# Third-Party Risk Management 1

**Company**: IT Infrastructure
**Location**: New York, New York
**Experience**: senior
**Job type**: full-time
**Salary**: $175,000 to $250,000
**Category**: IT
**Industry**: Finance

**Apply**: https://mlp.eightfold.ai/careers/job/755958689251?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_8af93ba2-1a9

## Description

We are seeking a Third-Party Risk Management 1 professional to join our Information Technology team at Millennium, a global alternative investment firm.

The successful candidate will conduct security risk assessments for prospective and existing vendors, evaluate findings, and recommend remediation or risk acceptance.

Key responsibilities include:

- Conducting security risk assessments for vendors, including questionnaire reviews and technical discussions

- Evaluating findings and recommending remediation or risk acceptance

- Preparing clear risk assessment reports and maintaining accurate records

- Communicating findings and implementation requirements to stakeholders

- Tracking remediation of identified security gaps

- Partnering with vendor management, procurement, and legal teams to embed security requirements into contracts

- Monitoring existing vendors for security incidents and adverse news

- Improving the third-party risk management program through methodology enhancements and automation

The ideal candidate will have:

- Experience conducting vendor security risk assessments, with familiarity with NIST CSF, SOC 2, ISO 27001, CIS Controls, SIG, and CAIQ

- Ability to analyze penetration-test reports and architecture diagrams

- Strong critical thinking and risk judgment

- Excellent written and verbal communication skills

- Ability to manage multiple assessments and deadlines effectively

- Bachelor's degree or higher in Computer Science, Cybersecurity, or a related field

- Five or more years of hands-on third-party risk management experience, with relevant security certifications preferred

- Experience with AI models, tools, and infrastructure, as well as on-premises and cloud infrastructure, is preferred

Millennium offers a total compensation package, including a base salary, discretionary performance bonus, and comprehensive benefits. The estimated base salary range for this position is $175,000 to $250,000.

## Skills

### Required
- NIST CSF
- SOC 2
- ISO 27001
- CIS Controls
- SIG
- CAIQ
- penetration-test reports analysis
- critical thinking
- risk judgment
- written and verbal communication

### Nice to have
- CTPRP
- CTPRA
- CISA
- CISSP
- AI models
- on-premises and cloud infrastructure
- TPRM platforms
- reporting and automation tools
- Windows
- Linux
- macOS

---

Source: [Apply at mlp.eightfold.ai](https://mlp.eightfold.ai/careers/job/755958689251?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
