotely in US
Remote
Senior level
Cloud • Software • Analytics
The Role
Maintains and matures the enterprise third-party risk management program. The role evaluates vendor cybersecurity, privacy, resiliency, and regulatory controls; maps findings to frameworks; manages remediation and documentation; supports SOC 2 and PCI DSS audits; and oversees vendor dependencies, exceptions, and notifications. It partners with cybersecurity, legal, procurement, product, auditors, and clients to communicate risk, support compliance, improve resiliency, and strengthen governance processes.
Summary Generated by Built In
Job Description

POSITION OVERVIEW

The Third-Party Risk Management (TPRM)Analyst serves as a core member of Momentive Software's Cybersecurity, Risk & Compliance organization. This role is responsible for maintaining and maturing Momentive's enterprise-wide third-party risk program, ensuring that all vendors, platforms, and service providers meet the Firm's cybersecurity, privacy, resiliency, and regulatory requirements.

The Analyst partners closely with Client Success, Cybersecurity Engineering, TVM, Legal, Procurement, Product, and the CISO to evaluate vendor risk, maintain continuous oversight of third-party controls, and support Momentive's compliance obligations — including SOC 2 Type II and PCI DSS. The role also supports TVM notifications to clients who manage their own cybersecurity posture, ensuring clear, accurate, and timely communication of vulnerabilities and remediation expectations.

This position requires strong analytical capability, deep familiarity with cybersecurity frameworks, and the ability to translate complex risk issues into actionable guidance for business and technical stakeholders.

KEY RESPONSIBILITIES

Third-Party Risk Management Program

  • Maintain Momentive's global inventory of third-party providers, applications, and services from onboarding through termination.
  • Lead vendor cybersecurity assessments, coordinating with Cybersecurity Engineering, Legal, and business owners to evaluate risk and required controls.
  • Assess vendor maturity using NIST CSF, CIS, CMMC, GDPR, PCI DSS, SOC 2, and other frameworks.
  • Oversee vendor SLAs, RPO/RTO commitments, breach notification requirements, and cybersecurity insurance documentation.
  • Ensure thorough documentation of findings, recommendations, and remediation plans for all vendor assessments.
  • Serve as a liaison to internal and external auditors for vendor-related controls and evidence collection.

Support for PCI DSS & SOC 2 Type II Audits

  • Provide evidence, documentation, and control validation related to third-party dependencies for Momentive's SOC 2 Type II and PCI DSS assessments.
  • Ensure vendor controls align with Momentive's ISMS, contractual obligations, and certification requirements.
  • Partner with the GRC team to maintain audit-ready documentation, including policies, standards, procedures, and risk treatment plans.
  • Track vendor exceptions and compensating controls, ensuring audit defensibility and continuous improvement.

TVM Notifications & Client Support

  • Collaborate with the Threat & Vulnerability Management (TVM) team to support vulnerability notifications to clients who manage their own cybersecurity controls.
  • Ensure communications are accurate, timely, and aligned with Momentive's contractual commitments and industry best practices.
  • Provide consultative guidance to clients regarding risk impact, remediation expectations, and recommended cybersecurity practices.
  • Maintain documentation and metrics related to client notifications, follow-up actions, and closure.

Governance, Risk & Compliance Integration

  • Contribute to the continual improvement of Momentive's ISMS by aligning vendor risk processes with Firm policies, standards, and procedures.
  • Provide input on control selection, risk treatment plans, and metrics used to monitor the effectiveness of Momentive's cybersecurity controls.
  • Maintain situational awareness of emerging threats, regulatory changes, and industry trends affecting third-party risk.
  • Support DR/BCP planning as it relates to vendor dependencies and resiliency requirements.

Stakeholder Engagement & Leadership

  • Act as a key point of contact when business units identify vendor-related risk; coordinate with Legal, Cybersecurity, and leadership on risk reduction strategies.
  • Promote a positive, enterprise-wide cybersecurity culture through outreach, training, and awareness activities.
  • Provide exemplary service to internal and external stakeholders, demonstrating professionalism, empathy, and expertise.
  • Mentor team members and contribute to the development of internal training materials and documentation.

SKILLS & EXPERIENCE

Required

  • 5+ years of experience in cybersecurity, risk management, audit, or compliance.
  • Deep understanding of regulatory requirements including PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST.
  • Experience evaluating both legacy and modern cloud technologies (AWS, GCP, Azure).
  • Strong knowledge of APIs, application cybersecurity, encryption, endpoint, and network cybersecurity concepts.
  • Familiarity with SIEM, IDS, log management, vulnerability management, and threat intelligence.
  • Ability to assess vendor controls, map them to frameworks, and articulate risk to non-technical stakeholders.
  • Strong project management, multitasking, and organizational skills.
  • Excellent written and verbal communication skills.

Preferred

  • Experience supporting SOC 2 Type II and PCI DSS audits.
  • Experience with EGRC/ITGRC platforms (e.g., Jira Service Manager GRC, Archer, OneTrust, LogicGate).
  • Certifications such as CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP.
About Us

Momentive Software amplifies the impact of over 20,000 purpose-driven organizations in over 30 countries, with over $11 billion raised and 55 million members served to date. Mission-driven nonprofits and associations rely on Momentive’s cloud-based software and services to address their most pressing challenges – from engaging their communities to simplifying operations and growing revenue. Designed to help organizations connect more, manage more, and ultimately expect more, Momentive's solutions are built with reliability at the core and strategically focus on fundraising, learning, events, careers, volunteering, accounting, and association management. Momentive partners with organizations that believe "good enough" is never enough – so they can bring on better outcomes for everyone they serve. Learn more at momentivesoftware.com.
 

Why Work Here?

At Momentive Software, we’re a team of passionate problem-solvers, innovators, and volunteers who believe in using technology to make a real difference. We dream big, support each other, and take pride in creating solutions that help our customers drive meaningful change. If you’re looking for a place where your work matters and your ideas are valued, you’ll find it here.

Medical, Dental & Vision Benefits

401(k) Savings Plan with Company Match

Flexible Planned Paid Time Off

Generous Sick Leave

Inclusive & Welcoming Environment

Purpose-Driven Culture

Work-Life Balance

Commitment to Community Involvement

Employer-Paid Parental Leave

Employer-Paid Short-Term Disability

Remote Work Flexibility
Momentive Software actively embraces diversity and equal opportunity in a meaningful way. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be, which is why we do not discriminate based on race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.
All persons hired will be required to verify identity, minimum age of 18, eligibility to work in the United States (without sponsorship), and to complete the required employment eligibility verification form upon hire.

Skills Required

  • 5+ years of experience in cybersecurity, risk management, audit, or compliance
  • Understanding of PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST
  • Experience evaluating legacy and modern cloud technologies, including AWS, GCP, and Azure
  • Knowledge of APIs, application cybersecurity, encryption, endpoint cybersecurity, and network cybersecurity concepts
  • Familiarity with SIEM, IDS, log management, vulnerability management, and threat intelligence
  • Ability to assess vendor controls, map them to frameworks, and communicate risk to non-technical stakeholders
  • Strong project management, multitasking, and organizational skills
  • Excellent written and verbal communication skills
  • Experience supporting SOC 2 Type II and PCI DSS audits
  • Experience with eGRC or ITGRC platforms such as Jira Service Manager GRC, Archer, OneTrust, or LogicGate
  • Certifications such as CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP

Momentive Software Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Momentive Software and has not been reviewed or approved by Momentive Software.

  • Leave & Time Off Breadth — Generous PTO, paid holidays, paid parental leave, and paid volunteer time are offered; feedback suggests time off is a consistent bright spot. A remote‑first setup can make taking leave and managing schedules more practical.
  • Flexible Benefits — Remote‑first options with remote and hybrid roles provide flexibility in work location and hours. Feedback suggests this flexibility helps offset middling cash compensation for some employees.
  • Wellbeing & Lifestyle Benefits — Offerings include an Employee Assistance Program, HSA with employer contributions, and pet insurance. Feedback suggests these non‑cash elements contribute to overall package appeal despite tradeoffs elsewhere.

Momentive Software Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: St. Petersburg, FL
820 Employees
Year Founded: 2017

What We Do

Momentive Software (formerly Community Brands) amplifies the impact of over 30,000 purpose-driven organizations globally. Mission–driven organizations and associations rely on the company’s cloud-based software and services to solve their most critical challenges: engage the people they serve, simplify operations, and grow revenue. Built with reliability at the core and strategically focused on events, careers, fundraising, financials, and operations, our solutions suite is bound by a common purpose to serve the organizations that make our communities a better place to live.

Similar Jobs

Worth Logo Worth

Senior Software Engineer

Artificial Intelligence • Fintech • Software • Financial Services
In-Office or Remote
4 Locations
84 Employees

ServiceNow Logo ServiceNow

Director, Pursuit Lead, Elevate

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Chicago, IL, USA
29000 Employees
193K-319K Annually

ServiceNow Logo ServiceNow

Senior Manager, Platform Engineering

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
San Diego, CA, USA
29000 Employees
181K-317K Annually

ServiceNow Logo ServiceNow

Senior Manager, Platform Engineering

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Santa Clara, CA, USA
29000 Employees
201K-352K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account