All roles

Third Party Risk Senior Consultant

Remote · USA Full-time New today

About the position Your Journey at Crowe Starts Here: At Crowe, you can build a meaningful and rewarding career. With real flexibility to balance work with life moments, you’re trusted to deliver results and make an impact. We embrace you for who you are, care for your well-being, and nurture your career. Everyone has equitable access to opportunities for career growth and leadership. Over our 80-year history, delivering excellent service through innovation has been a core part of our DNA across our audit, tax, and consulting groups. That’s why we continuously invest in innovative ideas, such as AI-enabled insights and technology-powered solutions, to enhance our services. Join us at Crowe and embark on a career where you can help shape the future of our industry. Job Description: Third Party Senior Staff Job Summary: The position will be primarily responsible for assessing the information security posture of key clients’ third parties and coordinating the overall execution and delivery of assessments. The position will work within a Crowe team at a client or third party site and be responsible for leading the effort to identify key risks and information security gaps. Projects would be performed through interacting with the client’s IS and Business Unit leadership, as well as the client’s vendors, service providers, and partners. Specific projects may include: Conducting Third Party Risk Assessments by evaluating third party questionnaire responses, performing control validation, and assessment of documentation per established procedures and standards Performing site visits to third-party facilities Evaluating the effectiveness of security controls for compliance with applicable policies, security laws, and regulations Assessing cloud technologies such as Software as a Service (SaaS) hosted applications, Platform as a Service (PaaS), and Infrastructure as a Service deployments (IaaS) Documenting information security risk and compliance findings and recommendations for remediation Perform quality assurance and review of assessments performed by other team members Delivering high quality, thorough reports Coordinating the schedules and assessments for key third party clients and overseeing all key deliverables Our clients operate in and our team members work across the following industries: Pharmaceutical Life Sciences Biotechnology Healthcare Manufacturing Financial Services Technology, Media and Telecomm

Responsibilities

  • Conducting Third Party Risk Assessments by evaluating third party questionnaire responses, performing control validation, and assessment of documentation per established procedures and standards
  • Performing site visits to third-party facilities
  • Evaluating the effectiveness of security controls for compliance with applicable policies, security laws, and regulations
  • Assessing cloud technologies such as Software as a Service (SaaS) hosted applications, Platform as a Service (PaaS), and Infrastructure as a Service deployments (IaaS)
  • Documenting information security risk and compliance findings and recommendations for remediation
  • Perform quality assurance and review of assessments performed by other team members
  • Delivering high quality, thorough reports
  • Coordinating the schedules and assessments for key third party clients and overseeing all key deliverables

Requirements

  • Bachelor's Degree
  • Information Technology and/or Cybersecurity background and/or experience, including 2-4 years IT experience with network, platform, and/or application technology
  • Willingness to obtain the Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), or Certified Third Party Risk Assessor (CTPRA) designations
  • Knowledge of security areas such as auditing, policy, database security, firewall design and implementation, risk analysis, identity management, access management, or web
  • Working knowledge of at least one compliance framework, such as SOC2, ISO 27001, NIST, HIPAA
  • Experience managing multiple projects, in a fast-paced environment
  • Proven ability to learn new technologies and systems, especially through independent research and self-study
  • Ability to communicate technical information verbally and through written documentation
  • Ability to manage project schedules and client expectations
  • Ability to travel domestically an average of 20%-50% per year

Nice-to-haves

  • Bachelors and/or advanced degree with a concentration in: Cybersecurity, Risk Management, Computer Science, or Management Information Systems
  • Any experience working with or assessing third party vendors is preferred but not required
  • IT experience at a leading industry public company. This might include either IT auditing or being a member of an IT or Cybersecurity team
  • Experience with Archer, Process Unity, ServiceNow or other GRC/VRM tools
  • Experience with security ratings platforms
  • Bilingual
  • Open to remote

Apply tot his job Apply To this Job

Related roles

Experienced Virtual Data Entry and Research Associate – Remote Work Opportunity for Motivated Individuals

Remote · USA Full-time

Experienced Data Entry Clerk and Focus Group Participant – Remote Work from Home Opportunity with Flexible Hours and Competitive Compensation

Remote · USA Full-time

Experienced Remote Sales Chat Representative – Shipping Container Sales and Customer Engagement Specialist

Remote · USA Full-time

Experienced Remote Data Entry Specialist – Flexible Work from Home Opportunity with arenaflex

Remote · USA Full-time

Experienced Customer Service Representative – Delivering Exceptional Support and Driving Business Growth at arenaflex

Remote · USA Full-time

Experienced Customer Service Representative – Remote Live Chat Specialist for Construction Industry Leader

Remote · USA Full-time

Experienced Part Time Remote Data Entry Specialist – Entry Level Opportunity for Career Growth and Development at arenaflex

Remote · USA Full-time

Experienced Remote Data Entry Clerk – Full-Time and Part-Time Opportunities for Career Growth and Development at arenaflex

Remote · USA Full-time

Experienced Remote Data Entry Specialist for Teens – No Prior Experience Required, Flexible Hours, and Comprehensive Training Provided at arenaflex

Remote · USA Full-time

Experienced Customer Experience Representative – Mom and Baby Division – Remote Opportunity at arenaflex

Remote · USA Full-time

Events & Marketing Manager | Zip | $90k-$115k | Remote (USA)

Remote · USA Full-time

[Remote] Manager, Customer Master / MDM Platform

Remote · USA Full-time

Property Adjuster (Trainee)- Southern Maryland

Remote · USA Full-time

Senior Backend Engineer - Health Profile team (100% remote-friendly within Spain)

Remote · USA Full-time

Senior Staff Cybersecurity Threat Analyst - Cyber Incident Response - Remote US Available

Remote · USA Full-time

Experienced Customer Support Representative – Online Remote Position at arenaflex

Remote · USA Full-time

Technology Transformation Senior Consultant (GUY) @ EY

Remote · USA Full-time

Ortho Registered Dental Assistant

Remote · USA Full-time

BCaBA (Board Certified Assistant Behavior Analyst) Full Time

Remote · USA Full-time

AIRLINE Inside Sales & Reservations / Ticketing Representative

Remote · USA Full-time