placement.solutions
HomeJobsSimpson Thacher › Senior Analyst, Third-Party Security

Senior Analyst, Third-Party Security

Simpson Thacher
New York, NY
The Senior Analyst, Third-Party Security will play a key role in supporting the Third-Party Security Team in both the development and execution of the firm’s Third-party Security Program. This includes identifying, assessing, monitoring, and mitigating risks associated with vendors, suppliers, and service providers across the globe as well as supporting strategic program initiatives. The ideal candidate is an experienced information security or IT risk management professional with a background in third-party assessment execution, IT Risk management or IT Audit. The candidate should possess strong analytical skills, attention to detail, and the ability to collaborate cross-functionally with legal, Vendor Management Office, and IT security teams. Strong communication and interpersonal skills are required to effectively engage with third parties and program stakeholders. Essential Job Duties & Responsibilities Conduct information security due diligence including secure by design reviews, during vendor onboarding, at renewal, and periodic review cycles. Apply a risk-based approach to third party security assessments, including documenting compensating controls and risks acceptances where appropriate. Evaluate third-party architectures, including network connectivity (VPN, reverse proxy), data flows, encryption models, and access controls. Assess risks related to cloud environments (AWS/Azure/GCP), SaaS platforms, and API integrations. Analyze external risk intelligence sources (e.g., BitSight, SecurityScorecard) and correlate with internal findings. Review and challenge secure design, identity/access models (SSO, OAuth, SCIM), and data protection mechanisms. Enhance and maintain a comprehensive vendor inventory, including vendor profiling and inherent risk determination. Enhance and maintain a third-party risk register and track mitigation efforts for identified security risks. Develop and implement strategies to mitigate identified risks, working closely with third parties and internal stakeholders to address security gaps. Support a continuous monitoring program to assess third-party security posture and follow up on identified vulnerabilities and security risks. Partner with general counsel and vendor management to incorporate information security requirements into third-party contracts. Work with internal security teams to investigate and respond to third-party related security incidents. Support and enhance escalation procedures and remediation requirements related to third-party security breaches. Prepare and present third-party risk metrics, dashboards, trends, and highlighted risks to senior management and IT leadership. Contribute to the continuous improvement and scalability of the Firm’s third-party security risk management program. Partner with the Third Party Security Senior Manager to build and enhance strategic objectives of the program. Education Required Bachelor’s degree or related experience required Preferred Professional cert
Apply on firm site →