Third-Party Cyber Risk Analyst
hace 18 horas
Irving
The Company NorthMark Strategies is a leading investment firm, combining capital, innovation, and engineering to drive long-term value. From operating complex businesses to backing breakthrough technologies, our mission is to build enduring businesses. Our team combines intelligent risk-taking, operational excellence, exceptional talent, and world-class computing capacity to create shareholder value. Our company offers a dynamic environment where individuals have the freedom to lead companies toward bold achievements by embracing innovation, leveraging technology, and fostering differentiated business strategies. Our values are Integrity, Ability, and Energy, and the company aims to hire individuals who possess those qualities. At NorthMark Strategies, we believe the future isn’t something to hope for, it’s something to build. We don’t just invest, we create. Bringing together strategic insight and technical horsepower to deliver outcomes that endure. The Position The Third-Party Cyber Risk Analyst will join the global effort in driving NorthMark Strategies' Third-Party Cyber Security Risk Management program in identifying, assessing, and managing risks to NorthMark Strategies and associated Enterprise companies. As a member of the IT Risk and Compliance team and part of the Office of the CISO, this role will be critical in maturing the current Third-Party risk program and creating/building new processes as part of an effort to grow our security maturity across our portfolio of companies. The ideal candidate is a proven thought leader, problem solver, and integrator of people and processes, as well as an effective internal consultant who is comfortable leveraging AI-assisted tooling to deliver faster, higher-quality vendor assessments. Reporting to the Manager of Third-Party Risk Management, this role will work alongside the broader Technology and Security teams to assess and quantify the risk presented by third parties in use across the group. This includes, but is not limited to, pre-contract cyber diligence for portfolio company vendor and third-party relationships, risk identification, and mitigation planning based on third-party risk profile. To be successful in this role, you will need to be a self-starter, ready to dig into new vendors and third parties, thorough in your evaluation of their security posture, and able to clearly convey any risks to both technical and non-technical stakeholders. You should be equally comfortable scrutinizing a SOC 2 report, interrogating a vendor's AI sub processor chain, and using AI-assisted platforms to accelerate questionnaire review and artifact analysis. This role will be responsible for identifying, evaluating, and reporting on third-party information security risks across the portfolio, and will work with our portfolio companies to assess their third-party risks, communicate those risks, and on an ongoing basis perform risk assessments of new vendors and third parties requested by the business. Responsibilities: • Lead risk/security assessments of suppliers and Third Parties to identify, validate, and remediate Cybersecurity Risks. Plan, coordinate, and lead assessments of Third Parties against NorthMark’s security framework and industry security standards., • Analyze a vendor's threat model at intake to scope a tightly focused review, tying the business use case to the risks it introduces, and the controls needed to mitigate them with a focus on identifying the true nature of the risk., • Conduct privacy-focused reviews of vendor data handling practices, including DPA terms, sub-processor disclosures, international data transfer mechanisms, and alignment with applicable privacy regulations., • Perform targeted assessments of vendor AI capabilities — including AI subprocessor chains, model training data practices, data retention and deletion commitments, and governance around enterprise vs. consumer AI tiers — and translate those findings into clear recommendations for the business., • Leverage AI-assisted TPRM platforms (e.g., Lema) and large language model to accelerate questionnaire review, artifact analysis, and report drafting, while applying sound analytical judgment to validate AI-generated outputs and identify gaps the tooling may miss., • Support ongoing monitoring of suppliers and third parties to review compliance against regulatory and contractual requirements, including monitoring changes to vendor AI feature scope, subprocessor composition, and certification posture between recertification cycles., • Identify, prioritize, and pursue opportunities to enhance NorthMark’s TPRM processes and introduce innovative approaches and solutions to optimize efficiency and effectiveness. Contribute towards process improvement of team processes, templates, and tools., • Develop trusted relationships with Business Partners, portfolio and group company IT Executives, Security & Compliance Officers, and other teams. Provide stakeholders with strong customer service-oriented guidance through TPRM requirements., • Stay current on the broader regulatory landscape affecting NorthMark's group business areas, including emerging AI governance frameworks (e.g., EU AI Act, NIST AI RMF, state-level AI legislation) alongside traditional privacy and security regulations., • Collaborate with internal partners and third parties to identify, track, and provide recommendations on mitigating third-party risks, including risks introduced by embedded AI features, browser extensions, marketplace applications, and other non-standard integration patterns., • Provide strategic cybersecurity third-party risk advisory and compliance expertise for portfolio and group companies, ranging from security assessments to policy definition/adoption., • Document current state of existing Third-Party Risk Management processes including controls, processes, and technologies and deliver key findings and recommendations., • Design, build, and iterate on agentic AI workflows that automate or augment TPRM processes — including vendor intake routing, questionnaire scoring, risk narrative generation, and assessment report drafting — using tools such as Claude API, Python-based orchestration frameworks, or no-code AI workflow platforms., • Develop implementation strategies and roadmaps to help our portfolio and group companies implement Third-Party Risk Management and onboard them to the NorthMark processes., • Perform peer review of assessment reports drafted by teammates and outsourced providers, ensuring accuracy, consistency with NorthMark standards, and professional quality of the final deliverable. Requirements: • 3 years of proven working experience in operational risk management, information security, cybersecurity, IT audit, crisis management, security standards and assessments, or risk management in a Big 4 or similar organization., • At least 1 year of proven working experience focused on supply chain or third-party risk management., • Demonstrated familiarity with AI/ML technologies as they appear in enterprise SaaS — including a working understanding of concepts such as model training, RAG architecture, prompt injection risk, data retention for AI training, and the distinction between enterprise and consumer AI deployments., • Hands-on experience using AI-assisted tools (e.g., Claude, ChatGPT, Copilot, or AI-enabled GRC platforms) to support analytical or written work, with the ability to critically evaluate AI-generated output for accuracy, completeness, and relevance., • Experience in a customer/client-facing environment delivering products, providing presentations, and running client status meetings., • Solid understanding of risk management concepts, particularly related to third-party risk management, information security, IT general controls, and basic audit terminology and concepts., • Attention to detail, sound judgment, logical thinking, and proven ability to drive tasks to completion, meet deadlines in a fast-paced environment, and adapt to a changing business environment with periodic supervision., • Demonstrated professional communication and client relationship skills., • Experience reviewing the work of outsourced providers and team members to ensure that assessment reports and overall product quality are professional and accurate, with the ability to effectively manage multiple tasks simultaneously., • Understanding of compliance, fraud, and risk mitigation frameworks; NIST (including NIST AI RMF), ISO (including ISO/IEC 42001 familiarity a plus), CIS, • Demonstrated hands-on experience building or prototyping agentic AI workflows in a professional or substantive project context. Expert-level development experience not required; curiosity, initiative, and willingness to learn are, • Bachelor’s degree with cyber, IT management, or strong technical focus required (e.g., information technology, computer science, management information systems)., • Certification in security or risk management (CTPRP, CRISC, CISA, CISM, or similar) preferred., • AI governance or AI risk-related credentials (e.g., IAPP AIGP, ISACA AAIA) a plus., • This role operates on a hybrid schedule requiring a minimum of 3 days per week in-office at either our Dallas, TX or New York, NY office. Candidates must be based in or willing to relocate to one of these locations.