Role description
We are looking for a detail-oriented and strategic Information Security – Risk Analyst to support the assessment, remediation, and continuous monitoring of cyber risks posed by external vendors, partners, and service providers. This role plays a critical part in the third-party risk lifecycle, with a primary focus on driving effective risk treatment plans, collaborating with internal stakeholders and vendors to remediate control gaps and reduce exposure in the supply chain. Key Responsibilities: • Analyze third-party security assessments to identify risk findings and determine appropriate treatment strategies (e.g., remediation, compensating controls, or acceptance). • Collaborate with vendors, procurement, legal, and business stakeholders to document and manage risk treatment plans based on due diligence and ongoing monitoring results. • Track and follow up on risk remediation activities, ensuring that treatment plans are executed within agreed timelines. • Maintain a centralized register of third-party risk treatment activities and ensure all documentation is audit-ready. • Recommend and support the implementation of compensating controls or alternative mitigation actions when direct remediation is not feasible. • Escalate high-risk third-party issues and delays in remediation to leadership. • Contribute to the enhancement of third-party risk management frameworks, processes, and tools, ensuring alignment with NIST CSF, ISO 27001, and regulatory requirements. • Provide insights and reporting on risk trends, treatment status, and control effectiveness across the third-party portfolio. • Support audit, regulatory, and internal assurance activities related to third-party cybersecurity risk. Qualifications: • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related discipline. • 3+ years of experience in IT or cybersecurity risk management, with specific experience in third-party or vendor risk. • Strong knowledge of third-party risk management frameworks and control standards (e.g., NIST, ISO 27001, SIG, SOC 2, CSA). • Hands-on experience reviewing third-party security assessments, risk questionnaires, and due diligence documentation. • Familiarity with GRC or third-party risk platforms (e.g., Onspring, OneTrust, Archer, ServiceNow, Prevalent, BitSight, Panorays). • Excellent communication and negotiation skills to work with internal and external stakeholders. • Industry certifications (e.g., CRISC, CTPRP, CISA, CISSP) are a plus.
Skills
Compliance Management, GRC, Internal Controls, Risk Management, Audit Support, Due Diligence, ISO 27001, NIST 800-53, SOC 2, Stakeholder Management, Legal Operations
About UST
UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.