TPRM Security Analyst


UpGuard, Inc. logo
UpGuard, Inc.
Apply now Apply later

Posted 2 weeks ago

Who are we?
UpGuard’s mission is to protect the world’s data. We obsessively seek out elegant, robust ways to enable our customers to find, acknowledge, and remediate cyber risk. With UpGuard, organizations leverage our security expertise and software to automate what were once laborious, spreadsheet-driven processes–whether it's monitoring the attack surface of hundreds of vendors or assessing the security of their own infrastructure. UpGuard is used by some of the world’s largest, fastest growing, and most innovative companies. 
Why are we hiring this role?
We have successfully implemented TPRM Security Managed Services for our customers and are looking to scale these efforts therefore need to scale the team!

What will you accomplish?

  • Translate complex and technical aspects into a report so that the business can understand it
  • Partner with customers to identify, measure and manage Third Party risks and controls
  • Assist with standardised reports, templates and scorecards used to inform customers on third party risks
  • Perform data leaks searches on each managed service vendor
  • Work closely with various teams including, sales and customer success to understand the changing needs of our customers
  • Develop and maintain working knowledge of emerging financial, operational, third party and regulatory/compliance related information to contribute to the continuous improvement of the Third Party risk management offering

What do we need from you?

  • Knowledge of relevant security frameworks, standards, requirements, laws e.g. ISO 27001, PCI DSS, APRA CPS 234, NIST CSF etc.
  • Thorough understanding of cybersecurity risk management
  • 3+ years of experience in Risk Management, Third Party Risk, Auditing or the equivalent
  • Understanding of Third Party risk management practices, including the lifecycle of risk identification, treatment, mitigation, acceptance, remediation as well as inherent and residual risks.
  • Have a track record of mastering highly technical problem spaces
  • Possess strong written and verbal communication skills, with a talent for precise articulations of customer problems

What would give you an edge?

  • Bachelor Degree in the fields of Information Systems or related major
  • Any relevant professional certification, such as Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC), Certified Regulatory Vendor Program Manager (CRVPM) or Certified Third Party Risk Professional (CTPRP)
  • Performed data leaks assessments
  • Experience in managing customer expectations
  • Experience or a keen interest in cybersecurity

What's in it for you?

  • Rapidly growing user base: Work directly with some of the world’s largest, fastest growing, and most innovative companies
  • Interesting problems, at scale: Deeply explore the ever-evolving world of cybersecurity, with a platform processing billions of data points daily
  • Learn from industry-leading experts: Our security research has been featured in The New York TimesThe New YorkerThe Washington PostTechCrunchBloombergGizmodoEngadgetForbesZDNet, and The Guardian
  • Impact: See the impact of your work on a daily basis, with data and impact available on dashboards you have access to
  • Work-life balance: No late finishes or unneeded stress, keep your plans with friends and family
  • Generous compensation: Extremely competitive base salary and equity 
  • Great perks: Free lunch, flexible work arrangements, and gym reimbursement

Job tags: Auditing CISA CISM CISSP Encryption ISO 27001 NIST PCI