Employer Active
Job Alert
You will be updated with latest job alerts via emailJob Alert
You will be updated with latest job alerts via emailThe Crum & Forster Cyber & Information Security team is seeking a ThirdParty Security Analyst. Reporting to the Director of Cyber & Information Security the analyst will perform thirdparty security assessments. You will work with a team of professional Security Analysts leveraging NextGen security tools to perform the full lifecycle of thirdparty reviews from onboarding to realtime monitoring of vendors and suppliers.
Responsibilities Functions and Duties
Conduct technical security assessments of thirdparty vendors suppliers and partners by reviewing their security controls adherence to regulations compliance and contracts.
Analyze thirdparty security assessment findings and document security risks within the management software for tracking of risk reporting.
Coordinate with various stakeholders to verify and remediate security risk findings.
Develop KRIs and KPIs around thirdparty risk assessments and the remediation of key findings.
Develop Update and Publish Policies and Standard Operating Procedures for thirdparty risk management.
Continuously monitor for active vulnerabilities and cyber events against our vendors and suppliers
Participate in thirdparty cyber incident response by reaching out to impacted vendors and tracking remediation.
Be an ambassador for Cyber & Information Security within Crum & Forster.
Previous experience performing technical security audits or thirdparty assessments
Understanding of current Cyber Vulnerabilities & threats.
Knowledge of security assessments (SOC reports ISO/NIST vulnerability and pen testing assessments).
Fundamental understanding of system and network security principles and technology.
Ability to interface with a wide audience of technical and nontechnical personnel.
Ability to prioritize and manage workloads and deadlines.
Excellent written and verbal communication skills.
Selfstarter who is motivated and driven to learn.
Bachelor s degree in a technical discipline or equivalent experience
Preferred Qualifications
Prior experience and/or certifications in AWS Azure and/or GCP
Experience in performing thirdparty assessments of SaaS providers and vendors operating in cloud environments.
Experience performing risk assessments
Any Security focused Certifications
35 year Cybersecurity related experience
Education
BE Btech
Full Time