Demo

Third-Party Risk Analyst

Simpson Thacher & Bartlett LLP
York, NY Full Time
POSTED ON 4/4/2026
AVAILABLE BEFORE 5/28/2026
The Third-Party Security Analyst will play a key role in supporting the Third-Party Security Team in both the development and execution of the firm’s Third-party Security Program. This includes identifying, assessing, monitoring, and mitigating risks associated with vendors, suppliers, and service providers across the globe as well as supporting strategic program initiatives.

The ideal candidate is an experienced information security or risk management professional with a background in third-party assessment execution, IT Risk management or IT Audit. The candidate should possess strong analytical skills, attention to detail, and the ability to collaborate cross-functionally with legal, Vendor Management Office, and IT security teams. Strong communication and interpersonal skills are required to effectively engage with third parties.

Essential Job Duties & Responsibilities

  • Conduct information security due diligence during vendor onboarding, at renewal, and periodic review cycles.
  • Apply a risk-based approach to third party security assessments, including documenting compensating controls and risks acceptances where appropriate.
  • Maintain comprehensive vendor inventory, including vendor profiling and Inherent Risk determination.
  • Maintain a third-party risk register and track mitigation efforts for identified security risks.
  • Develop and implement strategies to mitigate identified risks, working closely with third parties and internal stakeholders to address security gaps.
  • Support a continuous monitoring program to assess third-party security posture and follow up on identified vulnerabilities and security risks.
  • Partner with general counsel and vendor management to incorporate information security requirements into third-party contracts.
  • Work with internal security teams to investigate and respond to third-party related security incidents.
  • Support and enhance escalation procedures and remediation requirements related to third-party security breaches.
  • Prepare and present third party risk metrics, dashboards, trends, and highlighted risks to senior management and IT leadership.
  • Contribute to the continuous improvement and scalability of the Firm’s third party security risk management program.

Education

Required

  • Bachelor’s degree or related experience required

Preferred

  • Professional certifications, such as CISSP, CRISC, CISM, CISA, ISO 27001 Lead Auditor/Implementor.

Required

Skills and Experience

  • 5 years of experience in information security, third-party risk management, IT risk, or cybersecurity assurance, with at least 3 years focused on third party risk management.
  • Experience conducting information security risk assessments of third-parties, vendors, and service providers.
  • Strong understanding of information security controls and frameworks (ISO 27001/27002, NIST CSF, CIS Controls, etc.)
  • Familiarity with third-party security domains, including data protection, access controls, incident response and cloud security.
  • Ability to assess third-party responses to security questionnaires, and analyze security documentation, audit reports, vulnerability scans, and penetration test results to identify control gaps and remediation requirements.
  • Ability to prioritize third party security risks based on inherent risk, business criticality, and compensating controls.
  • Experience producing clear risk summaries, remediation recommendations, and executive level reporting
  • Familiarity with information security and data protections requirements in third party contracts.
  • Strong communication and negotiation skills to work effectively with internal and external stakeholders.
  • Ability to work independently and collaboratively in a team environment
  • Demonstrated ability to handle sensitive and/or confidential material and information with suitable discretion.

Preferred

  • Experience developing processes aligned with the third-party risk management lifecycle.
  • Familiarity with information security considerations for vendors leveraging AI or providing AI centric solutions.

Salary Information

NY Only: The estimated base salary range for this position is $100,000 to $120,000 at the time of posting.

The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible.

Simpson Thacher will not sponsor applicants for work visas for this position.

Privacy Notice

For information about how Simpson Thacher & Bartlett LLP collects and processes your personal information, please refer to our Privacy Notice available at https://www.stblaw.com/other/privacy-notice.

Simpson Thacher & Bartlett is committed to a collegial work environment in which all individuals are treated with respect and dignity. The Firm prohibits discrimination or harassment based upon race, color, religion, gender, gender identity or expression, age, national origin, citizenship status, disability, marital or partnership status, sexual orientation, veteran’s status or any other legally protected status. This Policy pertains to every aspect of an individual’s relationship with the Firm, including but not limited to recruitment, hiring, compensation, benefits, training and development, promotion, transfer, discipline, termination, and all other privileges, terms and conditions of employment.

Salary : $100,000 - $120,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Third-Party Risk Analyst?

Sign up to receive alerts about other jobs on the Third-Party Risk Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$96,228 - $129,772
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$121,926 - $164,179
Income Estimation: 
$124,413 - $154,875
Income Estimation: 
$87,128 - $112,557
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Simpson Thacher & Bartlett LLP

  • Simpson Thacher & Bartlett LLP York, NY
  • The Senior UX Researcher will lead efforts to scale and operationalize UX research capabilities within the Practice Solutions team, while working closely w... more
  • 9 Days Ago

  • Simpson Thacher & Bartlett LLP Palo Alto, CA
  • Simpson Thacher & Bartlett LLP is one of the world’s leading international law firms. The Firm was established in 1884 and has approximately 2,000 lawyers.... more
  • 9 Days Ago

  • Simpson Thacher & Bartlett LLP Los Angeles, CA
  • Simpson Thacher & Bartlett LLP is one of the world’s leading international law firms. The Firm was established in 1884 and has approximately 2,000 lawyers.... more
  • 9 Days Ago

  • Simpson Thacher & Bartlett LLP York, NY
  • Position Summary The Digital Adoption Content Manager supports the firm’s digital adoption initiatives by implementing scalable digital learning strategies... more
  • 10 Days Ago


Not the job you're looking for? Here are some other Third-Party Risk Analyst jobs in the York, NY area that may be a better fit.

  • kalshi York, NY
  • What We're Up To Kalshi has defined a new category: prediction markets. Kalshi allows people to trade on the outcome of any events and turn any question ab... more
  • 12 Days Ago

  • Cititec York, NY
  • Techno-Functional Risk / P&L Analyst Oil Trading New York, NY Permanent Our client is a global energy trading firm who are seeking a techno-functional spec... more
  • 15 Days Ago

AI Assistant is available now!

Feel free to start your new journey!