Hiring.Camp

Senior Third-Party Risk Management Analyst

Communitybrands

·

Today

Location
US-HQ-Home Office, United States of America
Workplace
Remote
Type
Full-time
Department
Finance
Seniority
Senior
Experience
5+ years
Visa
Not sponsored
Source
Workday

Description

Job Description

POSITION OVERVIEW

The Third-Party Risk Management (TPRM)Analyst serves as a core member of Momentive Software's Cybersecurity, Risk & Compliance organization. This role is responsible for maintaining and maturing Momentive's enterprise-wide third-party risk program, ensuring that all vendors, platforms, and service providers meet the Firm's cybersecurity, privacy, resiliency, and regulatory requirements.

The Analyst partners closely with Client Success, Cybersecurity Engineering, TVM, Legal, Procurement, Product, and the CISO to evaluate vendor risk, maintain continuous oversight of third-party controls, and support Momentive's compliance obligations — including SOC 2 Type II and PCI DSS. The role also supports TVM notifications to clients who manage their own cybersecurity posture, ensuring clear, accurate, and timely communication of vulnerabilities and remediation expectations.

This position requires strong analytical capability, deep familiarity with cybersecurity frameworks, and the ability to translate complex risk issues into actionable guidance for business and technical stakeholders.

KEY RESPONSIBILITIES

Third-Party Risk Management Program

  • Maintain Momentive's global inventory of third-party providers, applications, and services from onboarding through termination.
  • Lead vendor cybersecurity assessments, coordinating with Cybersecurity Engineering, Legal, and business owners to evaluate risk and required controls.
  • Assess vendor maturity using NIST CSF, CIS, CMMC, GDPR, PCI DSS, SOC 2, and other frameworks.
  • Oversee vendor SLAs, RPO/RTO commitments, breach notification requirements, and cybersecurity insurance documentation.
  • Ensure thorough documentation of findings, recommendations, and remediation plans for all vendor assessments.
  • Serve as a liaison to internal and external auditors for vendor-related controls and evidence collection.

Support for PCI DSS & SOC 2 Type II Audits

  • Provide evidence, documentation, and control validation related to third-party dependencies for Momentive's SOC 2 Type II and PCI DSS assessments.
  • Ensure vendor controls align with Momentive's ISMS, contractual obligations, and certification requirements.
  • Partner with the GRC team to maintain audit-ready documentation, including policies, standards, procedures, and risk treatment plans.
  • Track vendor exceptions and compensating controls, ensuring audit defensibility and continuous improvement.

TVM Notifications & Client Support

  • Collaborate with the Threat & Vulnerability Management (TVM) team to support vulnerability notifications to clients who manage their own cybersecurity controls.
  • Ensure communications are accurate, timely, and aligned with Momentive's contractual commitments and industry best practices.
  • Provide consultative guidance to clients regarding risk impact, remediation expectations, and recommended cybersecurity practices.
  • Maintain documentation and metrics related to client notifications, follow-up actions, and closure.

Governance, Risk & Compliance Integration

  • Contribute to the continual improvement of Momentive's ISMS by aligning vendor risk processes with Firm policies, standards, and procedures.
  • Provide input on control selection, risk treatment plans, and metrics used to monitor the effectiveness of Momentive's cybersecurity controls.
  • Maintain situational awareness of emerging threats, regulatory changes, and industry trends affecting third-party risk.
  • Support DR/BCP planning as it relates to vendor dependencies and resiliency requirements.

Stakeholder Engagement & Leadership

  • Act as a key point of contact when business units identify vendor-related risk; coordinate with Legal, Cybersecurity, and leadership on risk reduction strategies.
  • Promote a positive, enterprise-wide cybersecurity culture through outreach, training, and awareness activities.
  • Provide exemplary service to internal and external stakeholders, demonstrating professionalism, empathy, and expertise.
  • Mentor team members and contribute to the development of internal training materials and documentation.

SKILLS & EXPERIENCE

Required

  • 5+ years of experience in cybersecurity, risk management, audit, or compliance.
  • Deep understanding of regulatory requirements including PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST.
  • Experience evaluating both legacy and modern cloud technologies (AWS, GCP, Azure).
  • Strong knowledge of APIs, application cybersecurity, encryption, endpoint, and network cybersecurity concepts.
  • Familiarity with SIEM, IDS, log management, vulnerability management, and threat intelligence.
  • Ability to assess vendor controls, map them to frameworks, and articulate risk to non-technical stakeholders.
  • Strong project management, multitasking, and organizational skills.
  • Excellent written and verbal communication skills.

Preferred

  • Experience supporting SOC 2 Type II and PCI DSS audits.
  • Experience with EGRC/ITGRC platforms (e.g., Jira Service Manager GRC, Archer, OneTrust, LogicGate).
  • Certifications such as CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP.

About Us

Momentive Software amplifies the impact of over 20,000 purpose-driven organizations in over 30 countries, with over $11 billion raised and 55 million members served to date. Mission-driven nonprofits and associations rely on Momentive’s cloud-based software and services to address their most pressing challenges – from engaging their communities to simplifying operations and growing revenue. Designed to help organizations connect more, manage more, and ultimately expect more, Momentive's solutions are built with reliability at the core and strategically focus on fundraising, learning, events, careers, volunteering, accounting, and association management. Momentive partners with organizations that believe "good enough" is never enough – so they can bring on better outcomes for everyone they serve. Learn more at momentivesoftware.com.
 

Why Work Here?

At Momentive Software, we’re a team of passionate problem-solvers, innovators, and volunteers who believe in using technology to make a real difference. We dream big, support each other, and take pride in creating solutions that help our customers drive meaningful change. If you’re looking for a place where your work matters and your ideas are valued, you’ll find it here.

Medical, Dental & Vision Benefits

401(k) Savings Plan with Company Match

Flexible Planned Paid Time Off

Generous Sick Leave

Inclusive & Welcoming Environment

Purpose-Driven Culture

Work-Life Balance

Commitment to Community Involvement

Employer-Paid Parental Leave

Employer-Paid Short-Term Disability

Remote Work Flexibility

Momentive Software actively embraces diversity and equal opportunity in a meaningful way. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be, which is why we do not discriminate based on race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.

All persons hired will be required to verify identity, minimum age of 18, eligibility to work in the United States (without sponsorship), and to complete the required employment eligibility verification form upon hire.

Skills

AWSAzureGCPJiraCybersecuritySIEMSOCSOXRisk ManagementComplianceProcurementProject ManagementSOC 2HIPAAGDPRCISSP

Similar Jobs

26

Senior Consultant, Third Party Issue Management - Third Party Risk Management

NT Careers·Chicago, IL +1

2d ago

Senior Third Party Risk (TPRM) Cybersecurity Analyst

The Future of Health Starts with You·Cork, IRL - 3300 Cork Airport Business Pk·Hybrid

2d ago

Senior Analyst, ORM & Third-Party Risk

Canadian Tire Corporation·Oakville 01, Canada

2d ago

Sr Third Party Risk Manager

Transamerica·Denver, Colorado +2

6d ago

Third Party Risk Senior Associate

Crowe Careers·Noida, India

6d ago

Senior Security Engineer - Enterprise & Third Party Risk Management

LinkedIn·Mountain View, CA·Hybrid

1w ago

Senior Risk Analyst, Privacy & Third-Party Risk

Troweprice·Baltimore, MD

3w ago

Sr Mgr Third Party Risk

Baylor Genetics·Remote·Remote

4w ago

Senior Business Analyst - Third Party Risk Management (TPRM)

Capitalone·McLean, VA +3

1mo ago

Senior Manager – Finance Third Party Risk Management

M&G·Mumbai Central Avenue, India

1mo ago

Senior Third Party Risk Analyst

Icwgroup·Innovation Point, US

1mo ago

Senior GRC / Third-Party Risk / Data Protection Analyst

Peraton·US·Remote

1mo ago

Senior Analyst, Enterprise Risk Management (Third-Party Risk & Regulatory Initiative Focus)

TMX group of companies includes·Toronto - 100 Adelaide St W, Canada·Hybrid, Onsite

1mo ago

Senior Analyst, Enterprise Risk Management (GRC Tool Implementation & Third-Party Risk Focus)

TMX group of companies includes·Toronto - 100 Adelaide St W, Canada·Hybrid, Onsite

1mo ago

Senior Consultant, Third Party Risk Management

NT Careers·Chicago, IL +1

2mo ago

Senior Third Party Risk Analyst

modernatx·POL - Mazowieckie - Warsaw - MESH Rondo Ignacego Daszynskiego 1, Poland +1

2mo ago

Senior Software Engineer, Trust and Third Party Risk Management

Vanta·Remote U.S. +1·Remote

3mo ago

Senior Third-Party Risk Analyst

Western Governors University·Salt Lake City Office, US

3mo ago

Third Party Risk Senior Consultant

Crowe Careers·Chicago, US +2

3mo ago

Senior Manager, Third Party & Contract Risk

Mgmresorts·Office - US, Las Vegas

3mo ago

Senior Manager, Third Party & Contract Risk

Mgmresorts·Office - US, Las Vegas

3mo ago

Senior Associate Cybersecurity Specialist- Third Party Risk Management Program

Travelers·Hartford - Tower, US·Hybrid

4mo ago

Third Party Risk Analyst, Sr

Old National Bank·Evansville, IN +2

7mo ago

(Senior) Consultant Outsourcing / Third Party Risk Management (all genders)

Wavestone·-

8mo ago

(Senior) Consultant Outsourcing / Third Party Risk Management (all genders)

Europe Wavestone·-, Deutschland

8mo ago

Risk Services - Technology, Cyber and Third Party Risk Management - Manager/ Senior Manager

Pwc·Singapore·Remote

11mo ago