Why This Role Stands Out
This remote, full-time role offers the opportunity to significantly impact a top-ranked healthcare institution by enhancing their information security risk management program, with a competitive annual salary of $105,000 - $110,000. You'll thrive here if you're a mid-senior level professional with 3+ years of cybersecurity experience, eager to hone your vendor risk assessment skills and contribute to a robust GRC team. Apply today to leverage your expertise and grow your career in a flexible, impactful environment.
Quick Overview
Job Description
Job Title: Information Security Third Party Risk Management Analyst
Location: Remote USA
Position: Full-Time Direct Hire
Join a Top Ranked Healthcare Institution
TalentFish is casting a line for an Information Security Third Party Risk Management (TPRM) Analyst. This is a Full-Time hire remote position in the United States. Candidates must be able to work Central Standard Time (CST) business hours.
Overview
- The Third Party Risk Management Analyst will play a critical role within the Governance, Risk and Compliance (GRC) team, executing and enhancing the organization's information security risk management program.
- Third-party risk management is a primary focus of this role, including independently conducting vendor risk assessments and managing identified risks through remediation and closure.
- You will independently conduct risk analysis on information systems, platforms, and processes in accordance with established regulatory requirements, organizational policies, and industry standards, leading and contributing to the identification, assessment, documentation, mitigation, and communication of information security risks across the organization.
What You Bring to the Role / Experience and Qualifications
- Bachelor's degree required in Information Security, Computer Science, Engineering, Information Technology, or related field; master's degree preferred.
- 3+ years of cybersecurity experience, information security risk management, third-party risk management, or audit experience.
- Clinical healthcare industry experience preferred but not required.
- Experience with risk management/GRC platforms; experience supporting risk platform implementations, upgrades, or process enhancements is beneficial.
- Experience managing a high volume of third-party risk assessments (e.g., 40+ risk assessment requests) from initiation through completion while meeting service-level timelines.
- Demonstrated experience with risk assessment methodologies, auditing, information security practices, and familiarity with risk management platforms and risk registers.
- Demonstrated experience identifying vendor risks and managing corrective action plans through remediation and closure in partnership with vendors, business stakeholders, and internal teams.
- Strong understanding of regulatory compliance and industry best practices for maintaining compliance with HIPAA, NIST, and other relevant healthcare regulations and standards.
- One or more of the following certifications required or must be obtained within 12 months of hire: CRISC, CISM, CISA, or any other applicable certification.
- Ability to lead and structure risk assessments with limited supervision and manage multiple concurrent assessments and projects in a fast-paced healthcare setting.
- Experience preparing both detailed technical risk reports and executive-level summaries tailored to varied audiences.
- Strong stakeholder management skills with the ability to communicate risk findings, influence remediation decisions, and drive action across technical and non-technical groups without direct authority.
- Strong written, verbal, and interpersonal communication skills, with the ability to translate technical findings into business-relevant language for leadership audiences.
- Experience tracking audit findings, third-party vendor risks, and remediation efforts, and analyzing contractual security language to identify risk exposure.
- Experience supporting the development and maintenance of information security policies, standards, and procedures.
What You'll Do
- Lead and conduct comprehensive information security risk analysis for IT assets, applications, processes, medical devices, and third-party vendors.
- Evaluate threats and vulnerabilities affecting the confidentiality, integrity, and availability of ePHI and other confidential or sensitive information, ensuring alignment with HIPAA Security Rule requirements and other applicable regulatory frameworks (e.g., NIST).
- Lead and manage risk management initiatives based on analysis of outcomes, including maintaining the organization's risk register and scoring methodology.
- Oversee corrective action plans (CAPs), penetration testing results, audit findings, and risk treatment outcomes.
- Collaborate with IT partners and key stakeholders to prioritize, implement, and track remediation efforts.
- Monitor regulatory changes and industry threats to proactively identify emerging risks, recommend mitigation strategies, and document findings.
- Contribute to risk reporting, including executive dashboards, and participate in risk acceptance processes and governance reviews.
- Contribute to the development, review, and improvement of cybersecurity policies, standards, and procedures, and evaluate policy exceptions for governance committees.
- Enhance the organization's cybersecurity awareness and training efforts by communicating risk insights to technical and non-technical audiences.
Compensation and Employment
This role requires authorization to work in the U.S. without current or future visa sponsorship. The expected salary range for this position is $105,000-$110,000 per year, depending on experience and qualifications. This role also qualifies for comprehensive benefits such as health insurance, 401(k), and paid time off. TalentFish is committed to pay transparency and equal opportunity. The salary range provided is in compliance with applicable state and federal regulations. All offers are contingent upon the completion of a background check, which may include but is not limited to reference checks, education verification, employment verification, drug testing, criminal records checks, and any required certifications or compliance requirements based on the end client's background check policies and applicable laws.
TalentFish is an employee-owned company pioneering a new realm in talent acquisition. We are redefining IT staffing by evolving AI, video screening, and our unique platform. TalentFish focuses on providing the best employee, consultant, and client experience possible. TalentFish is an Equal Opportunity Employer; we embrace and encourage diversity.
Similar jobs
- NG
2027 Associate Cyber Systems Engineer/Cyber Systems Engineer - C with Security Clearance
NewNorthrop Grumman
San Diego, CA🇺🇸$83.8k - $125.8k/yrOn-site19 hours agoHTTPTechnology - MI
Lead Cyber Security Engineer with Security Clearance
MITRE Corporation
McLean, VA🇺🇸$158.8k - $198.5k/yrHybrid2 months agoMachine LearningAgileTechnology - ST
Cyber Threat Hunter (Evening/Night Shifts) with Security Clearance
NewStratasCorp
Pensacola, FL🇺🇸$80k - $85k/yrOn-site19 hours agoTechnology - TC
Cyber Security Engineer with Security Clearance
NewTEKsystems c/o Allegis Group
Washington Dc Brm, DC🇺🇸Hybrid19 hours agoSplunkConfluenceJira+1Technology - KA
Information Systems Security Engineer (ISSE) – Skill Level 2 with Security Clearance
NewKaizen Approach, Inc
Annapolis Junction, MD🇺🇸Hybrid19 hours agoCSSTechnology - TI
Lead Palo Alto Cyber Specialist
NewTwo95 International
Camden, NJ🇺🇸Hybrid19 hours agoTechnology