Sr. Risk Analyst
Current- Gather information security controls evidence (policies/procedures) from Third-Parties on behalf of clients
- Maintain an inventory of approved Legal and Healthcare vendors & reassess them based on their risk rating
- Create and deliver online information risk surveys (SIG, NYDFS, H-ISAC, PCF) to our clients’ third-party vendors, which would include monitoring, technical support, and final provisioning of reviewed results
- Overcome steep learning curves and have a basic understanding of software application structure and software development lifecycles
- Remediating vendor risks based on criticality and other key controls
- Create documentation and reports (Baseline Executive Analysis, Risk Review, Contextual Risk Review, SOC2 Review) based on assessment and documented material