Cybersecurity BA
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Our client is seeking a Cybersecurity Business Analyst to support its Third-Party Risk Management team. This individual will be responsible for conducting cybersecurity risk assessments on vendors, SaaS platforms, hardware providers, consulting organizations, and other third parties that interact with company systems, data, or infrastructure.
This role requires a strong blend of cybersecurity knowledge, business analysis, risk management, and stakeholder communication. The ideal candidate will be comfortable reviewing technical security documentation, identifying potential risks, interacting directly with vendors, and presenting findings to business leaders and stakeholders in a clear and concise manner.
This is a fast-paced environment where the analyst will manage multiple assessments simultaneously while partnering closely with business units, procurement, legal, IT, and cybersecurity teams.
Conduct cybersecurity risk assessments throughout the vendor lifecycle for software, SaaS platforms, hardware, cloud services, and consulting engagements.
Review vendor security documentation including
SOC reports
Security policies
Penetration test results
Compliance certifications
Risk questionnaires
Architecture and security documentation
Evaluate vendor cybersecurity controls and identify potential security, compliance, operational, and data protection risks.
Assign risk ratings and develop risk findings, recommendations, and remediation requirements.
Engage directly with vendors to obtain missing documentation and clarify security controls.
Work closely with business stakeholders to understand vendor use cases, data flows, and business requirements.
Analyze cloud, SaaS, on-premises, and AI-related technology solutions to determine potential cybersecurity risks.
Maintain documentation and assessment records within enterprise risk management platforms.
Present assessment findings and recommendations to directors, managers, and business stakeholders.
Assist business units in understanding assessment results and risk-related impacts.
Partner with legal, procurement, IT, and security teams to support vendor onboarding and approval processes.
Manage multiple vendor assessments concurrently while meeting established service-level expectations.
Requirements
Bachelor’s degree in Cybersecurity, Information Security, Information Systems, Computer Science, Business, or a related field.
5+ years of experience performing:
Third-Party Risk Management (TPRM)
Vendor Risk Assessments
Cybersecurity Audits
Information Security Assessments
Governance, Risk & Compliance (GRC)
Strong understanding of
SaaS platforms
Cloud technologies
Microsoft technologies and services
Enterprise applications
Vendor security review processes
Experience reviewing
SOC 1 / SOC 2 reports
Security policies
Penetration testing reports
Risk assessments
Compliance documentation
Ability to identify cybersecurity risks and effectively communicate findings to both technical and non-technical audiences.
Excellent verbal and written communication skills.
Strong stakeholder management and interpersonal skills.
Ability to thrive in a high-volume, fast-paced environment managing multiple assessments simultaneously. CISA (Certified Information Systems Auditor)
Certified Third-Party Risk Assessor (CTPRA) or similar risk-related certification
Experience with AI-related risk assessments and emerging AI technologies
Experience evaluating cloud-based solutions and vendor-hosted environments
Familiarity with cybersecurity frameworks such as
NIST, Experience using GRC, BitSight, SecurityScorecard, Dun & Bradstreet, or similar risk management tools
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
What Are The Top Skills Required For Azure Developers?
Walking Into The Era of Supply Chain Risks