Vendor Risk Analyst
The Vendor Risk Analyst is responsible for supporting Central Hudson's efforts to assess, monitor and mitigate information and cybersecurity risks associated with our vendors and third-party relationships. The ideal candidate will have a strong understanding of vendor risk management principles, excellent analytical skills, and the ability to communicate effectively with internal stakeholders and vendors alike.
What does a Vendor Risk Analyst do?
- Conducts comprehensive risk assessments of new and existing vendors, evaluating factors such as financial stability, regulatory compliance, security protocols and data privacy practices
- Performs light system administration duties for the Third-Party Risk Management (TPRM) platform (Whistic), including user access management, configuration updates, troubleshooting support, and coordination with platform support teams to ensure optimal system performance and data integrity
- Implements and supports processes for ongoing monitoring of vendor activities and performance, identifying potential risks and implementing mitigation strategies as needed
- Collaborates with cross-functional teams to develop and update vendor risk management policies, procedures, and standards in alignment with industry best practice and regulatory requirements
- Conducts due diligence reviews of potential vendors, assessing their capabilities, reputation, and adherence to contractual obligations
- Cultivates positive and collaborative relationships with vendors, serving as a point of contact for risk-related inquiries and facilitating regular communications
- Monitors vendor compliance with contractual and regulatory requirements, escalating issues as necessary and coordinating remediation efforts as needed
- Prepares and maintains accurate records of vendor risk assessments, findings, and remediation activities, generating regular reports for senior management and regulatory authorities as required
- Provides support for storm restoration efforts
What does it take to be a Vendor Risk Analyst?
Required :
Bachelor's degree in Cybersecurity, Information Assurance, Risk Management or related field of study. In lieu of a bachelor's degree, an associate degree in the aforementioned fields and 3 years of relevant experience or a high school diploma or equivalency degree and 5 years of relevant experience will be consideredStrong understanding of risk management principles, methodologies, and frameworks (e.g., ISO, NIST Cybersecurity Framework, NIST RMF, NATF Supply Chain Risk)Familiarity with Third Party Risk Management software & toolsExcellent analytical skills with the ability to identify, assess, and prioritize risks effectivelyEffective communication skills, with the ability to collaborate with diverse teams, and communicate complex concepts clearly and conciselyDetail oriented with strong organizational skills and ability to manage multiple tasks and deadlines effectivelyAbility to work with limited direct supervision and professionally respond to constructive feedbackValid driver's licensePreferred :
Experience in conducting risk assessments, developing risk mitigation strategies and evaluating contractual agreementsExperience in Energy & Utilities or services industryExperience with Microsoft Power BIExperience with data visualization toolsRelevant certifications such as CISSP, CISM, or comparableApplications will be accepted until December 3, 2025. This position has a career path which allows for advancement opportunities within a job series. The title and level are commensurate with experience. Pay range : $71,900 $168,700