
Security Analyst II – Third Party Risk Management
Há 2 dias
About the Company:
At Playlist, life's richest moments happen when people step away from screens to move, connect, explore, and play. We're building the definitive platform for intentional living, connecting people with inspiring experiences in fitness, wellness, and beyond. With popular brands like Mindbody and ClassPass, Playlist empowers businesses and individuals, making it effortless for aspirations to become actions. Join us in reshaping technology's role to foster meaningful, real-world connections.
Who we are
We are a dedicated team of security and information technology professionals focused on evolving Playlist's security posture. Our collective goal is to protect the future, fostering increased opportunities for wellness businesses worldwide to empower their customers in leading secure and healthy lives. Committed to a higher purpose, we continuously challenge ourselves and our organization to excel, understanding the strength derived from collaborative efforts towards a common objective. We are advocates for a diverse workplace, fostering an environment where individuals can bring their authentic selves to contribute to our shared success. At the heart of our achievements lies the belief in the value of our people. If you share our passion and vision, consider joining our team, and let's explore the remarkable feats we can achieve together
Your role
The Security Risk Analyst II will serve as trusted advisor for Playlist's business stakeholders. This role is part of the Governance, Risk and Compliance team which is responsible for managing risks across the organization. You will be responsible for identifying, assessing, and mitigating risks related to third-party relationships and services. The role requires an organized, action-oriented team player with the ability to prioritize daily work and support multiple initiatives simultaneously; strong communication and customer focus is required. This role also works closely with internal business customers to ensure existing and potential customers are provided accurate security posture information through timely questionnaire responses and content provided in our customer trust center.
You will:
- Manage third party risk management queues to include onboarding, periodic assessments, offboarding and due diligence requests to ensure appropriate actions are taken to engage or disengage third parties.
- Perform periodic security risk assessments and monitor the security posture of our existing third-party vendors.
- Implement enhancements to the TPRM Program, including recommendations on process, automation, and tools used for the TPRM Program's processes, policies, standards, procedures, and tooling.
- Assign risk rankings of vendor and customer relationships by analyzing due diligence questionnaire responses and documentation.
- Partners with Procurement and Legal departments during contractual negotiations to provide consultation on security and privacy clauses included in third party agreements.
- Collaborates with our BISOs to advise Business Partners on the appropriate implementation of cyber security, procurement and legal controls for new third-party services, leveraging a combination of these controls and the Third Party's security and privacy programs to maintain our information security and privacy posture.
- Prepare security risk reports, dashboards, and operational review metrics (KRIs) or other metrics for continuous improvement and monitoring.
- Maintain the integrity of Playlist's Customer Trust Center documentation and customer security requests.
- Manages any internal and external audit requests related to TPRM activities and other compliance requests as needed.
About the right team member
- Self-starter with the desire to ramp up quickly, collaborate, execute and propose alternative or creative solutions when necessary.
- Excellent time management, critical thinking, analytical and communication skills.
- Strong interpersonal skills, capable of interacting at all levels of the organization and with vendors.
- The ability to multitask and complete assignments within deadlines that may have short lead times.
- Strong collaboration skills
- Detail-oriented, deadline-driven, self-directed and organized.
- Resourceful and can work well independently.
You'll thrive in this role with experience in:
- 3-4 years of professional work experience in third party risk, enterprise risk, cyber security governance and/or related functions (such as IT Risk Management and IT Audit).
- Demonstrate leadership skills, excellent interpersonal skills, and proven problem-solving ability.
- Strong knowledge of industry best practices for third party risk management.
- Relevant industry certifications (e.g. CISSP, CISM, CRISC, CISA).
- Ability to provide excellent customer service to internal customers
Have we piqued your curiosity?
Sound like the role for you? We'd love to hear from you Even if you're not 100% sure about potential fit, we still encourage you to apply. We're looking for the right person, not the perfect series of checkboxes.
Playlist is an Equal Opportunity Employer. We highly value diversity at our company and encourage people of all different backgrounds, experiences, abilities and perspectives to apply. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or other protected characteristics.
By entering your email and phone number and submitting your application, you consent to receive emails, calls and SMS about your application and other roles at Mindbody, including by auto-dialer. Message and data rates may apply. Opt-out or text STOP to cancel at any time. If you are a California resident or reside outside the United States then by submitting your application you confirm that you have read, understood, agree and - where applicable - grant your prior, free, informed and express consent for the processing of your personal information, including sensitive personal information, as described in our California Applicant Privacy Notice or International Applicant Privacy Notice (as applicable).
Note: This description outlines key responsibilities but isn't intended to cover every task or duty. Additional responsibilities may be assigned as needed to support the team and business goals.
-
Director, Information Security Risk Management
4 semanas atrás
São Paulo, São Paulo, Brasil IQVIA Tempo inteiro**Job Overview**- Leading risk-related projects- Maintaining ongoing testing and development of Information Security Risk Management framework, liaising with senior stakeholders and providing regular updates to stakeholders.- Producing risk reports when required- Working closely with other senior leaders within the team regarding training and guidance to...
-
Risk and Compliance Analyst
4 semanas atrás
São Paulo, São Paulo, Brasil Johnson & Johnson Tempo inteiroAt Johnson & Johnson, the largest healthcare company in the world, we come together for one purpose: to transform the history of health in humanity.Diversity & Inclusion are essential to continue building our history of pioneering and innovation, which has been impacting the health of more than 1 billion patients and consumers every day for more than 130...
-
Information Security Analyst Ii
4 semanas atrás
São Paulo, São Paulo, Brasil Sovos Compliance Tempo inteiro**The Work You'll Do**The Sovos Information Security Analyst II is tasked with security systems administration and implementation and the investigations and review of system alerts, logs, and reports. This member of the Information Security Team will also assist with the architectural design, planning, and implementation of enterprise operational defenses...
-
Information Security Risk Management Lead
4 semanas atrás
São Paulo, São Paulo, Brasil Bitso Tempo inteiroAs an Information Security Lead, you will be a key player in the planning, design, implementation, operation and maintenance of the organization's Information Security Risk Management program, guaranteeing that it complies with the legal and regulatory requirements, as well as implementing and promoting the adoption of security and risk standards such as...
-
Credit Risk Management Senior Analyst
4 semanas atrás
São Paulo, São Paulo, Brasil Mastercard Tempo inteiro**Our Purpose**- Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation,...
-
Business Security Management
4 semanas atrás
São Paulo, São Paulo, Brasil Santander Tempo inteiroBusiness Security ManagementSAO PAULO, Brazil**WHAT YOU WILL BE DOING**Descrição do cargoThe Business Security Management function is implemented by a distributed team that collaborates closely with business lines to ensure security is appropriately considered as part of all business activities - internal and key suppliers. Business Security Managers embed...
-
AI Risk Management Lead
2 semanas atrás
São Paulo, São Paulo, Brasil Nubank Tempo inteiro R$120.000 - R$150.000 por anoAbout NubankNubank is one of the largest digital financial services platforms in the world, empowering millions of customers across Latin America to take control of their financial lives. We're driven by an "AI-First" vision, leveraging cutting-edge technology to redefine financial services and deliver exceptional experiences. Our commitment to responsible...
-
Security Analyst
4 semanas atrás
São Paulo, São Paulo, Brasil Bunge Iberica SA Tempo inteiroOverview The Security Analyst II serves as Tier 1-2 Analyst member of the Bunge Global SOC and all operational activities that serve to protect the confidentiality, integrity and security management of business and employee information and systems in compliance with organization policies and standards. He/she will focus on structured tasks associated with...
-
Senior Manager, Security Risk Management
4 semanas atrás
São Paulo, São Paulo, Brasil Kroll Tempo inteiroIn a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate...
-
Compliance Analyst
4 semanas atrás
São Paulo, São Paulo, Brasil ACI Worldwide Tempo inteiro**Compliance Analyst - São Paulo, Brazil****Join Us as We Make Possibilities Happen**If you've ever used an ATM, paid a bill through your phone, sent money to a friend or shopped online, chances are your transaction was safeguarded and processed using our software. Now it's your turn to serve the payment needs of organizations and people the world over.As a...