Description: Security Analyst - Sourcing Security Assurance Team
Location: Oakland, CA
Contract: 1 year+
About the Role:
We are seeking a highly skilled Security Analyst to support our continuous monitoring program, particularly in conducting security assessments of third-party vendors. This role requires strong security expertise, an ability to quickly understand company infrastructure and products, and the capability to deliver audit-ready assessments based on comprehensive research.
Responsibilities:
Conduct security assessments of third-party vendors in accordance with audit standards such as SOC2, ISO 27001, NIST, and PCI.
Review vendor onboarding requests and establish risk profiles.
Perform thorough case investigations and research on vendor usage within the company.
Execute due diligence assurance activities, including reviewing audit reports, risk assessments, and security documentation.
Provide risk-based recommendations and deliver defensible assessments to auditors.
Engage with stakeholders and vendor representatives to ensure compliance and risk mitigation.
Support software governance and continuous monitoring across the enterprise.
Required Qualifications:
Strong understanding of security risks posed by third-party vendors, especially software providers.
Proficiency in authentication and authorization frameworks, including SSO/SAML, OAuth, and OpenID Connect.
Experience in assessing vendor deployment models (cloud-based, on-premise, integrations, APIs).
Familiarity with security audit standards: SOC2, ISO 27001, NIST, PCI, etc.
Ability to evaluate the use of Generative AI in third-party solutions and associated risks.
Experience in risk countermeasures, compensating controls, and security program management.
Strong analytical and investigative skills to synthesize information from various sources.
Ability to manage multiple security reviews and prioritize effectively.
Experience working in a fast-paced, remote team environment.
Prior experience conducting vendor security assessments is preferred.
Knowledge of ticketing systems such as Jira and ability to adapt to new technologies.
Preferred Qualifications:
Experience in customer-facing roles with the ability to collaborate across teams.
Curiosity and a proactive approach to learning emerging technologies.
By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.
Contact: rranjan@judge.com
This job and many more are available through The Judge Group. Find us on the web at www.judge.com