
IT Risk & Compliance Third Party Engineer
Wilson Sonsini Goodrich & Rosati
- Washington DC
- $105,400-142,600 per year
- Permanent
- Full-time
- Conduct regular audits and assessments of third-party vendors to evaluate compliance with the organization’s policies and regulatory requirements
- As part of the Third-Party Risk Management (TPRM) team, ability to focus on engineering continuous improvement efforts in the Third-Party risk assessment process
- Work with TPRM teams to schedule and execute a variety of activities related to third party risk assessment
- As a Third-Party Risk Engineer, ability to support the implementation of the Third-Party Management Policy, risk remediation and risk scoring
- Review, measure, monitor and report on the state of key risk metrics and compliance gaps across the WSGR
- Evaluate, quantify, and communicate risk across the WSGR internal technical and procedural controls
- Improve risk monitoring and observability through log analysis, dashboard creation, and automated alerts and response
- Track and monitor IT remediation and risk treatment plans
- Assist in implementing and enforcing audit, governance, and risk frameworks across the WSGR
- Perform deep-dive analysis of cybersecurity issues using data from various threat management and provide recommendations and remediation
- Bachelor's Degree required in Computer Science, Information Technology, or related field of study
- ServiceNow certifications required, 3+ years of ServiceNow experience
- 4+ years of relevant experience in risk and compliance or security
- Knowledge of Governance Risk & Compliance (GRC) tools is highly desired
- Knowledge of the NIST Cybersecurity Framework (CSF) and NIST 800-53
- Strong analytical, problem- solving, multitasking and time management skills and ability to follow through on issues to resolution
- Excellent technical writing and verbal communication skills
- Ability to work independently and to carry out assignments to completion within parameters of instructions given, prescribed routines, and standard accepted practices