Summary
Lincoln Financial helps people plan for financial security through products and services including annuities, life insurance, group protection, and retirement plan services. The Sr Associate Cybersecurity Risk Analyst - Third Party supports enterprise IT and cybersecurity risk assessment activities, with a focus on evaluating third-party vendors, documenting findings, developing mitigation recommendations, and reporting risk trends and remediation progress.
Responsibilities
- Maintains knowledge of current and emerging information security trends, threats, technologies, regulatory requirements, industry best practices, and AI-related risks applicable to assigned areas of responsibility
- Supports departmental and enterprise initiatives by contributing to change management efforts, team objectives, and continuous improvement activities
- Performs information security risk management activities and delivers on assigned projects while building expertise within assigned areas of responsibility
- Identifies opportunities for process improvements that enhance efficiency, consistency, and quality and communicates recommendations to management
- Conducts information security risk assessments of third-party vendors by reviewing security questionnaires, audit reports, control documentation, and other supporting evidence
- Evaluates assessment results and assists in determining third-party information security risk profiles using established methodologies, company policies, and industry standards
- Develops recommendations to address identified security gaps and collaborates with internal stakeholders and external parties to support risk mitigation and remediation efforts
- Documents assessment activities, findings, recommendations, and communications within approved governance, risk, and compliance platforms
- Responds to requests regarding the organization's information security practices by providing accurate, approved, and professionally written information
- Partners with business stakeholders, risk functions, and other teams across the enterprise to support risk assessment activities, remediation tracking, and risk management efforts
- Collects, maintains, and analyzes assessment and risk management data to support program oversight, reporting, and decision-making
- Assists in the preparation of metrics, dashboards, reports, and presentations that communicate assessment results, risk trends, remediation progress, and program performance to stakeholders and leadership
- Identifies trends, reporting opportunities, and data quality improvements to support continuous improvement efforts and informed decision-making
- Applies critical thinking to analyze and synthesize information from multiple sources, including security questionnaires, audit reports, assessment evidence, policies, standards, and stakeholder discussions, to develop clear findings, recommendations, and reporting
- Communicates effectively through both written and verbal channels, tailoring messages, reports, and presentations to technical, business, and leadership audiences
- Assists in the development, maintenance, and implementation of information security standards, policies, procedures, and related documentation
- Evaluates security considerations associated with third-party AI solutions and provides input based on established policies, standards, and industry best practices
- Demonstrates curiosity and a willingness to learn emerging technologies, including AI, and explores opportunities to improve team processes, reporting, and analysis capabilities
Skills
- 4 Year/Bachelor's degree (or equivalent)
- 1 - 3+ Years of Information Security experience that directly aligns with the specific responsibilities for this position
- Ability to read, analyze and interpret both internal and external documents such as general media/publications, professional journals, technical procedures, governmental regulations, policies, proposals, and standard operating procedures
- Strong written and verbal communication skills
- Demonstrates excellent organizational skills with the ability to prioritize workload and multi-task while maintaining strict attention to detail
- Demonstrates solid project management skills including, critical ability to coordinate and balance multiple projects in a time-sensitive environment, under pressure, and meeting deadlines
- Demonstrates strong interpersonal skills with a collaborative style
- Demonstrates the ability to use sound judgment and discretion regarding confidential information
- Finds common ground and can gain collaboration among management, colleagues and peers; can influence outcomes without directing or commanding
- Proficiency with Microsoft Office Suite (Word, Excel, PowerPoint, Outlook)
- Successfully completes regulatory and job training requirements
- Agile Mindset; awareness/understanding of Agile methodologies (Preferred)
Qualifications
Must Haves
- 4 Year/Bachelor's degree (or equivalent)
- 1 - 3+ Years of Information Security experience that directly aligns with the specific responsibilities for this position
- Ability to read, analyze and interpret both internal and external documents such as general media/publications, professional journals, technical procedures, governmental regulations, policies, proposals, and standard operating procedures
- Strong written and verbal communication skills
- Demonstrates excellent organizational skills with the ability to prioritize workload and multi-task while maintaining strict attention to detail
- Demonstrates solid project management skills including, critical ability to coordinate and balance multiple projects in a time-sensitive environment, under pressure, and meeting deadlines
- Demonstrates strong interpersonal skills with a collaborative style
- Demonstrates the ability to use sound judgment and discretion regarding confidential information
- Finds common ground and can gain collaboration among management, colleagues and peers; can influence outcomes without directing or commanding
- Proficiency with Microsoft Office Suite (Word, Excel, PowerPoint, Outlook)
- Successfully completes regulatory and job training requirements
Nice to Haves
- Agile Mindset; awareness/understanding of Agile methodologies (Preferred)
Benefits
- Clearly defined career tracks and job levels, along with associated behaviors for each of Lincoln's core values and leadership attributes
- Leadership development and virtual training opportunities
- PTO/parental leave
- Competitive 401K and employee benefits
- Free financial counseling, health coaching and employee assistance program
- Tuition assistance program
- Work arrangements that work for you
- Effective productivity/technology tools and training
- The role may be eligible for the Annual Incentive Program, which is discretionary and based on the performance of the company, business unit and individual
- Other rewards may include long-term incentives, sales incentives and Lincoln’s standard benefits package