Job Description
• Perform third‑party information security risk and control assessments
• Support vendor assessment planning, due diligence, and continuous monitoring efforts
• Identify and report information security risks related to third‑party vendors
• Provide recommendations to improve vendor security and risk management practices
• Maintain and improve third‑party security assessment processes and procedures
• Assist with third‑party incident reporting activities as needed
Collaborate cross‑functionally with Security, Technology, and Business stakeholders
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Required Skills & Experience
• 7–10 years in Sec and/or Third‑Party Security Risk Management
○ applying CSF
○ ex: Assessing Cloud Risk - managing cloud services from a vendor perspective
• Hands‑on experience performing third‑party/vendor security risk assessments
• Strong knowledge of information security risk and control assessment methodologies
• Experience working with security frameworks such as NIST, FFIEC, and COBIT
• Ability to identify, document, track, and report third‑party security risks
○ just moving from Vendor Insight or Prevalent (third party risk platform (not what security uses, just 3rd party))
§ another automated vendor system (can't be someone that's done word and excel for this)
○ MS365
○ SmartSheets
Regulated industry
Nice to Have Skills & Experience
• Big 4 audit background
• Prior experience supporting or partnering with Third‑Party Risk Management (TPRM) teams
• Information Security–related certifications
• Experience preparing executive‑level reporting and presentations
AI Background
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.