Senior Security Risk Management Analyst

Rubrik Rubrik · Enterprise · Cork, Ireland · Information Security

This role is for a Senior Security Risk Management Analyst focused on Third-Party/Vendor Risk Assessment. The primary responsibilities include leading risk assessments of vendors, evaluating security documentation, coordinating remediation efforts, and partnering with internal teams to improve supplier security management processes. The role also involves identifying opportunities for automation in the assessment process and staying updated on emerging risks and regulatory requirements. While the company mentions AI transformation and AI operations, this specific role is centered on traditional cybersecurity risk management and vendor governance, not direct AI/ML model development or deployment.

What you'd actually do

  1. Lead and conduct comprehensive risk assessments of new and existing third-party vendors and service providers, focusing on cybersecurity, and regulatory compliance.
  2. Evaluate third-party security questionnaires, audit reports (e.g., SOC 2, ISO 27001), and risk documentation.
  3. Coordinate with vendors to request and verify security controls, remediation plans, and ongoing compliance.
  4. Oversee facilitation of risk remediation efforts agreed upon with suppliers, ensuring timely resolution.
  5. Collaborate during supplier contract development, reviewing deviations from security requirements and offering subject matter expertise on risk remediation.

Skills

Required

  • third-party risk assessment
  • vendor governance
  • cybersecurity risk management
  • risk assessment methodologies
  • information security frameworks
  • regulatory compliance requirements

Nice to have

  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Risk Management, or a related field
  • ISO 27001/2
  • FedRAMP
  • SOC 2 Trust Services Criteria
  • PCI DSS
  • NIST CSF
  • synthesize and communicate complex risk findings
  • detail-oriented
  • process-driven
  • managing multiple vendor assessments concurrently
  • Coupa
  • OneTrust
  • JIRA
  • Coverbase
  • CISA
  • CISM
  • CISSP
  • CRISC

What the JD emphasized

  • proven track record in managing third-party risk, vendor governance, or related domains
  • comprehensive risk assessments
  • cybersecurity
  • regulatory compliance