Talent.com
Third-Party Information Security Risk Analyst

Third-Party Information Security Risk Analyst

Stifel FinancialSaint Louis, MO, US
22 hours ago
Job type
  • Full-time
Job description

Overview

The Third-Party Cyber Risk Analyst performs comprehensive third-party risk assessments, focusing on data security, regulatory compliance and emerging AI use risks. This includes reviewing DDQs, SOC reports, AI governance disclosures, vendor security reports, and supporting documentation from vendors and service providers. The Third-Party Cyber Risk Analyst plays a critical role in safeguarding the organization data by ensuring third-party partners have implemented sufficient data protection safeguards. Ideal candidate thinks strategically and is intellectually curious. The Third-Party Cyber Risk Analyst will be expected to help refine the risk program.

What We're Looking For

  • Evaluate third-party cybersecurity posture using DDQs, SOC 2 Type II reports, ISO certifications, penetration test results, and AI usage documentation.
  • Assess AI models used by third parties for privacy, security, and compliance risks (e.g., data training, model outputs, governance).
  • Identify gaps in vendor controls and recommend mitigations or compensating controls.
  • Advise on residual risk and escalation paths for critical or high-risk vendors.
  • Assist with defining third-party security standards and playbooks.
  • Collaborate with legal, compliance, procurement, and enterprise risk management teams.
  • Maintain and update third-party risk assessment templates to include AI and emerging technology risks.
  • Track and report risk status, remediation plans, and residual risk acceptance.
  • Contribute to continuous improvement of the third-party risk management (TPRM) framework.
  • Create third-party cyber risk posture reports and metrics.
  • Must handle highly sensitive information with discretion and objectivity.
  • May be required to participate in third-party incident response after hours or on short notice.

What You'll Bring

  • Strong understanding of NIST CSF, ISO 27001, SOC 2, contractual cybersecurity clauses, and regulatory expectations (e.g., SEC, FINRA, GLBA).
  • Working knowledge of AI governance data security issues, and compliance risks (e.g., data governance, shadow AI).
  • Experience reviewing security questionnaires, due diligence documentation, and audit reports.
  • Excellent analytical, communication, and documentation skills.
  • Education & Experience

  • Minimum Required : Bachelor\'s degree in Cybersecurity, Information Technology, or related discipline, or equivalent experience.
  • Minimum Required : 7+ years of experience in cybersecurity, third-party risk, or IT audit.
  • Licenses & Credentials

  • Certifications : CISA, CISSP, CTPRP, or vendor risk-specific credentials preferred.
  • Systems & Technology

  • Experience with third-party risk platforms e.g. Archer, OneTrust, ProcessUnity, ServiceNow TPRM, etc.
  • Understanding of emerging AI risk frameworks e.g., NIST AI RMF, EU AI Act.
  • Stifel is an Equal Opportunity Employer.

    About Stifel

    Stifel is more than 130 years old and still thinking like a start-up. We are a global wealth management and investment banking firm serious about innovation and fresh ideas. Built on a simple premise of safeguarding our clients' money as if it were our own, coined by our namesake, Herman Stifel, our success is intimately tied to our commitment to helping families, companies, and municipalities find their own success.

    While our headquarters is in St. Louis, we have offices in New York, San Francisco, Baltimore, London, Frankfurt, Toronto, and more than 400 other locations. Stifel is home to approximately 9,000 individuals who are currently building their careers as financial advisors, research analysts, project managers, marketing specialists, developers, bankers, operations associates, among hundreds more. Let\'s talk about how you can find your place here at Stifel, where success meets success.

    At Stifel we offer an entrepreneurial environment, comprehensive benefits package to include health, dental and vision care, 401k, wellness initiatives, life insurance, and paid time off.

    Stifel is an Equal Opportunity Employer.

    J-18808-Ljbffr

    Create a job alert for this search

    Information Security Analyst • Saint Louis, MO, US

    Related jobs
    • Promoted
    Security Specialist III

    Security Specialist III

    ServiceSource, Inc.Arnold, MO, United States
    Full-time
    Make an impact by joining ServiceSource, a champion for people with disabilities.Explore new opportunities! ServiceSource is an organization of talented people who drive innovation, embrace change,...Show moreLast updated: 30+ days ago
    • Promoted
    Customs and Border Protection Officer

    Customs and Border Protection Officer

    U.S. Customs and Border ProtectionSmithton, IL, United States
    Full-time
    Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...Show moreLast updated: 30+ days ago
    • Promoted
    Transportation Analyst

    Transportation Analyst

    Leonardo DRSHigh Ridge, MO, United States
    Full-time
    Focused on defense technology, we develop, manufacture and support a broad range of systems for mission critical and military sustainment requirements, as well as homeland security.Headquartered in...Show moreLast updated: 1 day ago
    • Promoted
    Information Assurance Engineer

    Information Assurance Engineer

    Global Enterprise Services, LLCBelleville, IL, US
    Full-time
    The Information Assurance Engineer determines enterprise information assurance and security standards.Develops and implements information assurance / security standards and procedures.Coordinates, de...Show moreLast updated: 30+ days ago
    • Promoted
    Director, Technology Risk Management

    Director, Technology Risk Management

    MastercardO Fallon, MO, US
    Full-time +1
    Director, Technology Risk Management.The Regulatory Relations Markets & Compliance (RRMC) team is responsible for working with, and demonstrating to, our stakeholders (e. Mastercard businesses) how ...Show moreLast updated: 30+ days ago
    Senior Requirements Analyst •

    Senior Requirements Analyst •

    SierTeK Ltd.Scott AFB, IL, USA
    Full-time
    Quick Apply
    SierTeK proudly serves our clients by providing expertise in the Program Management, Information Technology, and Administrative Support domains. Founded in 2007 as a minority and service-disabled ve...Show moreLast updated: 12 days ago
    • Promoted
    Day Drive - Special time

    Day Drive - Special time

    EmploybridgeSmithton, IL, US
    Full-time
    Come join the team at a live auto auction.We are looking for awesome people like you to join our team! Come drive cool cars and experience life at the Auction!. MUST BRING VALID DRIVER'S LICENSE...Show moreLast updated: 1 day ago
    • Promoted
    33 SISO-TR-DO-0033 Security Analyst Area Security Officer - L3

    33 SISO-TR-DO-0033 Security Analyst Area Security Officer - L3

    Integrated Intel SolutionsSaint Louis, MO, US
    Full-time
    SISO Position 5 : Security Specialist – Skill Level 3.Overall Assignment Description : Security Analyst Area Security Officer. U) Utilize security concepts, principles and practices to analyze a...Show moreLast updated: 30+ days ago
    CI Cyber Threat Analyst IV

    CI Cyber Threat Analyst IV

    TechGuard SecuritySt. Louis, MO, USA
    Full-time
    Quick Apply
    The senior Contractor CI Cyber Threat Analyst will ensure all required reports are complete with minimal errors and that all processes, activities, and reports are conducted within established time...Show moreLast updated: 11 days ago
    • Promoted
    Security Officer - 3rd Shift

    Security Officer - 3rd Shift

    SecuritasEdwardsville, IL, US
    Full-time
    Focus on the core content of the job post, removing any extra metadata, navigation mentions, and redundant headers.Keep the formatting beautiful and consistent, using only the specified HTML tags.R...Show moreLast updated: 30+ days ago
    • Promoted
    Field Risk Specialist

    Field Risk Specialist

    DataScanSt Louis, MO, United States
    Full-time
    Field Risk Specialist Position Opportunity!We pay for drive time so candidates must live in the immediate area of St.This is a Field Based Position so you will not be assigned to a local office.Hea...Show moreLast updated: 22 days ago
    Systems Analyst •

    Systems Analyst •

    SierTeK Ltd.Scott AFB, IL, USA
    Full-time
    Quick Apply
    SierTeK proudly serves our clients by providing expertise in the Program Management, Information Technology, and Administrative Support domains. Founded in 2007 as a minority and service-disabled ve...Show moreLast updated: 12 days ago
    • Promoted
    Field Risk Specialist

    Field Risk Specialist

    Datascan Technologies, LLCSaint Louis, MO, US
    Full-time
    Field Risk Specialist Position Opportunity! W.This is a Field Based Position so you will not be assigned to a local office. Headquartered in Alpharetta, Georgia, DataScan stands at the forefro...Show moreLast updated: 30+ days ago
    • Promoted
    Cybersecurity Analyst

    Cybersecurity Analyst

    Leidos IncScott Air Force Base, IL, United States
    Full-time
    The Leidos Digital Modernization sector is seeking talented and cleared Cyber Security Analysts to join our dynamic team supporting the DISA GSM-O II program. We are continuously building our team a...Show moreLast updated: 30+ days ago
    • Promoted
    Security Analyst II

    Security Analyst II

    TOUCHETTECollinsville, IL, US
    Full-time
    Monitors the health of Touchette Regional Hospital and SIHF Healthcare’s security threat posture and cybersecurity & network infrastructure. Develops a deep understanding of the threat lan...Show moreLast updated: 30+ days ago
    • Promoted
    SAP Security Manager

    SAP Security Manager

    Anheuser-BuschWest Alton, MO, United States
    Full-time
    And more than ever, it’s our future.A future where we’re always looking forward.Always serving up new ways to meet life’s moments. A future where we keep dreaming bigger.We look for people with pass...Show moreLast updated: 5 days ago
    TSCM Practitioner (Level III)

    TSCM Practitioner (Level III)

    Tetrad Digital Integrity LLCSt. Louis, MO, US
    Permanent
    Quick Apply
    Tetrad Digital Integrity (TDI) is a leading-edge cybersecurity firm with a mission to safeguard and protect our customers from increasing threats and vulnerabilities in this digital age.TDI is...Show moreLast updated: 4 days ago
    • Promoted
    Border Patrol Agent

    Border Patrol Agent

    U.S. Customs and Border ProtectionJosephville, MO, United States
    Full-time
    Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...Show moreLast updated: 30+ days ago
    • Promoted
    Traveling Electronic Security Systems Technician

    Traveling Electronic Security Systems Technician

    Evergreen Fire and SecuritySaint Louis, MO, US
    Full-time
    Evergreen Fire and Security (EFS) is a recognized leader in the life safety and security solutions industry.We are entrusted by the Federal Government and commercial customers to protect lives, cri...Show moreLast updated: 30+ days ago
    • Promoted
    Customs and Border Protection Officer - Experienced (GS9)

    Customs and Border Protection Officer - Experienced (GS9)

    U.S. Customs and Border ProtectionWinfield, MO, United States
    Full-time
    Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...Show moreLast updated: 30+ days ago