Talent.com
Third-Party Information Security Risk Analyst

Third-Party Information Security Risk Analyst

Stifel FinancialSaint Louis, MO, US
job_description.job_card.variable_hours_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Overview

The Third-Party Cyber Risk Analyst performs comprehensive third-party risk assessments, focusing on data security, regulatory compliance and emerging AI use risks. This includes reviewing DDQs, SOC reports, AI governance disclosures, vendor security reports, and supporting documentation from vendors and service providers. The Third-Party Cyber Risk Analyst plays a critical role in safeguarding the organization data by ensuring third-party partners have implemented sufficient data protection safeguards. Ideal candidate thinks strategically and is intellectually curious. The Third-Party Cyber Risk Analyst will be expected to help refine the risk program.

What We're Looking For

  • Evaluate third-party cybersecurity posture using DDQs, SOC 2 Type II reports, ISO certifications, penetration test results, and AI usage documentation.
  • Assess AI models used by third parties for privacy, security, and compliance risks (e.g., data training, model outputs, governance).
  • Identify gaps in vendor controls and recommend mitigations or compensating controls.
  • Advise on residual risk and escalation paths for critical or high-risk vendors.
  • Assist with defining third-party security standards and playbooks.
  • Collaborate with legal, compliance, procurement, and enterprise risk management teams.
  • Maintain and update third-party risk assessment templates to include AI and emerging technology risks.
  • Track and report risk status, remediation plans, and residual risk acceptance.
  • Contribute to continuous improvement of the third-party risk management (TPRM) framework.
  • Create third-party cyber risk posture reports and metrics.
  • Must handle highly sensitive information with discretion and objectivity.
  • May be required to participate in third-party incident response after hours or on short notice.

What You'll Bring

  • Strong understanding of NIST CSF, ISO 27001, SOC 2, contractual cybersecurity clauses, and regulatory expectations (e.g., SEC, FINRA, GLBA).
  • Working knowledge of AI governance data security issues, and compliance risks (e.g., data governance, shadow AI).
  • Experience reviewing security questionnaires, due diligence documentation, and audit reports.
  • Excellent analytical, communication, and documentation skills.
  • Education & Experience

  • Minimum Required : Bachelor\'s degree in Cybersecurity, Information Technology, or related discipline, or equivalent experience.
  • Minimum Required : 7+ years of experience in cybersecurity, third-party risk, or IT audit.
  • Licenses & Credentials

  • Certifications : CISA, CISSP, CTPRP, or vendor risk-specific credentials preferred.
  • Systems & Technology

  • Experience with third-party risk platforms e.g. Archer, OneTrust, ProcessUnity, ServiceNow TPRM, etc.
  • Understanding of emerging AI risk frameworks e.g., NIST AI RMF, EU AI Act.
  • Stifel is an Equal Opportunity Employer.

    About Stifel

    Stifel is more than 130 years old and still thinking like a start-up. We are a global wealth management and investment banking firm serious about innovation and fresh ideas. Built on a simple premise of safeguarding our clients' money as if it were our own, coined by our namesake, Herman Stifel, our success is intimately tied to our commitment to helping families, companies, and municipalities find their own success.

    While our headquarters is in St. Louis, we have offices in New York, San Francisco, Baltimore, London, Frankfurt, Toronto, and more than 400 other locations. Stifel is home to approximately 9,000 individuals who are currently building their careers as financial advisors, research analysts, project managers, marketing specialists, developers, bankers, operations associates, among hundreds more. Let\'s talk about how you can find your place here at Stifel, where success meets success.

    At Stifel we offer an entrepreneurial environment, comprehensive benefits package to include health, dental and vision care, 401k, wellness initiatives, life insurance, and paid time off.

    Stifel is an Equal Opportunity Employer.

    J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Information Security Analyst • Saint Louis, MO, US

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    South Carolina Licensed Information Security Analyst

    South Carolina Licensed Information Security Analyst

    VirtualVocationsSaint Louis, Missouri, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security GRC Analyst II.Key Responsibilities Develop and maintain information security policies and procedures in alignment with regulatory requirements C...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Third-Party Risk Strategy Lead

    Third-Party Risk Strategy Lead

    Talent BridgeSaint Louis, MO, US
    serp_jobs.job_card.full_time
    Third-Party Risk Strategy Lead.Location : Saint Louis, MO (Hybrid 3 days onsite / 2 days remote).Position Overview : We are seeking a senior business execution & third-party risk consultant to lead ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Detection Analyst

    Senior Detection Analyst

    VirtualVocationsFlorissant, Missouri, United States
    serp_jobs.job_card.full_time
    A company is looking for a Detection & Response Analyst.Key Responsibilities Act as the point of escalation for security incidents and lead the Incident Detection team Triage security incidents ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Security Assurance Analyst

    Senior Security Assurance Analyst

    VirtualVocationsSaint Charles, Missouri, United States
    serp_jobs.job_card.full_time
    Security Assurance Analyst to lead the design, implementation, and optimization of enterprise information security controls and compliance programs. Key Responsibilities Lead and maintain SOC 2 an...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Security Analyst

    Security Analyst

    Bunge Iberica SASaint Louis, MO, US
    serp_jobs.job_card.full_time
    Select how often (in days) to receive an alert : .At Bunge, people don't just come here to work, they come here to grow – solving challenges that directly impact the world with a diverse and talented...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Senior Security Analyst

    Senior Security Analyst

    VirtualVocationsFlorissant, Missouri, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Analyst to monitor and respond to cybersecurity threats.Key Responsibilities Monitor and triage security alerts from various sources and lead incident r...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Texas Licensed Security Operations Analyst

    Texas Licensed Security Operations Analyst

    VirtualVocationsFlorissant, Missouri, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Operations Analyst.Key Responsibilities Analyze security incidents and provide timely responses Monitor security systems and generate reports on security metr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    IAM Security Analyst

    IAM Security Analyst

    VirtualVocationsSaint Charles, Missouri, United States
    serp_jobs.job_card.full_time
    A company is looking for an IAM Security Analyst.Key Responsibilities Execute user access certifications for compliance and collaborate with audit teams Enhance IAM controls and participate in d...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Application Security Analyst

    Application Security Analyst

    VirtualVocationsFlorissant, Missouri, United States
    serp_jobs.job_card.full_time
    A company is looking for an Application Security Analyst to protect its digital ecosystem.Key Responsibilities Analyze and refine security findings from various security tools Reduce false posit...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Security Analyst

    Security Analyst

    VirtualVocationsSaint Charles, Missouri, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Analyst (Governance Program) to work remotely.Key Responsibilities Develop and implement governance frameworks for security policies and procedures Conduct ri...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Analyst II

    Security Analyst II

    TOUCHETTECollinsville, IL, US
    serp_jobs.job_card.full_time
    Monitors the health of Touchette Regional Hospital and SIHF Healthcare’s security threat posture and cybersecurity & network infrastructure. Develops a deep understanding of the threat lan...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Information Security Manager

    Information Security Manager

    NOUS Imaging Inc.Saint Louis, MO, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Information Security Manager Who You Are You are an experienced IT security professional with a proven track record in developing and implementing robust information security policies...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Border Patrol Agent

    Border Patrol Agent

    U.S. Customs and Border ProtectionJosephville, MO, United States
    serp_jobs.job_card.full_time
    Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    SOC Analyst Level 2

    SOC Analyst Level 2

    VirtualVocationsFlorissant, Missouri, United States
    serp_jobs.job_card.full_time
    A company is looking for a SOC Analyst (L2) to maintain its cybersecurity posture through monitoring, detection, and incident response. Key Responsibilities Monitor and analyze security alerts to ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Oracle Cloud Security Analyst

    Oracle Cloud Security Analyst

    VirtualVocationsSaint Charles, Missouri, United States
    serp_jobs.job_card.full_time
    A company is looking for an Oracle Cloud Application Security Analyst.Key Responsibilities Develop and implement security policies and procedures for the Oracle Financial Applications system Def...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Information Security Training Lead

    Information Security Training Lead

    VirtualVocationsSaint Louis, Missouri, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Training Awareness Lead to enhance cybersecurity awareness through training and outreach initiatives. Key Responsibilities Develop and implement an...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Senior Information Security Analyst

    Senior Information Security Analyst

    StifelSaint Louis, MO, US
    serp_jobs.job_card.full_time
    Stifel strives for a culture that puts its clients and associates first : a culture where everyone belongs, everyone is welcome, and everyone contributes to the success of our clients, their careers...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Cyber Security Analyst - MUST LIVE IN KANSAS, MISSOURI OR ILLINOIS

    Cyber Security Analyst - MUST LIVE IN KANSAS, MISSOURI OR ILLINOIS

    MedStar HealthSaint Charles, MO, US
    serp_jobs.job_card.full_time
    Join the team at Heartland Coca-Cola Bottling Company!.Days / Hours of Work : Monday-Friday 8-5 some on call hours required - MUST LIVE WITHIN THE HEARTLAND COCA COLA TERRITORY (KANSAS, MISSOURI, ILLI...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours