> Markdown version of [/jobs/ext/220760-senior-specialist-information-security-third-party-risk](https://www.wearedevelopers.com/jobs/ext/220760-senior-specialist-information-security-third-party-risk). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Specialist, Information Security, Third Party Risk - **Company:** Planned Parenthood Federation of America - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $88,000.0 - $93,000.0 - **Contract:** Permanent contract - **Skills:** Asana, Confluence, JIRA, Microsoft Basic Data Partition, Spreadsheets, Software as a Service, Cyber Security, Information Systems, Google Tools, PCI Data Security Standards, Workflow Management Systems, Cyber Threat Analysis, Information Technology, RSA Archer Platform - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ae504b9bb734cd40 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or a related discipline (required). * Relevant coursework or training in data privacy, regulatory compliance, or cyber risk management (preferred). * Industry certifications, CTPRA, CTPRP, CISA (preferred). Obtain industry certification within 1 year of hire (required). * 3-6 years of professional experience in information security, vendor risk management, IT/IS risk, or compliance roles (required). * At least 2 years of experience conducting or supporting third-party/vendor security risk assessments, preferably within a regulated industry (e.g., healthcare, finance, or tech) (required). * Experience reviewing vendor security questionnaires, SOC 2 reports, SIG assessments, or similar compliance documentation. * Familiarity with security frameworks such as NIST CSF, HIPAA Security Rule, PCI DSS, and basic data privacy regulations (e.g., CCPA, GDPR). * Hands-on experience using assessment tracking or GRC platforms (e.g., UpGuard, LogicGate, OneTrust, or spreadsheets with workflow tools like Jira or Asana). * Exposure to working with procurement, legal, privacy, or compliance teams during vendor onboarding or contract review cycles. * Ability to carefully review documentation, identify small errors or gaps in responses, and understand technical security controls and how they apply in a third-party context. * Experience in basic contract management, including reviewing contracts, understanding basic terms and general contract language, especially legal documents that require data privacy and security language. * Ability to work in a dynamic, fast-paced environment, managing competing cross-functional priorities and complex requirements. * Excellent ability to conceive, draft, proofread, and edit written materials quickly, including demonstrated ability to understand and communicate about complex, technical, or sensitive subjects in a clear, concise, and engaging manner. * High proficiency in Google products * Flexibility and ability to adapt to quickly changing priorities and ambiguous situations * Commitment and track record of advancing racial equity in both operations and communications. * Commitment to PPFA's mission and diversity, equity, and inclusion, particularly surrounding race equity * A deep commitment to Planned Parenthood's mission of promoting Sexual and Reproductive Health ## Description * The Senior Specialist for the Information Security Third Party Risk Management (TPRM) team will be responsible for executing comprehensive information security risk assessments of third-party vendors engaged by PPFA, Affiliate, and Ancillary organizations. This includes evaluating vendors across multiple risk tiers to ensure they meet internal information security policies, HIPAA and PCI DSS requirements, and applicable regulatory standards. The Senior Specialist will thoughtfully analyze vendor-provided documentation, proactively identify potential risks, collaborate with key parties to determine appropriate risk management strategies, and produce detailed and accurate assessment reports to inform business, procurement, and contracting decisions. This role plays a critical part in safeguarding sensitive organizational data by ensuring that all third-party engagements align with PPFA's privacy, compliance, and cybersecurity expectations and requirements., * The Senior Specialist delivers by managing the end-to-end TPRM process for their assigned vendors. This includes initiating and maintaining communications with internal and external partners; reviewing and analyzing security and compliance documentation; identifying and documenting risks and control gaps; and producing formal assessment reports to inform risk management decisions. This role partners with vendors and internal stakeholders to ensure third-party engagements meet established security, privacy, and compliance requirements, and supports continuous improvement through diligent documentation, analysis, and escalation of identified issues. * Initiate required communications in a timely manner and engage directly with key parties to gather needed information, clarify responses, and support risk management efforts. * Review intake/triage responses in collaboration with the TPRM Manager to determine the appropriate evaluation path based on inherent risk indicators. * Adhere to TPRM-defined SLAs, templates, processes, guidelines, requirements, and expectations throughout the TPRM lifecycle process. * Conduct detailed information security risk assessments of third-party vendors across various risk levels (e.g., SaaS, consulting, low-risk), in alignment with strategies and expectations as defined by the Manager and within TPRM documentation. * Evaluate all vendor-provided documentation and responses against internal policies and applicable regulatory and industry standards, including HIPAA, NIST CSF, PCI DSS, and PPFA information security policies. * Produce clear and actionable risk assessment reports that communicate findings to procurement, legal, security, and business stakeholders to support risk management decision-making. * Collaborate with internal partners to advise on vendor-related risks during intake, onboarding, and renewal processes. * Monitor and report on assessment progress, including delays, risk management status, and escalation needs using risk management tools (e.g., Asana, Jira, GRC platforms, ). * Support and contribute to the maintenance of TPRM documentation, templates, and workflows. Engagement: * Engage directly with internal and external partners to facilitate the information gathering process, clarify responses and security documentation, and support resolution of identified risks. * Collaborate with internal stakeholders such as procurement, legal, privacy, and IT to ensure vendor assessments are aligned with contract and compliance requirements. * Partner with internal risk owners to track and follow up on remediation plans, ensuring timely risk management and communication of outstanding items. * Participate in regular team meetings and working groups to share findings, escalate concerns, and contribute to the improvement of TPRM workflows. * Support the TPRM team by maintaining documentation, resource materials, and tools (e.g., Asana, Confluence, Jira, GRC platforms) for transparency and knowledge sharing. * Represent the TPRM function in cross-functional intake or triage discussions, offering risk input for new or renewing vendor relationships. ## Related Videos - [A Founder's Journey : From Startup Chaos to Purposeful Growth](https://www.wearedevelopers.com/videos/1926-a-founder-s-journey-from-startup-chaos-to-purposeful-growth) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [42 x 2 Canvases Later: Two Years, Two Minds, Many Lessons](https://www.wearedevelopers.com/videos/1458-42-x-2-canvases-later-two-years-two-minds-many-lessons) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)