Sr. Analyst, IT Security Risk Assessment - Third Party

Posted 10 days ago
Job Viewed
Job Description
**Work Arrangement:**
Remote : Work at home employee
**Relocation assistance:** is not available for this opportunity.
**Requisition #:** 74284
**The Role at a Glance**
This position will develop and conduct information security risk assessments on parties' external to Lincoln Financial Group to ensure that information security risks associated with those relationships are within acceptable tolerances. S/he will provide direction and guidance to stakeholders concerning risks associated with assessment findings and adherence to applicable procedures, regulations, and/or laws. S/he will respond to requests from external parties concerning Lincoln's own information risk management practices.
**What you'll be doing**
+ Maintains knowledge on current and emerging developments/trends for assigned area(s) of responsibility, assesses the impact, and collaborates with senior management to incorporate new trends and developments in current and future solutions.
+ Directs and enhances organizational initiatives by positively influencing and supporting change management and/or departmental/enterprise initiatives within assigned area(s) of responsibility.
+ Identifies and directs the implementation of process improvements that significantly improve quality across the team, department and/or business unit for his/her assigned area(s) of responsibility.
+ Provides subject matter expertise to team members and applicable internal/external stakeholders on complex assignments/projects for his/her assigned area(s) of responsibility.
+ Provides direction on complex assignments, projects, and/or initiatives to build and enhance the capability of his/her assigned area(s) of responsibility.
+ Performs complex risk assessments of external party information security controls to ensure they meet or exceed Lincoln's information security risk management requirements for the services to be provided.
+ Determines information security risk profiles for various vendor and business partner services using questionnaires and knowledge of Lincoln policy and relevant industry best practices and standards.
+ Recommends mitigation plans/solutions to eliminate, reduce, or mitigate risk, and communicates said solutions to both external parties and internal business stakeholders.
+ Records pertinent documentation and communications for all assessments in Lincoln's online information technology (IT) governance, risk, and compliance platform.
+ Responds to incoming requests from external parties for information concerning Lincoln's information security practices by providing appropriately scoped and accurate information in a timely and professionally written manner.
+ Reports status of engagements to Information Security management, project managers, and other business stakeholders as appropriate.
+ Performs other information security risk management tasks as assigned.
+ Assists in creating and enforcing information security standards, policies and procedures.
+ Researches and maintains current knowledge regarding information security issues, trends, and legislation related to information security.
+ Evaluate and identify security risks of third-party AI solutions to provide guidance to internal stakeholders based on Lincoln policies and industry best practices.
+ Stay updated on emerging AI trends and technologies to support innovation within the organization
+ Demonstrates understanding of AI
**What we're looking for**
+ 4 Year/Bachelor's degree in Information Systems, IT Audit, Information Security, Information Risk Management, or related field or equivalent experience in lieu of Bachelor's
+ 5+ years of experience in IT Security, IT Audit or Information Risk Management that directly aligns with the specific responsibilities for this position.
+ 2+ years of experience in Artificial Intelligence that directly aligns with the specific responsibilities for this position.
**Application Deadline**
Applications for this position will be accepted through October 3, 2025, subject to earlier closure due to applicant volume.
**What's it like to work here?**
At Lincoln Financial, we love what we do. We make meaningful contributions each and every day to empower our customers to take charge of their lives. Working alongside dedicated and talented colleagues, we build fulfilling careers and stronger communities through a company that values our unique perspectives, insights and contributions and invests in programs that empower each of us to take charge of our own future.
**What's in it for you:**
+ Clearly defined career tracks and job levels, along with associated behaviors for each of Lincoln's core values and leadership attributes
+ Leadership development and virtual training opportunities
+ PTO/parental leave
+ Competitive 401K and employee benefits ( Free financial counseling, health coaching and employee assistance program
+ Tuition assistance program
+ Work arrangements that work for you
+ Effective productivity/technology tools and training
The pay range for this position is $93,300 - $169,700 with **anticipated pay for new hires between the minimum and midpoint of the range** and could vary above and below the listed range as permitted by applicable law. Pay is based on non-discriminatory factors including but not limited to work experience, education, location, licensure requirements, proficiency and qualifications required for the role. The base pay is just one component of Lincoln's total rewards package for employees. In addition, the role may be eligible for the Annual Incentive Program, which is discretionary and based on the performance of the company, business unit and individual. Other rewards may include long-term incentives, sales incentives and Lincoln's standard benefits package.
**About The Company**
Lincoln Financial (NYSE: LNC) helps people to confidently plan for their version of a successful future. We focus on identifying a clear path to financial security, with products including annuities, life insurance, group protection, and retirement plan services.
With our 120-year track record of expertise and integrity, millions of customers trust our solutions and service to help put their goals in reach.
Lincoln Financial Distributors, a broker-dealer, is the wholesale distribution organization of Lincoln Financial. Lincoln Financial is the marketing name for Lincoln Financial Corporation and its affiliates including The Lincoln National Life Insurance Company, Fort Wayne, IN, and Lincoln Life & Annuity Company of New York, Syracuse, NY. Lincoln Financial affiliates, their distributors, and their respective employees, representatives and/or insurance agents do not provide tax, accounting or legal advice.
Lincoln is committed to creating a diverse and inclusive ( environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
Follow us on Facebook ( , X ( , LinkedIn ( , Instagram ( , and YouTube ( . For the latest company news, visit our newsroom ( .
**Be Aware of Fraudulent Recruiting Activities**
If you are interested in a career at Lincoln, we encourage you to review our current openings and apply on our website. Lincoln values the privacy and security of every applicant and urges all applicants to diligently protect their sensitive personal information from scams targeting job seekers. These scams can take many forms including fake employment applications, bogus interviews and falsified offer letters.
Lincoln will not ask applicants to provide their social security numbers, date of birth, bank account information or other sensitive information in job applications. Additionally, our recruiters do not communicate with applicants through free e-mail accounts (Gmail, Yahoo, Hotmail) or conduct interviews utilizing video chat rooms. We will never ask applicants to provide payment during the hiring process or extend an offer without conducting a phone, live video or in-person interview. Please contact Lincoln's fraud team at if you encounter a recruiter or see a job opportunity that seems suspicious.
**Additional Information**
This position may be subject to Lincoln's Political Contribution Policy. An offer of employment may be contingent upon disclosing to Lincoln the details of certain political contributions. Lincoln may decline to extend an offer or terminate employment for this role if it determines political contributions made could have an adverse impact on Lincoln's current or future business interests, misrepresentations were made, or for failure to fully disclose applicable political contributions and or fundraising activities.
Any unsolicited resumes or candidate profiles submitted through our web site or to personal e-mail accounts of employees of Lincoln Financial are considered property of Lincoln Financial and are not subject to payment of agency fees.
Lincoln Financial is an Equal Opportunity employer and, as such, is committed in policy and practice to recruit, hire, compensate, train and promote, in all job classifications, without regard to race, color, religion, sex (including pregnancy), age, national origin, disability, sexual orientation, gender identity and expression, Veteran status, or genetic information. Applicants are evaluated on the basis of job qualifications. If you are a person with a disability that impedes your ability to express your interest for a position through our online application process, or require TTY/TDD assistance, contact us by calling .
This Employer Participates in E-Verify. See the E-Verify ( notices.
Este Empleador Participa en E-Verify. Ver el E-Verify ( avisos.
Lincoln Financial Group ("LFG") is an Equal Opportunity employer and, as such, is committed in policy and practice to recruit, hire, compensate, train and promote, in all job classifications, without regard to race, color, religion, sex (including pregnancy), age, national origin, disability, sexual orientation, gender identity and expression, veterans status, or genetic information. Opportunities throughout LFG are available to employees and applicants and are evaluated on the basis of job qualifications. We have a drug free work environment and we perform pre-employment substance abuse testing.
AVP, Cybersecurity Risk Assessment Mgt

Posted 10 days ago
Job Viewed
Job Description
**Work Arrangement:**
Remote : Work at home employee
**Relocation assistance:** is not available for this opportunity.
**Requisition #:** 74793
**The Role at a Glance**
This position provides leadership, strategic direction and functional expertise to ensure departmental results for the Supplier Risk Team. You will contribute to the strategic development of business solutions that meet the needs, goals and objectives of Cyber Risk Governance.
**What you'll be doing**
+ Delivers and maintains metrics for the Supplier Risk Team.
+ Provides subject matter expertise to internal/external stakeholders on third party security risk assessment.
+ Maintains knowledge on current and emerging developments/trends for cyber security related to third party risk management and third party contracting.
+ Manages a team of analysts responsible for assessing the security risk related to third party engagements.
+ Identifies and directs the implementation of strategic process improvements that significantly improve the quality of third party risk management and due diligence.
+ Responsible for management of IT Audit support activities related to third party assessments for both internal and external audits and exams.
+ Identifies and directs the implementation of strategic process improvements that significantly improve the quality for IT audit support activities.
+ Maintains knowledge on current and emerging developments/trends, assesses the impact, and collaborates with senior management to incorporate new trends and developments in current and future strategies.
+ Directs and enhances organizational initiatives by positively influencing and supporting change management and/or departmental/enterprise initiatives.
+ Identifies and directs strategic process improvements that significantly reduce workloads or improve quality across the team, department and/or business unit.
+ Provides subject matter expertise to team members and internal/external stakeholders on complex assignments/projects.
+ Provides training and development opportunities, including stretch assignments, for team members and gives honest and open feedback to aid in the development of talent.
+ Directs, establishes and implements priorities, performance goals and objectives to ensure departmental results.
+ Directs and evaluates departmental performance and takes appropriate action to meet and/or exceed performance standards.
+ Provides strategic leadership and direction to continually improve the capability and results.
+ Directs/executes approved strategy decisions and contributes to strategy creation.
+ Ensures that top talent is hired and retained.
**What we're looking for**
Must Haves
+ 4 Year/Bachelor's degree (or equivalent)
+ 10+ Years of information security experience including 3+ years of managerial, supervisory, and/or demonstrated leadership experience including influencing senior management/critical stakeholder experience.
**Application Deadline**
Applications for this position will be accepted through October 3, 2025, subject to earlier closure due to applicant volume.
**What's it like to work here?**
At Lincoln Financial, we love what we do. We make meaningful contributions each and every day to empower our customers to take charge of their lives. Working alongside dedicated and talented colleagues, we build fulfilling careers and stronger communities through a company that values our unique perspectives, insights and contributions and invests in programs that empower each of us to take charge of our own future.
**What's in it for you:**
+ Clearly defined career tracks and job levels, along with associated behaviors for each of Lincoln's core values and leadership attributes
+ Leadership development and virtual training opportunities
+ PTO/parental leave
+ Competitive 401K and employee benefits ( Free financial counseling, health coaching and employee assistance program
+ Tuition assistance program
+ Work arrangements that work for you
+ Effective productivity/technology tools and training
The pay range for this position is $146,501 - $264,700 with **anticipated pay for new hires between the minimum and midpoint of the range** and could vary above and below the listed range as permitted by applicable law. Pay is based on non-discriminatory factors including but not limited to work experience, education, location, licensure requirements, proficiency and qualifications required for the role. The base pay is just one component of Lincoln's total rewards package for employees. In addition, the role may be eligible for the Annual Incentive Program, which is discretionary and based on the performance of the company, business unit and individual. Other rewards may include long-term incentives, sales incentives and Lincoln's standard benefits package.
**About The Company**
Lincoln Financial (NYSE: LNC) helps people to confidently plan for their version of a successful future. We focus on identifying a clear path to financial security, with products including annuities, life insurance, group protection, and retirement plan services.
With our 120-year track record of expertise and integrity, millions of customers trust our solutions and service to help put their goals in reach.
Lincoln Financial Distributors, a broker-dealer, is the wholesale distribution organization of Lincoln Financial. Lincoln Financial is the marketing name for Lincoln Financial Corporation and its affiliates including The Lincoln National Life Insurance Company, Fort Wayne, IN, and Lincoln Life & Annuity Company of New York, Syracuse, NY. Lincoln Financial affiliates, their distributors, and their respective employees, representatives and/or insurance agents do not provide tax, accounting or legal advice.
Lincoln is committed to creating an inclusive ( environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
Follow us on Facebook ( , X ( , LinkedIn ( , Instagram ( , and YouTube ( . For the latest company news, visit our newsroom ( .
**Be Aware of Fraudulent Recruiting Activities**
If you are interested in a career at Lincoln, we encourage you to review our current openings and apply on our website. Lincoln values the privacy and security of every applicant and urges all applicants to diligently protect their sensitive personal information from scams targeting job seekers. These scams can take many forms including fake employment applications, bogus interviews and falsified offer letters.
Lincoln will not ask applicants to provide their social security numbers, date of birth, bank account information or other sensitive information in job applications. Additionally, our recruiters do not communicate with applicants through free e-mail accounts (Gmail, Yahoo, Hotmail) or conduct interviews utilizing video chat rooms. We will never ask applicants to provide payment during the hiring process or extend an offer without conducting a phone, live video or in-person interview. Please contact Lincoln's fraud team at if you encounter a recruiter or see a job opportunity that seems suspicious.
**Additional Information**
This position may be subject to Lincoln's Political Contribution Policy. An offer of employment may be contingent upon disclosing to Lincoln the details of certain political contributions. Lincoln may decline to extend an offer or terminate employment for this role if it determines political contributions made could have an adverse impact on Lincoln's current or future business interests, misrepresentations were made, or for failure to fully disclose applicable political contributions and or fundraising activities.
Any unsolicited resumes or candidate profiles submitted through our web site or to personal e-mail accounts of employees of Lincoln Financial are considered property of Lincoln Financial and are not subject to payment of agency fees.
Lincoln Financial ("Lincoln" or "the Company") is an Equal Opportunity employer and, as such, is committed in policy and practice to recruit, hire, compensate, train and promote, in all job classifications, without regard to race, color, religion, sex, age, national origin or disability. Opportunities throughout Lincoln are available to employees and applicants are evaluated on the basis of job qualifications. If you are a person with a disability that impedes your ability to express your interest for a position through our online application process, or require TTY/TDD assistance, contact us by calling .
This Employer Participates in E-Verify. See the E-Verify ( notices.
Este Empleador Participa en E-Verify. Ver el E-Verify ( avisos.
Lincoln Financial Group ("LFG") is an Equal Opportunity employer and, as such, is committed in policy and practice to recruit, hire, compensate, train and promote, in all job classifications, without regard to race, color, religion, sex (including pregnancy), age, national origin, disability, sexual orientation, gender identity and expression, veterans status, or genetic information. Opportunities throughout LFG are available to employees and applicants and are evaluated on the basis of job qualifications. We have a drug free work environment and we perform pre-employment substance abuse testing.
Senior IS Security Risk Analyst
Posted today
Job Viewed
Job Description
Location: Columbia, SC (Partially onsite - Onsite Tuesday, Wednesday, Thursday)
Duration: 12 Months
C2 Eligibility is required
Job Summary:
Duties/About the role:
- Develop strategies and approaches for business development proposals within a compliance and systems security context. Plan and perform compliance and systems security activities in alignment with contractual role. Communicate and escalate compliance and risk issues to the appropriate customer representative and/or level of management. Act as a change agent to influence I/S and corporate compliance culture in alignment with business constituency. Develop strong systems security customer business relationship. Provide expert level consultation regards contractual system security obligations, frameworks, control requirements.
- 20% Oversee remediation of new and outstanding issues, including Information Security Risk Exception process, across multiple business areas and security frameworks. Utilize tools to track and report on compliance posture.
- 20% Conduct or lead others in the procedural and operational review of internal IS security compliance standards. Oversee formal risk analysis and self-assessments to determine effectiveness of controls and ensure creation of action plans to remediate identified risks. Identify and champion efficiency improvements related to security, risk and compliance processes. Engage appropriate Client Management areas to facilitate process improvements through formal IS Methodology.
- 20% Lead the development, implementation and documentation of Information Security policies, procedures, processes and programs to guide IS toward continuous compliance. May conduct or lead others in the analysis and interpretation of security regulations and controls. Proactively provide strategic consulting to IS functional teams with the development, implementation, monitoring, and reporting of control processes, documentation and compliance routines for moderate to highly complex work efforts.
- 20% Serve as an interface with external entities for governance and compliance reviews regarding information security risk.
- 10% Conduct or lead others in the investigation, documentation and resolution of Information Security Incidents. Advises senior management of critical issues that may affect organization.
- 10% Research emerging security topics, threats and capabilities to create/update policy and governance. Engage appropriate leaders to evaluate and mitigate potential exposure. Promote organizational security awareness by developing security training, Security Council bulletins, security policies, standards and best practices, as well as delivering training to personnel
- Management of risk management activities: Process, monitor, and report on security/compliance risk items.
- Perform Corporate Risk Assessment and communicate results to Senior Management.
- Conduct research and assessments on security related topics. (Policy, Third-Party, Security Processes)
- Develop and communicate security policies and security standards.
- Provide consultation and guidance to the different Business Units for security and compliance activities.
- Facilitate meetings and conduct presentations with various levels of management.
- Strategic Security & Compliance Services
- SSCS Team is a small team, however we work with multiple Lines of Business (LOB) and teams across the company.
- Currently oversee multiple strategies: Enterprise Risk Management, Third Party Risk Management, Access Management, Application Security, and others.
- Support over 20 LOBs under the Client's umbrella.
- Manage Corporate Security Framework (Security Policies).
- Conduct risk assessments periodically and present results to senior management.
- Conduct research and analysis on security/compliance related topics.
- Part of the I/S Governance committee. Chair the Policy and I/S Standards Committee.
- Engaged in the yearly budget for Security and Compliance activities.
Required Experience:
- 8 years of I/T experience including 6 years of IT security, risk assessment and/or compliance experience. Successful completion of Client's I/S Entry Level Training Program (ELTP) may be substituted for 2 years of I/T experience.
- Bachelor's Degree in Computer Science, Information Technology or related degree. or 4 years of job related work experience or 2 years of job related experience plus an associate's degree in Computer Science, Information Technology or other job related degree.
- ISC2 Certified Information Systems Security Professional (CISSP).
- Microsoft (M365): Outlook, Teams, Excel, Word, Lists, PowerPoint, SharePoint (Intermediate)
- Complete understanding of systems security business life cycle methodologies.
- Subject Matter Expert in both government and private risk frameworks and control implementations.
- Comprehensive understanding of business system security risk management, information system security and compliance practices.
- Demonstrate excellent analytical, problem solving, decision-making skills, interpersonal and ownership skills.
- Proven ability to interpret and apply knowledge of regulatory/accreditation requirements.
- Ability to lead others in solving problems often spanning multiple environments and business areas. Ability to effect change and bring security, risk and compliance knowledge to the organization through the use of positive influence.
- Understanding of infrastructure and networking architecture WANs, LANs, Internet, intranets and communication protocols.
- Excellent communication skills in presenting results to customer, senior management, and matrix staff both verbally and in writing.
- Demonstrated ability to develop metrics, perform critical analysis and develop executive decision support content.
- Possess excellent collaboration skills with a wide variety of internal matrix and management staff.
- Microsoft: Visio, Planner, Forms, PowerBI, Power Automate). RSA-Archer, Service Now (Intermediate)
Security Engineer - Security Risk Management
Posted 1 day ago
Job Viewed
Job Description
Summary:
The Meta Security team is responsible for improving the security posture of the software and services used throughout our company. Our work spans Facebook, Instagram, WhatsApp, Oculus, and all of the underlying systems and infrastructure that power these products behind the scenes.We are seeking a committed and experienced security engineer to join our Security Risk Management (SRM) team to help design and build solutions to:* Drive better understanding of security risk and enable investment decisions through automation, monitoring, and tracking of Meta's security tools, systems, and controls* Enable security and software engineers to seamlessly respond to requests to prove effective design and operation of security capabilities* Increase maturity of security capabilities through control improvements and redesign
Required Skills:
Security Engineer - Security Risk Management Responsibilities:
-
Work with a team of software, data, and security engineers that design, build, and own software solutions that scale high fidelity security risk contextualization, tracking, and reporting
-
Understand and influence evolution of security capabilities across various domains to scale and automate: a) monitoring the effectiveness, and b) increasing the maturity of those capabilities
-
Design and build solutions to scale managing and responding to risk management & compliance related requests
Minimum Qualifications:
Minimum Qualifications:
-
Bachelor's degree or equivalent experience in information security
-
5+ years work experience securing enterprise-scale infrastructure software and services
-
3-5+ years programming experience with at least one of the following languages: Python, PHP, Ruby, or similar scripting languages
-
Experience remediating infrastructure security gaps across broad corporate boundaries using influence and relationships
-
Experience with security control automation/monitoring or "compliance as code" implementations
-
Experience thinking critically and defending solutions with solid communications skills in a cross-functional setting to influence decision makers across all levels of technical background
Preferred Qualifications:
Preferred Qualifications:
-
Networking and system administration experience of server (Linux, Windows) and client (Windows, macOS, Linux) operating systems
-
Experience influencing software engineers to build products meant to scale security solutions
-
Experience generating automated metrics to measure service and program effectiveness and consistency
-
Experience with common risk & compliance program activities (e.g., controls, risk, policy management)
Public Compensation:
$147,000/year to $208,000/year + bonus + equity + benefits
Industry: Internet
Equal Opportunity:
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at
Senior IS Security Risk Analyst
Posted 1 day ago
Job Viewed
Job Description
Duties: Develop strategies and approaches for business development proposals within a compliance and systems security context. Plan and perform compliance and systems security activities in alignment with contractual role. Communicate and escalate compliance and risk issues to the appropriate customer representative and/or level of management. Act as a change agent to influence I/S and corporate compliance culture in alignment with business constituency. Develop strong systems security for customer business relationship. Provide expert level consultation regarding contractual system security obligations, frameworks, control requirements.
•20% Oversee remediation of new and outstanding issues, including Information Security Risk Exception process, across multiple business areas and security frameworks. Utilize tools to track and report on compliance posture.
•20% Conduct or lead others in the procedural and operational review of internal IS security compliance standards. Oversee formal risk analysis and self-assessments to determine effectiveness of controls and ensure creation of action plans to remediate identified risks. Identify and champion efficiency improvements related to security, risk and compliance processes. Engage appropriate Client Management areas to facilitate process improvements through formal IS Methodology.
•20% Lead the development, implementation and documentation of Information Security policies, procedures, processes and programs to guide IS toward continuous compliance. May conduct or lead others in the analysis and interpretation of security regulations and controls. Proactively provide strategic consulting to IS functional teams with the development, implementation, monitoring, and reporting of control processes, documentation and compliance routines for moderate to highly complex work efforts.
•20% Serve as an interface with external entities for governance and compliance reviews regarding information security risk.
•10% Conduct or lead others in the investigation, documentation and resolution of Information Security Incidents. Advises senior management of critical issues that may affect organization.
•10% Research emerging security topics, threats and capabilities to create/update policy and governance. Engage appropriate leaders to evaluate and mitigate potential exposure. Promote organizational security awareness by developing security training, Security Council bulletins, security policies, standards and best practices, as well as delivering training to personnel.
Skills: Required Skills and Abilities: Complete understanding of system security business life cycle methodologies. Subject Matter Expert in both government and private risk frameworks and control implementations. Comprehensive understanding of business system security risk management, information system security and compliance practices. Demonstrate excellent analytical, problem solving, decision-making skills, interpersonal and ownership skills. Proven ability to interpret and apply knowledge of regulatory/accreditation requirements. The ability to lead others in solving problems often spanning multiple environments and business areas. Ability to effect change and bring security, risk and compliance knowledge to the organization using positive influence. Understanding of infrastructure and networking architecture WANs, LANs, Internet, intranets and communication protocols. Excellent communication skills in presenting results to customer, senior management, and matrix staff both verbally and in writing. Demonstrated ability to develop metrics, perform critical analysis and develop executive decision support content. Possess excellent collaboration skills with a wide variety of internal matrix and management staff.
Required Software and Tools: Standard office equipment.
Preferred Licenses and Certificates:
ISC2 Certified Information Systems Security Professional (CISSP).
Keywords:
Education: Required Education : Bachelor's Degree in Computer Science, Information Technology or related degree. or 4 years of job related work experience or 2 years of job related experience plus an associate’s degree in Computer Science, Information Technology or other job related degree.
Required Work Experience : 8 years of I/T experience including 6 years of IT security, risk assessment and/or compliance experience. Successful completion of I/S Entry Level Training Program (ELTP) may be substituted for 2 years of I/T experience.
IS Required Education: Bachelor's Degree in Computer Science, Information Technology or related degree. or 4 years of job related work experience or 2 years of job related experience plus an associate’s degree in Computer Science, Information Technology or other job related degree.
Required Work Experience : 8 years of I/T experience including 6 years of IT security, risk assessment and/or compliance experience. Successful completion of I/S Entry Level Training Program (ELTP) may be substituted for 2 years of I/T experience.
C2 Eligibility is required Team Name: Strategic Security & Compliance Services Work Hours - 8-5 p.m. Partially onsite – Onsite Tuesday, Wednesday, Thursday, but could also be required to come in more for important meetings etc. It is highly recommended to be onsite more days during training period. Not required but highly recommended.
Required Technologies : Microsoft (M365): Outlook, Teams, Excel, Word, Lists, PowerPoint, SharePoint (Intermediate)
Nice to Have:
Microsoft: Visio, Planner, Forms, PowerBI, Power Automate). RSA-Archer, Service Now (Intermediate)
Day to Day:
1. Management of risk management activities: Process, monitor, and report on security/compliance risk items.
2. Perform Corporate Risk Assessment and communicate results to Senior Management.
3. Conduct research and assessments on security-related topics. (Policy, Third-Party, Security Processes)
4. Develop and communicate security policies and security standards.
5. Provide consultation and guidance to the different Business Units for security and compliance activities.
6. Facilitate meetings and conduct presentations with various levels of management.
About The Team: 1. SSCS Team is a small team, however we work with multiple Lines of Business (LOB) and teams across the company.
a. Currently oversee multiple strategies: Enterprise Risk Management, Third Party Risk Management, Access Management, Application Security, and others.
b. Support over 20 LOBs under our umbrella.
c. Manage Corporate Security Framework (Security Policies).
d. Conduct risk assessments periodically and present results to senior management.
e. Conduct research and analysis on security/compliance related topics.
f. Part of the I/S Governance committee. Chair the Policy and I/S Standards Committee.
g. Engaged in the yearly budget for Security and Compliance activities.
Security Engineer - Security Risk Management

Posted 18 days ago
Job Viewed
Job Description
The Meta Security team is responsible for improving the security posture of the software and services used throughout our company. Our work spans Facebook, Instagram, WhatsApp, Oculus, and all of the underlying systems and infrastructure that power these products behind the scenes.We are seeking a committed and experienced security engineer to join our Security Risk Management (SRM) team to help design and build solutions to:* Drive better understanding of security risk and enable investment decisions through automation, monitoring, and tracking of Meta's security tools, systems, and controls* Enable security and software engineers to seamlessly respond to requests to prove effective design and operation of security capabilities* Increase maturity of security capabilities through control improvements and redesign
**Required Skills:**
Security Engineer - Security Risk Management Responsibilities:
1. Work with a team of software, data, and security engineers that design, build, and own software solutions that scale high fidelity security risk contextualization, tracking, and reporting
2. Understand and influence evolution of security capabilities across various domains to scale and automate: a) monitoring the effectiveness, and b) increasing the maturity of those capabilities
3. Design and build solutions to scale managing and responding to risk management & compliance related requests
**Minimum Qualifications:**
Minimum Qualifications:
4. Bachelor's degree or equivalent experience in information security
5. 5+ years work experience securing enterprise-scale infrastructure software and services
6. 3-5+ years programming experience with at least one of the following languages: Python, PHP, Ruby, or similar scripting languages
7. Experience remediating infrastructure security gaps across broad corporate boundaries using influence and relationships
8. Experience with security control automation/monitoring or "compliance as code" implementations
9. Experience thinking critically and defending solutions with solid communications skills in a cross-functional setting to influence decision makers across all levels of technical background
**Preferred Qualifications:**
Preferred Qualifications:
10. Networking and system administration experience of server (Linux, Windows) and client (Windows, macOS, Linux) operating systems
11. Experience influencing software engineers to build products meant to scale security solutions
12. Experience generating automated metrics to measure service and program effectiveness and consistency
13. Experience with common risk & compliance program activities (e.g., controls, risk, policy management)
**Public Compensation:**
$147,000/year to $208,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at
Security Engineer - Security Risk Management

Posted 18 days ago
Job Viewed
Job Description
The Meta Security team is responsible for improving the security posture of the software and services used throughout our company. Our work spans Facebook, Instagram, WhatsApp, Oculus, and all of the underlying systems and infrastructure that power these products behind the scenes.We are seeking a committed and experienced security engineer to join our Security Risk Management (SRM) team to help design and build solutions to:* Drive better understanding of security risk and enable investment decisions through automation, monitoring, and tracking of Meta's security tools, systems, and controls* Enable security and software engineers to seamlessly respond to requests to prove effective design and operation of security capabilities* Increase maturity of security capabilities through control improvements and redesign
**Required Skills:**
Security Engineer - Security Risk Management Responsibilities:
1. Work with a team of software, data, and security engineers that design, build, and own software solutions that scale high fidelity security risk contextualization, tracking, and reporting
2. Understand and influence evolution of security capabilities across various domains to scale and automate: a) monitoring the effectiveness, and b) increasing the maturity of those capabilities
3. Design and build solutions to scale managing and responding to risk management & compliance related requests
**Minimum Qualifications:**
Minimum Qualifications:
4. Bachelor's degree or equivalent experience in information security
5. 5+ years work experience securing enterprise-scale infrastructure software and services
6. 3-5+ years programming experience with at least one of the following languages: Python, PHP, Ruby, or similar scripting languages
7. Experience remediating infrastructure security gaps across broad corporate boundaries using influence and relationships
8. Experience with security control automation/monitoring or "compliance as code" implementations
9. Experience thinking critically and defending solutions with solid communications skills in a cross-functional setting to influence decision makers across all levels of technical background
**Preferred Qualifications:**
Preferred Qualifications:
10. Networking and system administration experience of server (Linux, Windows) and client (Windows, macOS, Linux) operating systems
11. Experience influencing software engineers to build products meant to scale security solutions
12. Experience generating automated metrics to measure service and program effectiveness and consistency
13. Experience with common risk & compliance program activities (e.g., controls, risk, policy management)
**Public Compensation:**
$147,000/year to $208,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at
Be The First To Know
About the latest Sr analyst it security risk assessment third party Jobs in Columbia !
Senior IS Security Risk Analyst - Request
Posted today
Job Viewed
Job Description
Description:
Why should you join the BlueCross BlueShield of South Carolina family of companies? Other companies come and go, but for more than seven decades we've been part of the national landscape, with our roots firmly embedded in the South Carolina community. Business and political climates may change, but we're stronger than ever. Our A.M. Best rating is A+ (Superior) - making us the only health insurance company in South Carolina with that rating. We're the largest insurance company in South Carolina .and much more. We are one of the nation's leading administrators of government contracts. We operate one of the most sophisticated data processing centers in the Southeast. We also have a diverse family of subsidiary companies that allows us to build on a variety of business strengths. We deliver outstanding service to our customers. If you are dedicated to the same philosophy, consider joining our team!
Job Title: Senior IS Security Risk Analyst
Position Notes:
- Required Education: Bachelor's Degree in Computer Science, Information Technology or related degree. or 4 years of job related work experience or 2 years of job related experience plus an associate's degree in Computer Science, Information Technology or other job related degree.
- Required Work Experience: 8 years of I/T experience including 6 years of IT security, risk assessment and/or compliance experience. Successful completion of BCBSSC I/S Entry Level Training Program (ELTP) may be substituted for 2 years of I/T experience.
- C2 Eligibility is required
- Team Name: Strategic Security & Compliance Services
- Work Hours - 8-5 p.m.
- Partially onsite - Onsite Tuesday, Wednesday, Thursday, but could also be required to come in more for important meetings etc. Highly recommended to be onsite more days during training period. Not required but highly recommended.
- Required Technologies: Microsoft (M365): Outlook, Teams, Excel, Word, Lists, PowerPoint, SharePoint (Intermediate)
- Nice to Have: Microsoft: Visio, Planner, Forms, PowerBI, Power Automate). RSA-Archer, Service Now (Intermediate)
Develop strategies and approaches for business development proposals within a compliance and systems security context. Plan and perform compliance and systems security activities in alignment with contractual role. Communicate and escalate compliance and risk issues to the appropriate customer representative and/or level of management. Act as a change agent to influence I/S and corporate compliance culture in alignment with business constituency. Develop strong systems security customer business relationship. Provide expert level consultation regards contractual system security obligations, frameworks, control requirements. 20% Oversee remediation of new and outstanding issues, including Information Security Risk Exception process, across multiple business areas and security frameworks. Utilize tools to track and report on compliance posture. 20% Conduct or lead others in the procedural and operational review of internal IS security compliance standards. Oversee formal risk analysis and self-assessments to determine effectiveness of controls and ensure creation of action plans to remediate identified risks. Identify and champion efficiency improvements related to security, risk and compliance processes. Engage appropriate Client Management areas to facilitate process improvements through formal IS Methodology. 20% Lead the development, implementation and documentation of Information Security policies, procedures, processes and programs to guide IS toward continuous compliance. May conduct or lead others in the analysis and interpretation of security regulations and controls. Proactively provide strategic consulting to IS functional teams with the development, implementation, monitoring, and reporting of control processes, documentation and compliance routines for moderate to highly complex work efforts. 20% Serve as an interface with external entities for governance and compliance reviews regarding information security risk. 10% Conduct or lead others in the investigation, documentation and resolution of Information Security Incidents. Advises senior management of critical issues that may affect organization. 10% Research emerging security topics, threats and capabilities to create/update policy and governance. Engage appropriate leaders to evaluate and mitigate potential exposure. Promote organizational security awareness by developing security training, Security Council bulletins, security policies, standards and best practices, as well as delivering training to personnel.
Required Skills and Abilities:
- Complete understanding of systems security business life cycle methodologies. Subject Matter Expert in both government and private risk frameworks and control implementations.
- Comprehensive understanding of business system security risk management, information system security and compliance practices.
- Demonstrate excellent analytical, problem solving, decision-making skills, interpersonal and ownership skills.
- Proven ability to interpret and apply knowledge of regulatory/accreditation requirements.
- Ability to lead others in solving problems often spanning multiple environments and business areas.
- Ability to effect change and bring security, risk and compliance knowledge to the organization through the use of positive influence.
- Understanding of infrastructure and networking architecture WANs, LANs, Internet, intranets and communication protocols. Excellent communication skills in presenting results to customer, senior management, and matrix staff both verbally and in writing.
- Demonstrated ability to develop metrics, perform critical analysis and develop executive decision support content.
- Possess excellent collaboration skills with a wide variety of internal matrix and management staff.
Required Education : Bachelor's Degree in Computer Science, Information Technology or related degree. or 4 years of job related work experience or 2 years of job related experience plus an associate's degree in Computer Science, Information Technology or other job related degree.
Required Work Experience: 8 years of I/T experience including 6 years of IT security, risk assessment and/or compliance experience. Successful completion of BCBSSC I/S Entry Level Training Program (ELTP) may be substituted for 2 years of I/T experience.
This is the pay range that Magnit reasonably expects to pay someone for this position is $40/hour - $63/hour . Benefits: Medical, Dental, Vision, 401K (provided minimum eligibility hours are met).
BlueCross is a strong supporter of our veterans, and many service men and women have joined our ranks. We've found the dedication, work ethic and job skills that serve well in the military excel in many of our lines of business, and we proudly have veterans filling positions in Human Resources, Information Technology, Customer Service, Operations, General Services and more.
Through our government contracts, we also have employees serving at Shaw Air Force Base, the Naval Health Clinic in Charleston, the Naval Hospital in Beaufort and in our hometown of Columbia, S.C., at Ft. Jackson. If you are a full-time employee in the National Guard or Reserves, we will even cover the difference in your pay if you are called to active duty. If you're ready to join in a diverse company with secure, community roots and an innovative future, apply for a position now!
QUALIFICATION/ LICENSURE :
- Work Authorization : US Citizen
- Preferred years of experience : 1+ Years
- Travel Required : No travel required
- Shift timings: Not specified
Senior IS Security Risk Analyst - Request
Posted 8 days ago
Job Viewed
Job Description
Description:
Why should you join the BlueCross BlueShield of South Carolina family of companies? Other companies come and go, but for more than seven decades we've been part of the national landscape, with our roots firmly embedded in the South Carolina community. Business and political climates may change, but we're stronger than ever. Our A.M. Best rating is A+ (Superior) - making us the only health insurance company in South Carolina with that rating. We're the largest insurance company in South Carolina .and much more. We are one of the nation's leading administrators of government contracts. We operate one of the most sophisticated data processing centers in the Southeast. We also have a diverse family of subsidiary companies that allows us to build on a variety of business strengths. We deliver outstanding service to our customers. If you are dedicated to the same philosophy, consider joining our team!
Job Title: Senior IS Security Risk Analyst
Position Notes:
- Required Education: Bachelor's Degree in Computer Science, Information Technology or related degree. or 4 years of job related work experience or 2 years of job related experience plus an associate's degree in Computer Science, Information Technology or other job related degree.
- Required Work Experience: 8 years of I/T experience including 6 years of IT security, risk assessment and/or compliance experience. Successful completion of BCBSSC I/S Entry Level Training Program (ELTP) may be substituted for 2 years of I/T experience.
- C2 Eligibility is required
- Team Name: Strategic Security & Compliance Services
- Work Hours - 8-5 p.m.
- Partially onsite - Onsite Tuesday, Wednesday, Thursday, but could also be required to come in more for important meetings etc. Highly recommended to be onsite more days during training period. Not required but highly recommended.
- Required Technologies: Microsoft (M365): Outlook, Teams, Excel, Word, Lists, PowerPoint, SharePoint (Intermediate)
- Nice to Have: Microsoft: Visio, Planner, Forms, PowerBI, Power Automate). RSA-Archer, Service Now (Intermediate)
Develop strategies and approaches for business development proposals within a compliance and systems security context. Plan and perform compliance and systems security activities in alignment with contractual role. Communicate and escalate compliance and risk issues to the appropriate customer representative and/or level of management. Act as a change agent to influence I/S and corporate compliance culture in alignment with business constituency. Develop strong systems security customer business relationship. Provide expert level consultation regards contractual system security obligations, frameworks, control requirements. • 20% Oversee remediation of new and outstanding issues, including Information Security Risk Exception process, across multiple business areas and security frameworks. Utilize tools to track and report on compliance posture. • 20% Conduct or lead others in the procedural and operational review of internal IS security compliance standards. Oversee formal risk analysis and self-assessments to determine effectiveness of controls and ensure creation of action plans to remediate identified risks. Identify and champion efficiency improvements related to security, risk and compliance processes. Engage appropriate Client Management areas to facilitate process improvements through formal IS Methodology. • 20% Lead the development, implementation and documentation of Information Security policies, procedures, processes and programs to guide IS toward continuous compliance. May conduct or lead others in the analysis and interpretation of security regulations and controls. Proactively provide strategic consulting to IS functional teams with the development, implementation, monitoring, and reporting of control processes, documentation and compliance routines for moderate to highly complex work efforts. • 20% Serve as an interface with external entities for governance and compliance reviews regarding information security risk. • 10% Conduct or lead others in the investigation, documentation and resolution of Information Security Incidents. Advises senior management of critical issues that may affect organization. • 10% Research emerging security topics, threats and capabilities to create/update policy and governance. Engage appropriate leaders to evaluate and mitigate potential exposure. Promote organizational security awareness by developing security training, Security Council bulletins, security policies, standards and best practices, as well as delivering training to personnel.
Required Skills and Abilities:
- Complete understanding of systems security business life cycle methodologies. Subject Matter Expert in both government and private risk frameworks and control implementations.
- Comprehensive understanding of business system security risk management, information system security and compliance practices.
- Demonstrate excellent analytical, problem solving, decision-making skills, interpersonal and ownership skills.
- Proven ability to interpret and apply knowledge of regulatory/accreditation requirements.
- Ability to lead others in solving problems often spanning multiple environments and business areas.
- Ability to effect change and bring security, risk and compliance knowledge to the organization through the use of positive influence.
- Understanding of infrastructure and networking architecture WANs, LANs, Internet, intranets and communication protocols. Excellent communication skills in presenting results to customer, senior management, and matrix staff both verbally and in writing.
- Demonstrated ability to develop metrics, perform critical analysis and develop executive decision support content.
- Possess excellent collaboration skills with a wide variety of internal matrix and management staff.
Required Education : Bachelor's Degree in Computer Science, Information Technology or related degree. or 4 years of job related work experience or 2 years of job related experience plus an associate's degree in Computer Science, Information Technology or other job related degree.
Required Work Experience: 8 years of I/T experience including 6 years of IT security, risk assessment and/or compliance experience. Successful completion of BCBSSC I/S Entry Level Training Program (ELTP) may be substituted for 2 years of I/T experience.
This is the pay range that Magnit reasonably expects to pay someone for this position is $40/hour - $63/hour . Benefits: Medical, Dental, Vision, 401K (provided minimum eligibility hours are met).
BlueCross is a strong supporter of our veterans, and many service men and women have joined our ranks. We've found the dedication, work ethic and job skills that serve well in the military excel in many of our lines of business, and we proudly have veterans filling positions in Human Resources, Information Technology, Customer Service, Operations, General Services and more.
Through our government contracts, we also have employees serving at Shaw Air Force Base, the Naval Health Clinic in Charleston, the Naval Hospital in Beaufort and in our hometown of Columbia, S.C., at Ft. Jackson. If you are a full-time employee in the National Guard or Reserves, we will even cover the difference in your pay if you are called to active duty. If you're ready to join in a diverse company with secure, community roots and an innovative future, apply for a position now!
QUALIFICATION/ LICENSURE :
- Work Authorization : US Citizen
- Preferred years of experience : 1+ Years
- Travel Required : No travel required
- Shift timings: Not specified