Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Third Party Cyber Risk Assesor image - Rise Careers
Job details

Third Party Cyber Risk Assesor

We are seeking a highly skilled and experienced Third Party Cyber Risk Assessor to join our team, responsible for conducting third-party cyber risk assessments for a global client portfolio. This individual will be critical in evaluating the security posture of third-party vendors, suppliers, and partners to ensure compliance with industry standards, regulations, and internal security policies as well as contracts. The ideal candidate will have a sound understanding of cyber risk management, vendor risk assessments, and an ability to communicate complex risk issues effectively to both technical and non-technical stakeholders.

  • Conduct detailed cybersecurity risk assessments (audits) for third-party vendors, including reviewing their information security practices, policies, and controls.
  • Assess third-party vendor security risks across multiple domains, including data protection, network security, identity & access management, and incident response.
  • Identify, evaluate gaps and/or deficiencies in cybersecurity technical and/or policy/procedure controls.
  • Perform thorough due diligence on third-party suppliers and partners, identifying potential vulnerabilities and risks that could impact the organization.
  • Recommend solutions and alternatives to remediate gaps and/or deficiencies in cybersecurity technical and/or policy/procedure controls.
  • Independently lead assessment meetings with clients and third parties to evaluate the implementation of cyber controls.
  • Collaborate closely with global line management and regional colleagues on delivery, client management and internal and client communications.
  • Master client’s proprietary security and contractual standards.
  • Apply recognized cybersecurity frameworks and standards (e.g., NIST, ISO 27001, CIS Controls) in risk assessments and audits.
  • Document findings, assessment processes, and recommended actions in a clear, concise, and actionable manner.
  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field (or equivalent experience).
  • 3-5+ years of experience in cybersecurity, risk management, or IT auditing, with at least 3 years focused on third-party risk assessments or vendor risk management.
  • Experience supporting Healthcare clients is required.
  • Demonstrable expertise leading the delivery of assessments based on cybersecurity standards and frameworks such as NIST CSF 2.0, IS27001 and 27002, SOC2, Center for Internet Security (CIS) best practices, PCI-DSS, CSA Cloud Controls Matrix, GDPR, HIPAA, HITRUST, etc.
  • Hands-on experience with tools and platforms used for third-party risk assessments, vulnerability scanning, and audit processes
  • Strong understanding of information security domains such as access control, encryption, vulnerability management, network security, and incident response.
  • Evidence of supporting clients overcome cybersecurity challenges in a broad array of sectors which may include, but is not limited to: Technology, Financial Services, and Retail.
  • A deep understanding of governance, standards, and compliance as they pertain to cyber security. 
  • Ability to analyze complex security data and translate findings into industry specific recommendations.

 Preferred Qualifications:

  • Certifications: CISSP, CISM, CRISC, CISA, SCP, CCNP, ISO 27001 Lead Auditor  or other relevant security or risk management certifications.
  • Experience working in a global organization and understanding of the challenges involved in managing risks across multiple jurisdictions.
  • Project management skills to manage multiple assessments, stakeholders, and deadlines effectively.
  • Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarized in the full job offer.
  • We operate a discretionary bonus scheme that incentivizes, and rewards individuals based on company and individual performance.
  • Control Risks supports hybrid working arrangements, wherever possible, that emphasize the value of in-person time together - in the office and with our clients - while continuing to support flexible and remote working.

Control Risks is committed to a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age or veteran status. If you require any reasonable adjustments to be made in order to participate fully in the interview process, please let us know and we will be happy to accommodate your needs.

Control Risks participates in the E-Verify program to confirm employment authorization of all newly hired employees. The E-Verify process is completed during new hire onboarding and completion of the Form I-9, Employment Eligibility Verification, at the start of employment. E-Verify is not used as a tool to pre-screen candidates. For more information on E-Verify, please visit www.uscis.gov.

Control Risks Glassdoor Company Review
3.5 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Control Risks DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Control Risks
Control Risks CEO photo
Nick Allan
Approve of CEO

Average salary estimate

$100000 / YEARLY (est.)
min
max
$80000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Third Party Cyber Risk Assesor, Control Risks

At Control Risks, we're looking for a talented Third Party Cyber Risk Assessor to join our dynamic team! In this role, you'll have the exciting opportunity to conduct comprehensive cyber risk assessments for our global client portfolio, ensuring that our third-party vendors, suppliers, and partners are secure and compliant with industry standards and internal policies. You'll evaluate the security posture of these vendors, dive deep into their information security practices, and identify potential vulnerabilities that could put our organization at risk. Your expertise will be crucial in recommending actionable solutions to remediate any gaps in their cybersecurity controls. We value effective communication, especially when it comes to discussing complex risk issues with both technical teams and non-technical stakeholders. With your solid background in cybersecurity and vendor risk management, you'll lead assessment meetings and collaborate with colleagues across the globe. If you’re passionate about protecting organizations from cybersecurity challenges and have the hands-on experience with risk frameworks like NIST and ISO, we'd love to hear from you! Plus, we offer a transparent compensation package, hybrid working arrangements, and a commitment to diversity and inclusion. Ready to make an impact in the cybersecurity realm?

Frequently Asked Questions (FAQs) for Third Party Cyber Risk Assesor Role at Control Risks
What are the main responsibilities of a Third Party Cyber Risk Assessor at Control Risks?

As a Third Party Cyber Risk Assessor at Control Risks, your primary responsibilities will include conducting detailed cybersecurity risk assessments for third-party vendors, identifying and evaluating gaps in their cybersecurity controls, and recommending remedial actions. You'll need to perform thorough due diligence on suppliers, assess risks across various domains such as data protection and network security, and communicate your findings clearly to clients and stakeholders.

Join Rise to see the full answer
What qualifications do I need to apply for a Third Party Cyber Risk Assessor position at Control Risks?

To qualify for the Third Party Cyber Risk Assessor role at Control Risks, you should hold a bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field, along with 3-5 years of cybersecurity experience, particularly in third-party risk assessments. Familiarity with frameworks like NIST and ISO, and certifications such as CISSP or CISA will give you an edge in the hiring process.

Join Rise to see the full answer
How important is experience in the healthcare sector for the Third Party Cyber Risk Assessor role at Control Risks?

Experience supporting Healthcare clients is crucial for the Third Party Cyber Risk Assessor position at Control Risks. Given the strict regulations and sensitive nature of healthcare data, having a solid understanding of compliance requirements like HIPAA and HITRUST will be essential in effectively assessing third-party vendor risks within this sector.

Join Rise to see the full answer
What tools and platforms should a Third Party Cyber Risk Assessor be familiar with?

A Third Party Cyber Risk Assessor at Control Risks should have hands-on experience with tools and platforms used for risk assessments, vulnerability scanning, and audits. Familiarity with cybersecurity standards and frameworks, combined with practical experience in using assessment tools, will greatly enhance your effectiveness in this role.

Join Rise to see the full answer
What does the career advancement look like for a Third Party Cyber Risk Assessor at Control Risks?

Control Risks recognizes and rewards talent, and as a Third Party Cyber Risk Assessor, you will have the opportunity to grow within the organization. Depending on your performance and career aspirations, potential paths may lead towards senior risk management roles, consultancy positions, or specialized positions in cybersecurity governance.

Join Rise to see the full answer
Common Interview Questions for Third Party Cyber Risk Assesor
Can you describe your experience with third-party risk assessments?

In responding to this question, focus on specific projects where you conducted assessments. Highlight the frameworks you used, the methodology followed, and the outcomes achieved. Make sure to relate your experience to the responsibilities of the Third Party Cyber Risk Assessor role at Control Risks.

Join Rise to see the full answer
How do you assess the security posture of a vendor?

When answering this question, discuss your approach to evaluating vendors by examining their security policies, incident response strategies, and compliance with recognized frameworks. Mention how you identify gaps and vulnerabilities, and then conclude with examples of how you’ve communicated your findings.

Join Rise to see the full answer
What cybersecurity frameworks are you most familiar with?

It's essential to mention the specific frameworks you’ve worked with, such as NIST, ISO 27001, or PCI-DSS. Explain how you’ve applied these frameworks in risk assessments and ensure to relate your knowledge to the Third Party Cyber Risk Assessor role at Control Risks.

Join Rise to see the full answer
How do you communicate risk findings to stakeholders without a technical background?

Explain your approach to translating complex cybersecurity concepts into clear, actionable insights for non-technical stakeholders. Provide examples of successful communication in past roles and emphasize your ability to foster understanding and drive informed decision-making.

Join Rise to see the full answer
What steps do you take when you identify a critical gap in a vendor's cybersecurity controls?

Discuss the importance of documenting your findings thoroughly, recommending immediate actions, and collaborating with the vendor to address identified issues. Ensure to mention how you would follow up to ensure compliance.

Join Rise to see the full answer
How do you stay updated with the latest cybersecurity trends and threats?

Mention the resources you use for keeping up-to-date with cybersecurity trends, such as industry blogs, professional organizations, webinars, and networking with other cybersecurity professionals. This shows your commitment to continuous learning.

Join Rise to see the full answer
Have you ever had to handle a vendor that resisted your recommendations? How did you approach it?

Provide an example of a challenging situation where you had to negotiate or persuade a vendor. Highlight your skills in communication, building rapport, and your ability to present evidence-based arguments to emphasize the importance of following best practices.

Join Rise to see the full answer
What do you think are the most significant risks facing third-party vendors today?

Discuss current trends in cyber threats such as ransomware attacks, data breaches, and compliance challenges, relating them back to third-party relationships. This illustrates your awareness of the evolving cyber landscape and its impact on business relationships.

Join Rise to see the full answer
How do you prioritize multiple assessments or projects simultaneously?

Highlight your project management skills including time management, setting priorities based on risk, and stakeholder engagement. Give an example of how you’ve effectively handled multiple projects in the past.

Join Rise to see the full answer
What motivates you in the field of cybersecurity?

Share your passion for cybersecurity and discuss what drives you to excel in this field, whether it be a commitment to protecting data, the thrill of solving complex problems, or working collaboratively in a team environment at Control Risks.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Control Risks Remote No location specified
Posted 9 days ago

Become a pivotal Marketing Manager at Control Risks, focusing on strategic B2B marketing in the vibrant LATAM market.

Photo of the Rise User
Control Risks Remote No location specified
Posted 9 days ago

Control Risks is looking for an Account Success Associate to enhance client relationships and drive business development initiatives in Canada.

Photo of the Rise User

Allstate is looking for a skilled Vended Application Consultant to manage desktop solutions and drive automation initiatives.

Photo of the Rise User

Join UNIVERSAL Technologies as a Copado Certified DevOps Specialist and drive the improvement of IT performance through innovative DevOps solutions.

Photo of the Rise User
DevRev Hybrid Palo Alto, California, United States
Posted 13 days ago

Join DevRev as an Applied AI Intern, where you'll enhance their cutting-edge knowledge operations and AI-driven solutions.

Photo of the Rise User

Join Bazaarvoice as a Technical Services Engineer and leverage your technical skills to improve client product integrations and support.

Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Join American Express as an Information Security Specialist and play a crucial role in safeguarding critical data while collaborating with cross-functional teams.

Photo of the Rise User
Posted 11 days ago

Join a dynamic team as a SailPoint Developer, specializing in Identity and Access Management solutions in Memphis, TN.

Photo of the Rise User

Join Highmark as a Lead IT Infrastructure Engineer and spearhead the design and maintenance of vital mainframe systems.

Photo of the Rise User
Anduril Industries Hybrid Costa Mesa, California, United States
Posted 8 days ago

Join Anduril Industries as an Offensive Security Engineer to enhance military technology's resilience against cyber threats.

Experts in risk and opportunity Control Risks is a global specialist risk consultancy that helps to create secure, compliant and resilient organisations. Combining unrivalled expertise, experience and reach with the power of data and technology, ...

168 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 19, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Cleveland just viewed Event Specialist at Marble Room
Photo of the Rise User
18 people applied to SOC Analyst I at CBIZ
Photo of the Rise User
Someone from OH, Youngstown just viewed Director, Clinical Informatics at Ro
Photo of the Rise User
Someone from OH, Dayton just viewed Shopify Specialist at Remote VA
L
Someone from OH, Dayton just viewed Mechanical Design Engineer(s) at LTTS
Photo of the Rise User
14 people applied to Junior Security Engineer at Epic
H
Someone from OH, Akron just viewed Financial Content Writer at Huntington
W
Someone from OH, Columbus just viewed Director of Regulatory Compliance - WEX Bank at WEX Inc