IT Governance and Compliance Analyst
GSK Solutions Inc
Contract
Chesterfield, VA
Job description
Analyst, TP Risk ManagementRole Overview
The TP Risk Management - Analyst is responsible for performing comprehensive cybersecurity risk assessments of third-party vendors and partners. You will work closely with cybersecurity, risk management, and business stakeholders to evaluate vendor risks, develop remediation strategies, and drive consistency across assessments using ServiceNow GRC.
Key Responsibilities
- Perform cybersecurity Third-Party Risk Assessments (TPRAs) within ServiceNow GRC, ensuring accuracy and completeness.
- Communicate assessment findings and recommendations to Information Security and Risk Management teams.
- Collaborate with stakeholders to design and implement remediation strategies for identified vendor risks.
- Provide consultative guidance to cybersecurity and business teams on third-party risk understanding and mitigation.
- Identify and implement process improvements to enhance efficiency and consistency in TPRA operations.
- Maintain detailed documentation of all assessments, decisions, and outcomes within ServiceNow.
Services and DeliverablesService / DeliverableFrequencyDue DateAcceptance CriteriaConduct cybersecurity risk assessments in ServiceNow GRC for third-party vendors, focusing on their cybersecurity capabilities and data protection practices.Weekly12/31/2025Each assessment meets the mutually agreed criteria defined during the Assessment Definition Phase.Identify and evaluate potential cyber risks associated with third-party vendors, assessing their impact on data security and confidentiality.Weekly12/31/2025Maintain complete and accurate records of consultations, outcomes, and recommendations in ServiceNow.Provide third-party cybersecurity consulting to business units, ensuring awareness of key risks and best practices.Weekly12/31/2025Deliverables meet predefined quality standards; maintain consultation records and recommendations in ServiceNow.Qualifications
- Bachelor's degree in Information Security, Risk Management, or a related field (or equivalent experience).
- 3+ years of experience conducting cybersecurity or third-party risk assessments.
- Hands-on experience with ServiceNow GRC or similar governance, risk, and compliance platforms.
- Strong understanding of cybersecurity frameworks (e.g., NIST, ISO 27001, SOC 2, HIPAA).
- Excellent communication and collaboration skills with cross-functional teams.
- Analytical mindset with attention to detail and continuous improvement focus.
Success Factors
- Ability to synthesize complex vendor information into actionable insights.
- Demonstrated consistency in delivering high-quality, on-time assessments.
- Effective stakeholder engagement and clear communication of risk posture.
- Commitment to continuous improvement and process excellence.
Join Our Team at Atlas
Job Type: Contract
Pay: $60.00 - $65.00 per hour
Expected hours: 40 per week
Experience:
- Cybersecurity: 4 years (Required)
Ability to Commute:
- Raritan, NJ (Required)
Work Location: In person