Information Security Third-Party Risk Analyst

Minneapolis

Saturday, 30 May 2026

This position is not eligible for visa sponsorship. Location expectations:This role requires working from a U.S. Bank location three (3) or more days per week. US Bank is seeking an Information Security Third-Party Risk Analyst to join our Information Security organization, supporting third-party risk management and vendor security oversight. This role is responsible for evaluating and managing information security risk across external vendors, ensuring appropriate controls are in place, and driving remediation of identified risks. This person will perform hands-on third-party security risk assessments, analyze vendor controls and security posture, and partner with internal stakeholders and external vendors to reduce risk exposure. They will play a key role in identifying control gaps, tracking remediation, supporting contract security reviews, and contributing to ongoing risk monitoring, reporting, and audit activities. Responsibilities:Perform information security risk assessments on third-party vendors (new and existing)Review and analyze vendor security questionnaires, control responses, and supporting documentation. Identify security gaps, control deficiencies, and non-compliance issues. Document and track risk findings and remediation efforts through resolution. Evaluate vendor remediation plans and compensating controls. Partner with business stakeholders and third parties to explain risks and recommend mitigation strategies. Support contract review and redlining with a focus on information security requirements. Conduct continuous monitoring of vendor security posture. Review and assess third-party security incidents and perform post-event analysis. Contribute to monthly and quarterly reporting, metrics, and trend analysis. Support audit activities, control testing, and quality assurance efforts. Collaborate across information security, risk, and compliance teams. Must-Have Skills:5 years of experience in information security 5 years of experience in third-party risk management, vendor risk, or risk analysis. Hands-on experience conducting third-party/vendor information security risk assessments. Strong understanding of information security controls and risk concepts. Experience identifying control gaps and evaluating remediation actions. Experience with contract review or redlining related to security requirements. Ability to clearly communicate risk to both technical and non-technical stakeholders. Nice-to-Have Skills:Familiarity with security frameworks (e.g., NIST 800-53)Experience reviewing SOC 2 Type II reports. Experience with continuous monitoring tools (e.g., Bit. Sight, Archer)Exposure to third-party security incident response and post-event analysis. Broader technical cybersecurity background. Exposure to emerging risks (e.g., AI, new technologies)If there’s anything we can do to accommodate a disability during any portion of the application or hiring process, please refer to our disability accommodations for applicants.

apply
 
Loading Similar Jobs...
JOBZ is an independent Job Search Engine. JOBZ is not an agent or representative and is not endorsed, sponsored or affiliated with any employer. JOBZ uses proprietary technology to keep the availability and accuracy of its job listings and their details. All trademarks, service marks, logos, domain names, job descriptions and other company descriptions / details are the property of their respective holder. JOBZ does not have its users apply for a job on the J-O-B-Z.com website. Additionally, JOBZ may provide a list of third-party job listings that may not be affiliated with any employer. Please make sure you understand and agree to the website's Terms & Conditions and Privacy Policies you are applying on as they may differ from ours and are not in our control.