Ampstek · 1 day ago
Third party Risk Analyst (ONLY USC AND GC -W2)
Ampstek is seeking a 3rd Party Risk Analyst to join their Technology Division. This role is crucial for protecting American Airlines’ digital ecosystem by identifying and managing cybersecurity risks, and involves conducting risk assessments and collaborating with various teams to enhance the Third-Party Risk Management program.
Responsibilities
Conduct cybersecurity risk assessments across internal systems and third-party vendors
Support and enhance the Third-Party Risk Management (TPRM) program, including vendor onboarding and continuous monitoring
Analyze cybersecurity risks and provide actionable insights to stakeholders across the organization
Collaborate with teams in IT, Legal, Procurement, and Business Units to ensure risk awareness and mitigation
Maintain risk registers and support the development of risk metrics and dashboards
Assist in the development and implementation of cybersecurity risk policies, standards, and procedures
Qualification
Required
Bachelor's degree in information technology or other related field experience
Experience in audit roles or a related control function - relevant certification or industry accreditation (e.g., CPA, CFA, CIA) encouraged
Working knowledge of ITSM/ITAM, regulatory compliance (SOX, PCI DSS, GDPR/PII and HIPAA) and cybersecurity principles
Strong proficiency in basic PC applications (Excel, Word, PowerPoint) with a general understanding of simple data analysis techniques like VLOOKUP, Pivot Tables etc
Excellent critical thinking and problem-solving skills with the ability to learn both AA and industry standards (NIST 800-171, NIST 800-871)
Strong written and oral communication skills, PC skills, team building skills and the ability to work independently