Demo

Business Analyst (Third-Party Security & Privacy Risk Management)

Talent Groups
Waltham, MA Full Time
POSTED ON 5/11/2026
AVAILABLE BEFORE 6/6/2026
Duration: 6 months to start

Job Description

Role Summary:

The Third Party Risk Management Analyst / Business Analyst (BA) is a temporary contractor supporting the Patient Trust initiative by identifying, strengthening oversight, accountability, and risk management of third-party processors that store, access, or handle patient data (including PHI/PII as applicable). The BA partners with Security, Privacy, Procurement, Legal, Risk, and business owners to define requirements, analyze current state and deliver foundational governance artifacts such as a unified third-party patient data inventory, a vendor lookback plan, and a risk-tiering model.

Key Responsibilities

  • Deliver Phase 1 foundations for Workstream 3: translate the deck deliverables into requirements, detailed process steps, owners, and measurable outputs across the Vendor Lookback Plan, Unified Third-Party Patient Data Inventory, and Risk-Tiering Model.
  • Vendor Lookback Plan (Apr-Nov): build the initial vendor universe: coordinate OneTrust pull, LeanIX pull, and define comparison logic to establish the starting population of potential patient-data vendors.
  • Identify likely patient-data service areas: perform procurement taxonomy review, category classification, and targeted vendor list requests to focus on service areas most likely to process patient data.
  • Consolidate and normalize the master vendor list: merge OneTrust/LeanIX/Procurement sources; deduplicate; standardize vendor names; and capture baseline context (service description, business owner, system/app linkage as available).
  • Confirm patient data processing (in-scope determination): execute desktop validation and drive targeted business owner confirmations to finalize binary in-scope / out-of-scope decisions.
  • Operationalize risk-based lookback triggers: define and document trigger logic (time since review, data sensitivity, volume, access level, criticality) and apply it to the in-scope vendor set to determine reassessment needs.
  • Drive formal approval of the lookback methodology: prepare decision materials and facilitate approvals for scope, triggers, and prioritization logic with Workstream 3 stakeholders.
  • Deliver the Unified Third-Party Patient Data Inventory (Jul-Nov): ensure the inventory captures required outputs (normalized vendor name, business owner, service description, patient data involvement yes/no, data types, geographic footprint, and risk tier once established).
  • Build the Risk-Tiering Model (Aug-Nov) and prioritized lookback queue: define tier inputs (sensitivity, volume, access, criticality, time since review), group vendors into high/medium/low tiers tied to review expectations, and create an execution queue aligned to capacity, phased waves, and future automation.
  • Support Phase 2 execution (Oversight & Monitoring): support conduct of lookback assessments and operationalization of the Third-Party Assurance Program (annual security & privacy reviews, evidence-based control testing, SOC 2 / ISO 27001 intake review processes).
  • Continuous monitoring of critical vendors: help define the monitoring approach using questionnaires, external signals, and/or integrated vendor-risk tools; document thresholds, cadence, escalation paths, and reporting.
  • Third-Party Incident Response Integration: define and document vendor notification and cooperation expectations within defined timeframes for patient data/PHI exposure events; align playbooks and handoffs with Security Incident Response and Privacy.

Required Qualifications

  • 5 years of business analysis experience delivering process, data, and governance outcomes in regulated environments.
  • Hands-on experience with third-party / vendor security risk management (TPRM), including risk assessments, evidence collection, remediation tracking, and stakeholder communications.
  • Strong understanding of security and privacy fundamentals as they relate to third parties (e.g., access, data handling, encryption, incident response, audit artifacts).
  • Demonstrated ability to build and maintain inventories or registries (vendors, applications, data flows) with attention to data quality, normalization, and reporting.
  • Proficiency with requirements elicitation/documentation techniques (workshops, interviews, user stories, acceptance criteria) and process mapping.
  • Excellent written and verbal communication skills; ability to translate technical and control concepts into business-friendly language.
  • Experience working cross-functionally with Security, Privacy, Procurement/Vendor
  • Management, Legal, IT, and business owners.


  • Preferred Qualifications:

    • Experience supporting healthcare data programs and/or familiarity with HIPAA/HITECH concepts (or equivalent healthcare privacy/security frameworks).
    • Experience reviewing third-party audit reports and certifications (SOC 2 Type II, ISO 27001, NIST Privacy Framework, ISO 27701) and translating results into risk decisions.
    • Experience with TPRM and GRC tooling and/or enterprise inventory sources (e.g., OneTrust, LeanIX, procurement systems, vendor-risk platforms).
    • Experience defining risk tiering methodologies and prioritization queues aligned to capacity and operational realities.
    • Familiarity with contract/security addenda requirements and third-party incident notification language.
    • Project delivery experience in Agile, hybrid, or waterfall environments; comfort with backlog management and delivery planning.

    Salary.com Estimation for Business Analyst (Third-Party Security & Privacy Risk Management) in Waltham, MA
    $111,561 to $136,474
    If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Business Analyst (Third-Party Security & Privacy Risk Management)?

    Sign up to receive alerts about other jobs on the Business Analyst (Third-Party Security & Privacy Risk Management) career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $79,521 - $98,503
    Income Estimation: 
    $101,242 - $124,726
    Income Estimation: 
    $107,442 - $160,602
    Income Estimation: 
    $110,400 - $142,096
    Income Estimation: 
    $118,913 - $150,937
    Income Estimation: 
    $98,772 - $126,519
    Income Estimation: 
    $124,737 - $157,493
    Income Estimation: 
    $132,928 - $192,066
    Employees: Get a Salary Increase
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at Talent Groups

    • Talent Groups Orange, CT
    • Key Responsibilities: Lead end-to-end ADM program delivery across multiple technologies Manage scope, delivery milestones, risks, budgets, and governance D... more
    • 1 Day Ago

    • Talent Groups Redmond, WA
    • Key Responsibilities Design and develop embedded software in Rust, C, C Write device drivers and system software to interact with micro-controllers Partici... more
    • 1 Day Ago

    • Talent Groups Hoboken, NJ
    • We are seeking a skilled Infrastructure Operations Support Engineer with strong experience supporting T24/Core Banking platforms in enterprise banking envi... more
    • 1 Day Ago

    • Talent Groups Boston, MA
    • 🔹 Key Responsibilities: • Manage onboarding workflows, background checks, CORI processing, I-9/E-Verify compliance, and occupational health requirements •... more
    • 1 Day Ago


    Not the job you're looking for? Here are some other Business Analyst (Third-Party Security & Privacy Risk Management) jobs in the Waltham, MA area that may be a better fit.

    • Catalyst Business Brokers Boston, MA
    • The ideal candidate is a team player who will be responsible for working with company data in various business areas. Specific responsibilities include rep... more
    • 2 Months Ago

    • myGwork - LGBTQ Business Community Cambridge, MA
    • This job is with Biogen, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ business community. Please do not contac... more
    • 10 Days Ago

    AI Assistant is available now!

    Feel free to start your new journey!