Skip to main content
Back to jobs

Senior Security Risk Management Analyst

External
Rubrik logoRubrik · Cork, Ireland
Full-timeOn-site2w ago
ComplianceDocumentationExcelInformation SecurityJiraLeadership
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

The Information Security organization advances the overall state of security at Rubrik through critical initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at Rubrik to develop secure software and protect data and systems with appropriate security controls. Information Security also develops systems to monitor and respond to attacks against our assets, provides awareness education to teams on security best practices for data protection, and ensures data governance and data sharing relationships with third parties in order to securely protect Rubrik information. Join Us in Securing and Accelerating the World's AI Transformation Rubrik (RBRK), the Security and AI Operations Company, leads at the intersection of data protection, cyber resilience, and enterprise AI acceleration. Rubrik Security Cloud delivers complete cyber resilience by securing, monitoring, and recovering data, identities, and workloads across clouds. Rubrik Agent Cloud accelerates trusted AI agent

Responsibilities

  • Lead and conduct comprehensive risk assessments of new and existing third-party vendors and service providers, focusing on cybersecurity, and regulatory compliance.
  • Evaluate third-party security questionnaires, audit reports (e.g., SOC 2, ISO 27001), and risk documentation.
  • Coordinate with vendors to request and verify security controls, remediation plans, and ongoing compliance.
  • Oversee facilitation of risk remediation efforts agreed upon with suppliers, ensuring timely resolution.
  • Collaborate during supplier contract development, reviewing deviations from security requirements and offering subject matter expertise on risk remediation.
  • Classify vendors according to risk tiers and maintain a comprehensive database of vendor risk profiles.
  • Participate in continuous security monitoring of existing suppliers to track changing risk profiles.
  • Partner with Procurement, Legal, Privacy, and InfoSec teams to improve supplier security management processes.
  • Identify opportunities to automate parts of the assessment process, thereby reducing manual work and enhancing efficiency.
  • Keep abreast of emerging risks, industry standards, and regulatory requirements affecting third-party vendors.
  • Manage and mentor contractors and junior team members, fostering professional growth and maintaining a collaborative team environment.

Requirements

  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, Risk Management, or a related field.
  • 6-8 years of professional experience in third-party risk assessment within cybersecurity or information risk management.
  • Understanding of relevant information security frameworks, including related regulatory compliance requirements, such as ISO 27001/2 (including ISO 27017 & 18), FedRAMP, SOC 2 Trust Services Criteria, PCI DSS, NIST CSF.
  • Solid understanding of risk assessment methodologies and best practices.
  • Ability to synthesize and communicate complex risk findings to both technical and non-technical audiences.
  • Detail-oriented, process-driven, and capable of managing multiple vendor assessments concurrently.
  • Experience with tools such as Coupa, OneTrust, JIRA and Coverbase is a plus.
  • Professional certifications in Information Security or Risk Management (e.g. CISA, CISM, CISSP, CRISC) is a plus.
  • Company Description

Additional Information

Job Title: Senior Security Risk Management Analyst (Third-Party/ Vendor Risk Assessment) Location: Ireland or United Kingdom Position Type : Full-time Rubrik is seeking an experienced professional to join our Third-Party/ Vendor Risk Assessment team. This team focuses on analyzing and managing risks associated with our vendors, service providers, and other third parties, ensuring our organization upholds the highest standards of compliance, security, and business resilience. While your primary responsibility will be Third-Party Risk Management, you will also collaborate on other cybersecurity risk management initiatives. Building strong cross-functional relationships across the company is a key component of this role. To excel, you must showcase exceptional leadership, communication, and decision-making skills, and have a proven track record in managing third-party risk, vendor governance, or related domains.


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at Rubrik? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect