Senior Analyst, Third-Party Security

Simpson Thacher
New York, New York 10261 United States  View Map
Posted: Jun 09, 2026
  • Full Time
  • Federal Government
  • Summary

    Senior Analyst, Third-Party Security The Senior Analyst, Third‑Party Security will play a key role in supporting the Third‑Party Security Team in both the development and execution of the firm's Third‑party Security Program. This includes identifying, assessing, monitoring, and mitigating risks associated with vendors, suppliers, and service providers across the globe as well as supporting strategic program initiatives. The ideal candidate is an experienced information security or IT risk management professional with a background in third‑party assessment execution, IT Risk management or IT Audit. The candidate should possess strong analytical skills, attention to detail, and the ability to collaborate cross‑functionally with legal, Vendor Management Office, and IT security teams. Strong communication and interpersonal skills are required to effectively engage with third parties and program stakeholders.Responsibilities Conduct information security due diligence including secure by design reviews, during vendor onboarding, at renewal, and periodic review cycles.Apply a risk‑based approach to third party security assessments, including documenting compensating controls and risks acceptances where appropriate.Evaluate third‑party architectures, including network connectivity (VPN, reverse proxy), data flows, encryption models, and access controls.Assess risks related to cloud environments (AWS/Azure/GCP), SaaS platforms, and API integrations.Analyze external risk intelligence sources (e.g., BitSight, SecurityScorecard) and correlate with internal findings.Review and challenge secure design, identity/access models (SSO, OAuth, SCIM), and data protection mechanisms.Enhance and maintain a comprehensive vendor inventory, including vendor profiling and inherent risk determination.Enhance and maintain a third‑party risk register and track mitigation efforts for identified security risks.Develop and implement strategies to mitigate identified risks, working closely with third parties and internal stakeholders to address security gaps.Support a continuous monitoring program to assess third‑party security posture and follow up on identified vulnerabilities and security risks.Partner with general counsel and vendor management to incorporate information security requirements into third‑party contracts.Work with internal security teams to investigate and respond to third‑party related security incidents.Support and enhance escalation procedures and remediation requirements related to third‑party security breaches.Prepare and present third‑party risk metrics, dashboards, trends, and highlighted risks to senior management and IT leadership.Contribute to the continuous improvement and scalability of the Firm's third‑party security risk management program.Partner with the Third Party Security Senior Manager to build and enhance strategic objectives of the program.Education Bachelor's degree or related experience required.Skills & Experience 10+ years of progressive experience in information security, third‑party risk management, IT risk, or cybersecurity assurance, with at least 3 years focused on third‑party risk management.Strong understanding of information security controls and frameworks (ISO 27001/27002, NIST CSF, CIS Controls, etc.).Proficient understanding of third‑party security domains, including data protection, access controls, incident response and cloud security.Proven ability to perform third‑party security risk assessments by reviewing security questionnaires, audit reports, policies and penetration test results to identify control gaps, formulate follow‑up inquiries, and document remediation requirements.Deep knowledge of technology supplier ecosystems (software, cloud, IT labor, and infrastructure) and associated risk dynamics.Experience producing clear risk summaries, remediation recommendations, and executive level reporting.Familiarity with information security and data protections requirements in third‑party contracts.Excellent communication skills: clear, structured, persuasive with the ability to educate and inspire teams around risk and performance ownership.Proven ability to influence stakeholders without direct authority.Ability to work independently and collaboratively in a team environment.Demonstrated ability to handle sensitive and/or confidential material and information with suitable discretion.Preferred Established track record in building and executing vendor risk frameworks, risk mitigation strategies, and regulatory‑compliant vendor governance programs.Proven ability to articulate technical security considerations to non‑technical stakeholders.Familiarity with information security considerations for vendors leveraging AI or providing AI‑centric solutions.CISSP, CRISC, CISM, CISA, ISO 27001 Lead Auditor/Implementor certification.Salary NY Only: The estimated base salary range for this position is $160,000 to $190,000 at the time of posting. The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible. Simpson Thacher will not sponsor applicants for work visas for this position.Equal Opportunity Simpson Thacher & Bartlett is committed to a collegial work environment in which all individuals are treated with respect and dignity. The Firm prohibits discrimination or harassment based upon race, color, religion, gender, gender identity or expression, age, national origin, citizenship status, disability, marital or partnership status, sexual orientation, veteran's status or any other legally protected status. This Policy pertains to every aspect of an individual's relationship with the Firm, including but not limited to recruitment, hiring, compensation, benefits, training and development, promotion, transfer, discipline, termination, and all other privileges, terms and conditions of employment.#J-18808-Ljbffr

  • Job Description

    Senior Analyst, Third-Party Security The Senior Analyst, Third‑Party Security will play a key role in supporting the Third‑Party Security Team in both the development and execution of the firm's Third‑party Security Program. This includes identifying, assessing, monitoring, and mitigating risks associated with vendors, suppliers, and service providers across the globe as well as supporting strategic program initiatives. The ideal candidate is an experienced information security or IT risk management professional with a background in third‑party assessment execution, IT Risk management or IT Audit. The candidate should possess strong analytical skills, attention to detail, and the ability to collaborate cross‑functionally with legal, Vendor Management Office, and IT security teams. Strong communication and interpersonal skills are required to effectively engage with third parties and program stakeholders.Responsibilities Conduct information security due diligence including secure by design reviews, during vendor onboarding, at renewal, and periodic review cycles.Apply a risk‑based approach to third party security assessments, including documenting compensating controls and risks acceptances where appropriate.Evaluate third‑party architectures, including network connectivity (VPN, reverse proxy), data flows, encryption models, and access controls.Assess risks related to cloud environments (AWS/Azure/GCP), SaaS platforms, and API integrations.Analyze external risk intelligence sources (e.g., BitSight, SecurityScorecard) and correlate with internal findings.Review and challenge secure design, identity/access models (SSO, OAuth, SCIM), and data protection mechanisms.Enhance and maintain a comprehensive vendor inventory, including vendor profiling and inherent risk determination.Enhance and maintain a third‑party risk register and track mitigation efforts for identified security risks.Develop and implement strategies to mitigate identified risks, working closely with third parties and internal stakeholders to address security gaps.Support a continuous monitoring program to assess third‑party security posture and follow up on identified vulnerabilities and security risks.Partner with general counsel and vendor management to incorporate information security requirements into third‑party contracts.Work with internal security teams to investigate and respond to third‑party related security incidents.Support and enhance escalation procedures and remediation requirements related to third‑party security breaches.Prepare and present third‑party risk metrics, dashboards, trends, and highlighted risks to senior management and IT leadership.Contribute to the continuous improvement and scalability of the Firm's third‑party security risk management program.Partner with the Third Party Security Senior Manager to build and enhance strategic objectives of the program.Education Bachelor's degree or related experience required.Skills & Experience 10+ years of progressive experience in information security, third‑party risk management, IT risk, or cybersecurity assurance, with at least 3 years focused on third‑party risk management.Strong understanding of information security controls and frameworks (ISO 27001/27002, NIST CSF, CIS Controls, etc.).Proficient understanding of third‑party security domains, including data protection, access controls, incident response and cloud security.Proven ability to perform third‑party security risk assessments by reviewing security questionnaires, audit reports, policies and penetration test results to identify control gaps, formulate follow‑up inquiries, and document remediation requirements.Deep knowledge of technology supplier ecosystems (software, cloud, IT labor, and infrastructure) and associated risk dynamics.Experience producing clear risk summaries, remediation recommendations, and executive level reporting.Familiarity with information security and data protections requirements in third‑party contracts.Excellent communication skills: clear, structured, persuasive with the ability to educate and inspire teams around risk and performance ownership.Proven ability to influence stakeholders without direct authority.Ability to work independently and collaboratively in a team environment.Demonstrated ability to handle sensitive and/or confidential material and information with suitable discretion.Preferred Established track record in building and executing vendor risk frameworks, risk mitigation strategies, and regulatory‑compliant vendor governance programs.Proven ability to articulate technical security considerations to non‑technical stakeholders.Familiarity with information security considerations for vendors leveraging AI or providing AI‑centric solutions.CISSP, CRISC, CISM, CISA, ISO 27001 Lead Auditor/Implementor certification.Salary NY Only: The estimated base salary range for this position is $160,000 to $190,000 at the time of posting. The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible. Simpson Thacher will not sponsor applicants for work visas for this position.Equal Opportunity Simpson Thacher & Bartlett is committed to a collegial work environment in which all individuals are treated with respect and dignity. The Firm prohibits discrimination or harassment based upon race, color, religion, gender, gender identity or expression, age, national origin, citizenship status, disability, marital or partnership status, sexual orientation, veteran's status or any other legally protected status. This Policy pertains to every aspect of an individual's relationship with the Firm, including but not limited to recruitment, hiring, compensation, benefits, training and development, promotion, transfer, discipline, termination, and all other privileges, terms and conditions of employment.#J-18808-Ljbffr

  • ABOUT THE COMPANY

    • Government Careers
    • Government Careers

    Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.

    Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.

    Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.

    Show more

MORE JOBS

  • Customs and Border Protection Officer

    • Detroit, Michigan
    • U.S. Customs and Border Protection
    • Jun 09, 2026
    • Full Time
    • Education and Training
    • Federal Government
  • AI Security Trainer - Remote Threat Evaluation & Training

    • New York, New York
    • DataAnnotation
    • Jun 09, 2026
    • Full Time
    • Federal Government
  • Security Officer - Corporate Locations

    • New York, New York
    • Alliance Building Services
    • Jun 09, 2026
    • Full Time
    • Public Safety
  • Air Interdiction Agent New Hire Sign-On Incentives

    • Thousand Oaks, California
    • U.S. Customs and Border Protections
    • Jun 09, 2026
    • Full Time
    • Clerical and Administrative Support
    • Federal Government
  • Air Interdiction Agent New Hire Sign-On Incentives

    • Minot, North Dakota
    • U.S. Customs and Border Protections
    • Jun 09, 2026
    • Full Time
    • Clerical and Administrative Support
    • Federal Government
  • Traffic EIT

    • Nashville, Tennessee
    • VOLKERT
    • Jun 09, 2026
    • Full Time
    • Federal Government
    • Transportation or Transit
Show More
Apply Now Please mention you found this employment opportunity on the CareersInGovernment.com Job Board.
Please mention you found this employment opportunity on the CareersInGovernment.com Job Board.