Your Opportunity:
Third Party Risk Analyst – Governance, Risk & Compliance (GRC) provides Tier-2 operational support within the Information Risk Management team, focusing on Third Party Risk and compliance activities. As a risk management professional your role will be responsible for consulting, assessing, reporting, monitoring and recommending actions to mitigate risks associated with vendors, suppliers, service providers and other third-party entities, including managing those relationships, to minimize cybersecurity risk exposure and impacts.
Description:
The Third Party Risk Analyst – Governance, Risk & Compliance (GRC) provides Tier‑2 operational support within the Information Risk Management team, with a focus on third‑party risk and compliance activities. This role is responsible for consulting, assessing, monitoring, reporting, and recommending actions to mitigate risks associated with vendors, suppliers, service providers, and other third‑party entities, including managing those relationships, to reduce cybersecurity risk exposure and potential impacts. The analyst supports the organization by ensuring third‑party relationships meet security, compliance, and regulatory requirements, while building strong internal partnerships and influencing third parties to comply with cybersecurity risk management policies. The role also supports audit and compliance activities, ensuring alignment with the NIST Cybersecurity Framework (CSF). Additional responsibilities include contributing to process improvements, updating governance documentation, and providing general GRC operational support.
Required Qualifications: Degree/Diploma in Information Technology.
Additional Required Qualifications: Preferred Qualifications: Third Party Risk Management certification. Understanding of IT process management and improvement. Understanding of the Healthcare IT sector. Third Party Risk Management/Vendor Risk Management experience. Good communication skills. Able to effectively communicate with internal and external stakeholders, both in technical and business terms.