Sr. Info Security Analyst IND

Seeking a Senior Information Security Analyst with expertise in Third-Party Risk Management (TPRM) and/or Security Controls Testing. In this role, you will play a critical part in protecting FM by assessing risks across external vendors, SaaS platforms, cloud solutions, and internal control environments. Your work will evaluate both the design and operating effectiveness of security controls and, where applicable, how third-party solutions interact with FM systems and data.


This includes reviewing security control environments, internal controls, and solution implementations with a focus on data handling, storage, processing, and system integrations. You will partner closely with business, technology, procurement, and risk stakeholders to identify risks, assess control effectiveness, and recommend practical, business-aligned mitigation strategies.


Responsibilities:

  • Lead end-to-end third-party risk assessments and/or security control testing activities, including planning, execution, documentation, and reporting.
  • Perform independent validation of control design and operating effectiveness across internal systems and/or external vendors in alignment with established frameworks and standards.
  • Evaluate vendor security programs, governance, and control environments, as well as internal controls, processes, and supporting evidence to determine effectiveness and maturity.
  • Assess solution architecture, cloud environments (SaaS/PaaS), APIs, data flows, and integration points, or validate controls governing these areas, depending on assignment.
  • Identify and communicate inherent and residual cyber risks, including issues related to data protection, identity & access management, system connectivity, and external exposure.
  • Review and interpret security documentation, including SOC 1/SOC 2 reports, control testing evidence, audit reports, architecture diagrams, and data flow diagrams.
  • Execute control testing procedures, including walkthroughs, sampling, evidence review, and documentation of results in a consistent and repeatable manner.
  • Document findings clearly, including control gaps, deficiencies, and improvement opportunities, and support remediation tracking and resolution.
  • Recommend practical risk mitigation strategies, including compensating controls, control enhancements, secure design improvements, and contractual safeguards.
  • Partner with business, technology, procurement, and legal teams to support risk acceptance, exception management, and governance activities.


Requirements:

  • 2-4 years of experience required in cybersecurity, information security, or cyber risk, with experience in third-party risk management (TPRM), security controls testing, IT risk, or audit.
  • General knowledge of operating systems, networks, databases, and application development, including how these components interact within secure enterprise environments.
  • Understanding of IT General Controls (ITGCs), including controls related to: Logical access management, Change management, Computer operations, System and database security controls.
  • Exposure to security frameworks such as NIST CSF, ISO 27001 CIS Controls, or SOC-aligned controls.
  • 4-year/ bachelor's degree required.
  • Preferred certifications: CISA, CISM, CISSP.


Soft Skills:

  • Strong verbal and written communication skills, with the ability to clearly document and communicate findings.
  • Strong interpersonal skills and ability to work across business, technology, and risk stakeholders.
  • Ability to manage multiple priorities and coordinate activities effectively.
  • Demonstrated attention to detail and professional scepticism.


Must Have Skills:

Controls Testing:

  • Security Control Testing and Validation: Experience performing control testing, reviews, or self-assessments against defined standards, procedures, or frameworks.
  • Familiarity with Security and Control Frameworks: Working knowledge of common frameworks such as NIST CSF, ISO 27001 CIS Controls, or SOC-aligned controls.
  • Documentation and Evidence Collection: Ability to gather, review, and clearly document evidence supporting control design and operating effectiveness
  • Attention to Detail and Consistency: Strong focus on accuracy, repeatability, and completeness when executing testing procedures and documenting results.
  • Collaboration and Coachability: Ability to work effectively with senior risk, compliance, and technology team members, take direction well, and continuously improve testing quality.
Back to blog

Other Jobs To Apply

No other job posts for this day.

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...