INFORMATION SECURITY ANALYST - FREMONT, CA
Purpose of Position
We are seeking an Information Security Analyst to assess and manage third-party risks during vendor evaluations. The ideal candidate will be responsible for conducting periodic risk assessments based on vendor sensitivity, data scope, or previous security incidents. This position requires a strong understanding of information security frameworks, risk management practices, and analytical expertise.
Essential Functions:
- Audit Planning and Execution:
- Develop and execute a comprehensive internal audit plan based on risk assessments and organizational priorities.
- Conduct audits of various departments and functions, including financial, operational, compliance, and IT audits.
- Security Assessments:
- Conduct detailed security risk evaluations during the initial stages of vendor engagements.
- Assess vendors' security practices, data privacy protocols, and operational frameworks.
- Perform regular reviews and reassessments of vendor risk levels, particularly those handling sensitive data or with a history of security breaches.
- Establish ongoing monitoring and risk reassessment processes for all third-party vendors.
- Risk Identification:
- Identify, evaluate, and rank potential risks associated with third-party vendors.
- Work closely with external partners and internal teams to create and implement risk reduction strategies.
- Collaboration:
- Advise stakeholders on security best practices and requirements.
- Deliver insightful risk assessments and clear reports with actionable recommendations for senior leadership.
- Build strong relationships with internal departments, IT teams, and vendors to promote a collaborative approach to risk management.
- Reporting:
- Perform data analysis and generate reports to track third-party risk.
- Monitor program performance and ensure milestones are met in a timely manner.
- Governance and Compliance:
- Develop and enforce 3rd party vendor management policies, procedures, and standards to maintain compliance with regulatory requirements, industry standards, and internal controls.
- Ensure adherence to key regulatory and security standards such as NIST 800-53, GDPR and ISO/IEC 27001.
- Support contract reviews to ensure vendor agreements align with security and risk mitigation standards.
- Contribute to enhancing vendor risk management protocols and processes.
Experience:
- 6+ years of experience in conducting security control assessments or audits.
- 6+ years of experience with information security standards and privacy laws (e.g., ISO 27001, NIST, HIPAA).
- 2+ years of experience in developing or managing security awareness programs.
- Proficiency in third-party risk assessment methodologies and tools.
- In-depth knowledge of GRC frameworks and tools.
- Understanding of emerging technologies such as Large Language Models (LLMs), Artificial Intelligence (AI), and Machine Learning (ML).
- Excellent analytical, critical thinking, and problem-solving skills.
- Strong written and verbal communication skills.
Education:
- Bachelor’s degree in Computer Science, Information Systems, Business, or a related field, or equivalent relevant experience.
Certifications (nice to have):
- Professional certifications such as CISA, CISM, CRISC, CISSP.
Salary Range:
$140,000 - $160,000 DOE