Communitybrands logo

Senior Third-Party Risk Management Analyst

Hiring from
United States
Work type
Remote
Posted
Is this job info correct?
Show job description

Job Description

POSITION OVERVIEW

The Third-Party Risk Management (TPRM)Analyst serves as a core member of Momentive Software's Cybersecurity, Risk & Compliance organization. This role is responsible for maintaining and maturing Momentive's enterprise-wide third-party risk program, ensuring that all vendors, platforms, and service providers meet the Firm's cybersecurity, privacy, resiliency, and regulatory requirements.

The Analyst partners closely with Client Success, Cybersecurity Engineering, TVM, Legal, Procurement, Product, and the CISO to evaluate vendor risk, maintain continuous oversight of third-party controls, and support Momentive's compliance obligations — including SOC 2 Type II and PCI DSS. The role also supports TVM notifications to clients who manage their own cybersecurity posture, ensuring clear, accurate, and timely communication of vulnerabilities and remediation expectations.

This position requires strong analytical capability, deep familiarity with cybersecurity frameworks, and the ability to translate complex risk issues into actionable guidance for business and technical stakeholders.

KEY RESPONSIBILITIES

Third-Party Risk Management Program

  • Maintain Momentive's global inventory of third-party providers, applications, and services from onboarding through termination.
  • Lead vendor cybersecurity assessments, coordinating with Cybersecurity Engineering, Legal, and business owners to evaluate risk and required controls.
  • Assess vendor maturity using NIST CSF, CIS, CMMC, GDPR, PCI DSS, SOC 2, and other frameworks.
  • Oversee vendor SLAs, RPO/RTO commitments, breach notification requirements, and cybersecurity insurance documentation.
  • Ensure thorough documentation of findings, recommendations, and remediation plans for all vendor assessments.
  • Serve as a liaison to internal and external auditors for vendor-related controls and evidence collection.

Support for PCI DSS & SOC 2 Type II Audits

  • Provide evidence, documentation, and control validation related to third-party dependencies for Momentive's SOC 2 Type II and PCI DSS assessments.
  • Ensure vendor controls align with Momentive's ISMS, contractual obligations, and certification requirements.
  • Partner with the GRC team to maintain audit-ready documentation, including policies, standards, procedures, and risk treatment plans.
  • Track vendor exceptions and compensating controls, ensuring audit defensibility and continuous improvement.

TVM Notifications & Client Support

  • Collaborate with the Threat & Vulnerability Management (TVM) team to support vulnerability notifications to clients who manage their own cybersecurity controls.
  • Ensure communications are accurate, timely, and aligned with Momentive's contractual commitments and industry best practices.
  • Provide consultative guidance to clients regarding risk impact, remediation expectations, and recommended cybersecurity practices.
  • Maintain documentation and metrics related to client notifications, follow-up actions, and closure.

Governance, Risk & Compliance Integration

  • Contribute to the continual improvement of Momentive's ISMS by aligning vendor risk processes with Firm policies, standards, and procedures.
  • Provide input on control selection, risk treatment plans, and metrics used to monitor the effectiveness of Momentive's cybersecurity controls.
  • Maintain situational awareness of emerging threats, regulatory changes, and industry trends affecting third-party risk.
  • Support DR/BCP planning as it relates to vendor dependencies and resiliency requirements.

Stakeholder Engagement & Leadership

  • Act as a key point of contact when business units identify vendor-related risk; coordinate with Legal, Cybersecurity, and leadership on risk reduction strategies.
  • Promote a positive, enterprise-wide cybersecurity culture through outreach, training, and awareness activities.
  • Provide exemplary service to internal and external stakeholders, demonstrating professionalism, empathy, and expertise.
  • Mentor team members and contribute to the development of internal training materials and documentation.

SKILLS & EXPERIENCE

Required

  • 5+ years of experience in cybersecurity, risk management, audit, or compliance.
  • Deep understanding of regulatory requirements including PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST.
  • Experience evaluating both legacy and modern cloud technologies (AWS, GCP, Azure).
  • Strong knowledge of APIs, application cybersecurity, encryption, endpoint, and network cybersecurity concepts.
  • Familiarity with SIEM, IDS, log management, vulnerability management, and threat intelligence.
  • Ability to assess vendor controls, map them to frameworks, and articulate risk to non-technical stakeholders.
  • Strong project management, multitasking, and organizational skills.
  • Excellent written and verbal communication skills.

Preferred

  • Experience supporting SOC 2 Type II and PCI DSS audits.
  • Experience with EGRC/ITGRC platforms (e.g., Jira Service Manager GRC, Archer, OneTrust, LogicGate).
  • Certifications such as CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP.

About Us

Momentive Software amplifies the impact of over 20,000 purpose-driven organizations in over 30 countries, with over $11 billion raised and 55 million members served to date. Mission-driven nonprofits and associations rely on Momentive’s cloud-based software and services to address their most pressing challenges – from engaging their communities to simplifying operations and growing revenue. Designed to help organizations connect more, manage more, and ultimately expect more, Momentive's solutions are built with reliability at the core and strategically focus on fundraising, learning, events, careers, volunteering, accounting, and association management. Momentive partners with organizations that believe "good enough" is never enough – so they can bring on better outcomes for everyone they serve. Learn more at momentivesoftware.com.

Why Work Here?

At Momentive Software, we’re a team of passionate problem-solvers, innovators, and volunteers who believe in using technology to make a real difference. We dream big, support each other, and take pride in creating solutions that help our customers drive meaningful change. If you’re looking for a place where your work matters and your ideas are valued, you’ll find it here.

Medical, Dental & Vision Benefits

401(k) Savings Plan with Company Match

Flexible Planned Paid Time Off

Generous Sick Leave

Inclusive & Welcoming Environment

Purpose-Driven Culture

Work-Life Balance

Commitment to Community Involvement

Employer-Paid Parental Leave

Employer-Paid Short-Term Disability

Remote Work Flexibility

Momentive Software actively embraces diversity and equal opportunity in a meaningful way. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be, which is why we do not discriminate based on race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.

All persons hired will be required to verify identity, minimum age of 18, eligibility to work in the United States (without sponsorship), and to complete the required employment eligibility verification form upon hire.

About Us

Momentive Software amplifies the impact of over 20,000 purpose-driven organizations in over 30 countries, with over $11 billion raised and 55 million members served to date. Mission-driven nonprofits and associations rely on Momentive’s cloud-based software and services to address their most pressing challenges – from engaging their communities to simplifying operations and growing revenue. Designed to help organizations connect more, manage more, and ultimately expect more, Momentive's solutions are built with reliability at the core and strategically focus on fundraising, learning, events, careers, volunteering, accounting, and association management. Momentive partners with organizations that believe "good enough" is never enough – so they can bring on better outcomes for everyone they serve. Learn more at momentivesoftware.com.

Similar jobs

Apply for this job