1 day ago Be among the first 25 applicants
Get AI-powered advice on this job and more exclusive features.
We are seeking a detail-oriented Information Security Analyst to join our growing team.
In this role, you will play a vital part in supporting third-party risk assessments and contributing to enterprise risk management initiatives, ensuring regulatory compliance and the security of data across our vendor network.
Responsibilities
- Support third-party risk assessments with a focus on Information Security and GRC, helping to evaluate inherent and residual risks to enable risk-informed decision-making
- Assist in conducting due diligence on prospective and existing vendors, with an emphasis on basic cybersecurity controls, regulatory compliance (e.g., GDPR, SOC 2, ISO 27001), and data protection practices
- Help ensure the integrity, consistency, and audit-readiness of third-party data within the GRC platform to support reporting and regulatory requirements
- Collaborate with stakeholders in Information Security, Privacy, Legal, Procurement, and Business Units to share insights and contribute to enterprise risk management initiatives
- Participate in processes related to third-party offboarding, ensuring risk management steps are followed, and data retention, access, and continuity controls are reviewed
- Assist in preparing documentation and responses for external audits, internal reviews, or regulatory inquiries related to third-party risk management practices
- Contribute to the maintenance and improvement of TPRM policies, playbooks, and program metrics to support ongoing program development
Requirements
2+ years of experience in third-party risk management, information security, IT audit, or GRC, ideally within Gaming, Technology, or Consulting industriesBasic understanding of security risk assessment frameworks and best practices (e.g., NIST, ISO 27001, SIG, CSA, etc.)Familiarity with tools like JIRA and GRC platforms (e.g., OneTrust, ServiceNow) is a plus, with a willingness to learn and support data analysis and platform improvementsAbility to identify and assess security, privacy, and operational risks with an analytical, solutions-oriented mindsetStrong verbal and written communication skills, with the ability to work collaboratively with team members and stakeholders across the organizationAdaptability and willingness to take on tasks in a cross-functional environment, even in the face of ambiguity or changing requirementsGeneral understanding of regulatory requirements and good practices related to vendor management and data security is desirableAwareness of IT risk management concepts as well as familiarity with the S-SDLC and Agile Methodology is a bonusFluent English communication skills at a B2+ levelWe offer
International projects with top brandsWork with global teams of highly skilled, diverse peersEmployee financial programsPaid time off and sick leaveUpskilling, reskilling and certification coursesUnlimited access to the LinkedIn Learning library and 22,000+ coursesGlobal career opportunitiesVolunteer and community involvement opportunitiesEPAM Employee GroupsAward-winning culture recognized by Glassdoor, Newsweek and LinkedInSeniority level
Seniority level
Associate
Employment type
Employment type
Full-time
Job function
Job function
Business Development, Information Technology, and Engineering
Industries
Software Development, IT Services and IT Consulting, and Technology, Information and Internet
Referrals increase your chances of interviewing at EPAM Systems by 2x
Sign in to set job alerts for “Information Security Analyst” roles.
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-Ljbffr