Momentive Software Logo

Momentive Software

Senior Third-Party Risk Management Analyst

Posted Yesterday
Remote
Hiring Remotely in US
Senior level
Remote
Hiring Remotely in US
Senior level
Maintains and matures the enterprise third-party risk management program. The role evaluates vendor cybersecurity, privacy, resiliency, and regulatory controls; maps findings to frameworks; manages remediation and documentation; supports SOC 2 and PCI DSS audits; and oversees vendor dependencies, exceptions, and notifications. It partners with cybersecurity, legal, procurement, product, auditors, and clients to communicate risk, support compliance, improve resiliency, and strengthen governance processes.
The summary above was generated by AI
Job Description

POSITION OVERVIEW

The Third-Party Risk Management (TPRM)Analyst serves as a core member of Momentive Software's Cybersecurity, Risk & Compliance organization. This role is responsible for maintaining and maturing Momentive's enterprise-wide third-party risk program, ensuring that all vendors, platforms, and service providers meet the Firm's cybersecurity, privacy, resiliency, and regulatory requirements.

The Analyst partners closely with Client Success, Cybersecurity Engineering, TVM, Legal, Procurement, Product, and the CISO to evaluate vendor risk, maintain continuous oversight of third-party controls, and support Momentive's compliance obligations — including SOC 2 Type II and PCI DSS. The role also supports TVM notifications to clients who manage their own cybersecurity posture, ensuring clear, accurate, and timely communication of vulnerabilities and remediation expectations.

This position requires strong analytical capability, deep familiarity with cybersecurity frameworks, and the ability to translate complex risk issues into actionable guidance for business and technical stakeholders.

KEY RESPONSIBILITIES

Third-Party Risk Management Program

  • Maintain Momentive's global inventory of third-party providers, applications, and services from onboarding through termination.
  • Lead vendor cybersecurity assessments, coordinating with Cybersecurity Engineering, Legal, and business owners to evaluate risk and required controls.
  • Assess vendor maturity using NIST CSF, CIS, CMMC, GDPR, PCI DSS, SOC 2, and other frameworks.
  • Oversee vendor SLAs, RPO/RTO commitments, breach notification requirements, and cybersecurity insurance documentation.
  • Ensure thorough documentation of findings, recommendations, and remediation plans for all vendor assessments.
  • Serve as a liaison to internal and external auditors for vendor-related controls and evidence collection.

Support for PCI DSS & SOC 2 Type II Audits

  • Provide evidence, documentation, and control validation related to third-party dependencies for Momentive's SOC 2 Type II and PCI DSS assessments.
  • Ensure vendor controls align with Momentive's ISMS, contractual obligations, and certification requirements.
  • Partner with the GRC team to maintain audit-ready documentation, including policies, standards, procedures, and risk treatment plans.
  • Track vendor exceptions and compensating controls, ensuring audit defensibility and continuous improvement.

TVM Notifications & Client Support

  • Collaborate with the Threat & Vulnerability Management (TVM) team to support vulnerability notifications to clients who manage their own cybersecurity controls.
  • Ensure communications are accurate, timely, and aligned with Momentive's contractual commitments and industry best practices.
  • Provide consultative guidance to clients regarding risk impact, remediation expectations, and recommended cybersecurity practices.
  • Maintain documentation and metrics related to client notifications, follow-up actions, and closure.

Governance, Risk & Compliance Integration

  • Contribute to the continual improvement of Momentive's ISMS by aligning vendor risk processes with Firm policies, standards, and procedures.
  • Provide input on control selection, risk treatment plans, and metrics used to monitor the effectiveness of Momentive's cybersecurity controls.
  • Maintain situational awareness of emerging threats, regulatory changes, and industry trends affecting third-party risk.
  • Support DR/BCP planning as it relates to vendor dependencies and resiliency requirements.

Stakeholder Engagement & Leadership

  • Act as a key point of contact when business units identify vendor-related risk; coordinate with Legal, Cybersecurity, and leadership on risk reduction strategies.
  • Promote a positive, enterprise-wide cybersecurity culture through outreach, training, and awareness activities.
  • Provide exemplary service to internal and external stakeholders, demonstrating professionalism, empathy, and expertise.
  • Mentor team members and contribute to the development of internal training materials and documentation.

SKILLS & EXPERIENCE

Required

  • 5+ years of experience in cybersecurity, risk management, audit, or compliance.
  • Deep understanding of regulatory requirements including PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST.
  • Experience evaluating both legacy and modern cloud technologies (AWS, GCP, Azure).
  • Strong knowledge of APIs, application cybersecurity, encryption, endpoint, and network cybersecurity concepts.
  • Familiarity with SIEM, IDS, log management, vulnerability management, and threat intelligence.
  • Ability to assess vendor controls, map them to frameworks, and articulate risk to non-technical stakeholders.
  • Strong project management, multitasking, and organizational skills.
  • Excellent written and verbal communication skills.

Preferred

  • Experience supporting SOC 2 Type II and PCI DSS audits.
  • Experience with EGRC/ITGRC platforms (e.g., Jira Service Manager GRC, Archer, OneTrust, LogicGate).
  • Certifications such as CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP.
About Us

Momentive Software amplifies the impact of over 20,000 purpose-driven organizations in over 30 countries, with over $11 billion raised and 55 million members served to date. Mission-driven nonprofits and associations rely on Momentive’s cloud-based software and services to address their most pressing challenges – from engaging their communities to simplifying operations and growing revenue. Designed to help organizations connect more, manage more, and ultimately expect more, Momentive's solutions are built with reliability at the core and strategically focus on fundraising, learning, events, careers, volunteering, accounting, and association management. Momentive partners with organizations that believe "good enough" is never enough – so they can bring on better outcomes for everyone they serve. Learn more at momentivesoftware.com.
 

Why Work Here?

At Momentive Software, we’re a team of passionate problem-solvers, innovators, and volunteers who believe in using technology to make a real difference. We dream big, support each other, and take pride in creating solutions that help our customers drive meaningful change. If you’re looking for a place where your work matters and your ideas are valued, you’ll find it here.

Medical, Dental & Vision Benefits

401(k) Savings Plan with Company Match

Flexible Planned Paid Time Off

Generous Sick Leave

Inclusive & Welcoming Environment

Purpose-Driven Culture

Work-Life Balance

Commitment to Community Involvement

Employer-Paid Parental Leave

Employer-Paid Short-Term Disability

Remote Work Flexibility
Momentive Software actively embraces diversity and equal opportunity in a meaningful way. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be, which is why we do not discriminate based on race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.
All persons hired will be required to verify identity, minimum age of 18, eligibility to work in the United States (without sponsorship), and to complete the required employment eligibility verification form upon hire.

Similar Jobs

12 Minutes Ago
Remote
US
Mid level
Mid level
Artificial Intelligence • HR Tech • Information Technology • Machine Learning • Software • App development • Industrial
Manage a portfolio of logistics, warehousing, fulfillment, and last-mile delivery accounts. Build client relationships, oversee staffing plans and shift fulfillment, resolve escalations, track account health and operational metrics, prepare business reviews, and identify retention, upsell, and expansion opportunities. Partner with Sales and Operations teams to align worker supply with client demand during peak periods and new site launches.
Top Skills: Google SuiteSalesforce
16 Minutes Ago
Remote or Hybrid
2 Locations
176K-242K Annually
Senior level
176K-242K Annually
Senior level
Healthtech • Software • Analytics • Biotech • Pharmaceutical • Manufacturing
Leads a regional IBD specialty sales organization across Wisconsin and Northern Illinois. Develops district business and sales strategies, coaches and develops Specialty Sales Representatives and Account Managers, manages customer and stakeholder relationships, analyzes market and account data, supports marketing initiatives, ensures regulatory compliance, and collaborates with managed markets and national account teams. The role includes recruiting, budgeting, performance management, account planning, and frequent travel to customer sites, meetings, and training.
Top Skills: ExcelMicrosoft PowerpointMicrosoft Word
16 Minutes Ago
In-Office or Remote
US
136K-220K Annually
Senior level
136K-220K Annually
Senior level
Consumer Web • eCommerce • Machine Learning • Software • Sports • Analytics
Build and own scalable data platforms and ingestion pipelines using BigQuery, dbt, and modern ingestion tools. Design batch and CDC workflows, improve reliability and observability, implement governance and access controls, and support analytics and AI agents. Develop Python services and internal tooling, contribute to architecture and lakehouse experiments, collaborate with stakeholders, and mentor engineers. The role requires strong SQL, Python, cloud infrastructure, testing, CI/CD, and AI-assisted development experience.
Top Skills: Ai Coding AgentsAmazon Web ServicesAPIsCdcCi/CdClaude CodeDbtEstuaryGitGoogle BigqueryGoogle Cloud PlatformHevoLakehouseMcpOpen Table FormatsPythonSQL

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account