OnePay · 1 month ago
Third Party Risk Analyst
OnePay is a consumer financial services app dedicated to helping people achieve financial progress. As a Third Party Risk Analyst, you will assess the security posture of high-risk vendors, review security attestations, and ensure compliance with audit and regulatory standards, playing a crucial role in maintaining customer trust and preventing breaches.
Financial Services
Responsibilities
Conduct vendor risk reviews and evaluate third-party attestations such as SOC 2, ISO 2700x, and other security certifications
Analyze vendor contracts and identify potential risk clauses or data security implications
Support annual high-risk vendor audits and maintain documentation to meet compliance requirements
Collaborate cross-functionally with Legal, Procurement, Engineering, and Compliance teams to assess risk exposure and mitigation plans
Provide technical insight into vendor integrations, authentication, and infrastructure security controls
Qualification
Required
5–8+ years of experience in information security, vendor risk management, or related technical risk roles
Strong understanding of security frameworks and certifications (SOC 2, ISO 2700x, NIST, etc.)
Familiarity with authentication, disaster recovery, and infrastructure security concepts
Ability to interpret and challenge vendor-provided attestations and control summaries
Comfort reviewing contracts and identifying clauses impacting data handling or access control
Excellent communication and analytical skills, with the ability to ask critical questions and present findings clearly
Drive and proactivity – everyone here is a builder and executor
Company
OnePay
We believe the future of financial services is meeting consumers where they already are — in their daily lives, workplaces, and communities nationwide.
Funding
Current Stage
Late StageRecent News
Payments Dive
2025-03-17
Crunchbase News
2025-01-16
Crunchbase News
2025-01-16
Company data provided by crunchbase