
Security Analyst II
Fanatics, Inc.
full-time
Posted on:
Location Type: Remote
Location: New York • United States
Visit company websiteExplore more
Salary
💰 $128,250 - $168,750 per year
Tech Stack
About the role
- Conduct comprehensive third-party security risk assessments by evaluating vendor controls, policies, and documentation (e.g., SOC 2, ISO, penetration tests) against established frameworks.
- Analyze assessment results to identify risks, document findings, and provide actionable remediation recommendations.
- Assess risks related to data handling, privacy, critical integrations, and system dependencies
- Assess risks associated with third parties use of emerging technologies, including AI/ML, with a focus on data security and governance
- Collaborate with procurement, legal, and business stakeholders to embed security requirements into vendor onboarding and lifecycle management processes.
- Monitor vendor risk posture over time, including tracking security incidents, control changes, and emerging risks.
- Track, measure, and report on third-party risk metrics, trends, and remediation progress to leadership.
- Support the development, maintenance, and continuous improvement of third-party risk management policies, standards, and procedures.
- Leverage available tools, including AI-assisted technologies, to improve the efficiency and consistency of third-party security risk assessments and documentation.
- Ensure compliance with applicable regulatory and security frameworks (e.g., NIST, ISO 27001, SOX) and support incident response efforts involving third parties.
Requirements
- 2 - 3+ years of experience in cybersecurity, risk management, or third-party/vendor risk management.
- Strong understanding of security frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, and SOC 2.
- Experience reviewing and assessing vendor security documentation (e.g., SOC reports, ISO certifications, security questionnaires).
- Experience working with or supporting third-party risk management programs and tools (e.g., OneTrust, SecurityScorecard)
- Understanding of risks associated with third-party use of AI/ML technologies
- Strong written and verbal communication skills, with the ability to communicate effectively with both technical and non-technical stakeholders.
- Ability to prioritize and balance multiple projects simultaneously
- Ability to collaborate and work in a team environment
Benefits
- For information about our benefits, please visit __https://benefitsatfanatics.com/__
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
cybersecurityrisk managementthird-party risk managementsecurity frameworksNIST CSFNIST 800-53ISO 27001SOC 2data securityemerging technologies
Soft Skills
written communicationverbal communicationcollaborationproject prioritizationteamwork