OnePay · 2 weeks ago
Third Party Risk Analyst
OnePay is an all-in-one financial platform aiming to improve financial accessibility for unbanked and underbanked Americans. As a Third Party Risk Analyst, you will assess vendor risks, ensure compliance with security standards, and collaborate with various teams to mitigate potential threats to the organization.
Financial Services
Responsibilities
Conduct vendor risk reviews and evaluate third-party attestations such as SOC 2, ISO 2700x, and other security certifications
Analyze vendor contracts and identify potential risk clauses or data security implications
Support annual high-risk vendor audits and maintain documentation to meet compliance requirements
Collaborate cross-functionally with Legal, Procurement, Engineering, and Compliance teams to assess risk exposure and mitigation plans
Provide technical insight into vendor integrations, authentication, and infrastructure security controls
Qualification
Required
5–8+ years of experience in information security, vendor risk management, or related technical risk roles
Strong understanding of security frameworks and certifications (SOC 2, ISO 2700x, NIST, etc.)
Familiarity with authentication, disaster recovery, and infrastructure security concepts
Ability to interpret and challenge vendor-provided attestations and control summaries
Comfort reviewing contracts and identifying clauses impacting data handling or access control
Excellent communication and analytical skills, with the ability to ask critical questions and present findings clearly
Drive and proactivity – everyone here is a builder and executor
Company
OnePay
We believe the future of financial services is meeting consumers where they already are — in their daily lives, workplaces, and communities nationwide.
Funding
Current Stage
Late StageRecent News
Payments Dive
2025-03-17
Crunchbase News
2025-01-16
Crunchbase News
2025-01-16
Company data provided by crunchbase