Momentive Software Logo

Momentive Software

Senior Third-Party Risk Management Analyst

Posted Yesterday
Remote
Hiring Remotely in US
Senior level
Remote
Hiring Remotely in US
Senior level
Maintains and matures the enterprise third-party risk management program. The role evaluates vendor cybersecurity, privacy, resiliency, and regulatory controls; maps findings to frameworks; manages remediation and documentation; supports SOC 2 and PCI DSS audits; and oversees vendor dependencies, exceptions, and notifications. It partners with cybersecurity, legal, procurement, product, auditors, and clients to communicate risk, support compliance, improve resiliency, and strengthen governance processes.
The summary above was generated by AI
Job Description

POSITION OVERVIEW

The Third-Party Risk Management (TPRM)Analyst serves as a core member of Momentive Software's Cybersecurity, Risk & Compliance organization. This role is responsible for maintaining and maturing Momentive's enterprise-wide third-party risk program, ensuring that all vendors, platforms, and service providers meet the Firm's cybersecurity, privacy, resiliency, and regulatory requirements.

The Analyst partners closely with Client Success, Cybersecurity Engineering, TVM, Legal, Procurement, Product, and the CISO to evaluate vendor risk, maintain continuous oversight of third-party controls, and support Momentive's compliance obligations — including SOC 2 Type II and PCI DSS. The role also supports TVM notifications to clients who manage their own cybersecurity posture, ensuring clear, accurate, and timely communication of vulnerabilities and remediation expectations.

This position requires strong analytical capability, deep familiarity with cybersecurity frameworks, and the ability to translate complex risk issues into actionable guidance for business and technical stakeholders.

KEY RESPONSIBILITIES

Third-Party Risk Management Program

  • Maintain Momentive's global inventory of third-party providers, applications, and services from onboarding through termination.
  • Lead vendor cybersecurity assessments, coordinating with Cybersecurity Engineering, Legal, and business owners to evaluate risk and required controls.
  • Assess vendor maturity using NIST CSF, CIS, CMMC, GDPR, PCI DSS, SOC 2, and other frameworks.
  • Oversee vendor SLAs, RPO/RTO commitments, breach notification requirements, and cybersecurity insurance documentation.
  • Ensure thorough documentation of findings, recommendations, and remediation plans for all vendor assessments.
  • Serve as a liaison to internal and external auditors for vendor-related controls and evidence collection.

Support for PCI DSS & SOC 2 Type II Audits

  • Provide evidence, documentation, and control validation related to third-party dependencies for Momentive's SOC 2 Type II and PCI DSS assessments.
  • Ensure vendor controls align with Momentive's ISMS, contractual obligations, and certification requirements.
  • Partner with the GRC team to maintain audit-ready documentation, including policies, standards, procedures, and risk treatment plans.
  • Track vendor exceptions and compensating controls, ensuring audit defensibility and continuous improvement.

TVM Notifications & Client Support

  • Collaborate with the Threat & Vulnerability Management (TVM) team to support vulnerability notifications to clients who manage their own cybersecurity controls.
  • Ensure communications are accurate, timely, and aligned with Momentive's contractual commitments and industry best practices.
  • Provide consultative guidance to clients regarding risk impact, remediation expectations, and recommended cybersecurity practices.
  • Maintain documentation and metrics related to client notifications, follow-up actions, and closure.

Governance, Risk & Compliance Integration

  • Contribute to the continual improvement of Momentive's ISMS by aligning vendor risk processes with Firm policies, standards, and procedures.
  • Provide input on control selection, risk treatment plans, and metrics used to monitor the effectiveness of Momentive's cybersecurity controls.
  • Maintain situational awareness of emerging threats, regulatory changes, and industry trends affecting third-party risk.
  • Support DR/BCP planning as it relates to vendor dependencies and resiliency requirements.

Stakeholder Engagement & Leadership

  • Act as a key point of contact when business units identify vendor-related risk; coordinate with Legal, Cybersecurity, and leadership on risk reduction strategies.
  • Promote a positive, enterprise-wide cybersecurity culture through outreach, training, and awareness activities.
  • Provide exemplary service to internal and external stakeholders, demonstrating professionalism, empathy, and expertise.
  • Mentor team members and contribute to the development of internal training materials and documentation.

SKILLS & EXPERIENCE

Required

  • 5+ years of experience in cybersecurity, risk management, audit, or compliance.
  • Deep understanding of regulatory requirements including PCI DSS, SOC 2, GDPR, GLBA, HIPAA, SOX, and HITRUST.
  • Experience evaluating both legacy and modern cloud technologies (AWS, GCP, Azure).
  • Strong knowledge of APIs, application cybersecurity, encryption, endpoint, and network cybersecurity concepts.
  • Familiarity with SIEM, IDS, log management, vulnerability management, and threat intelligence.
  • Ability to assess vendor controls, map them to frameworks, and articulate risk to non-technical stakeholders.
  • Strong project management, multitasking, and organizational skills.
  • Excellent written and verbal communication skills.

Preferred

  • Experience supporting SOC 2 Type II and PCI DSS audits.
  • Experience with EGRC/ITGRC platforms (e.g., Jira Service Manager GRC, Archer, OneTrust, LogicGate).
  • Certifications such as CISSP, CISM, CISA, CRISC, CTPRA, or CTPRP.
About Us

Momentive Software amplifies the impact of over 20,000 purpose-driven organizations in over 30 countries, with over $11 billion raised and 55 million members served to date. Mission-driven nonprofits and associations rely on Momentive’s cloud-based software and services to address their most pressing challenges – from engaging their communities to simplifying operations and growing revenue. Designed to help organizations connect more, manage more, and ultimately expect more, Momentive's solutions are built with reliability at the core and strategically focus on fundraising, learning, events, careers, volunteering, accounting, and association management. Momentive partners with organizations that believe "good enough" is never enough – so they can bring on better outcomes for everyone they serve. Learn more at momentivesoftware.com.
 

Why Work Here?

At Momentive Software, we’re a team of passionate problem-solvers, innovators, and volunteers who believe in using technology to make a real difference. We dream big, support each other, and take pride in creating solutions that help our customers drive meaningful change. If you’re looking for a place where your work matters and your ideas are valued, you’ll find it here.

Medical, Dental & Vision Benefits

401(k) Savings Plan with Company Match

Flexible Planned Paid Time Off

Generous Sick Leave

Inclusive & Welcoming Environment

Purpose-Driven Culture

Work-Life Balance

Commitment to Community Involvement

Employer-Paid Parental Leave

Employer-Paid Short-Term Disability

Remote Work Flexibility
Momentive Software actively embraces diversity and equal opportunity in a meaningful way. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be, which is why we do not discriminate based on race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.
All persons hired will be required to verify identity, minimum age of 18, eligibility to work in the United States (without sponsorship), and to complete the required employment eligibility verification form upon hire.

Similar Jobs

22 Minutes Ago
Easy Apply
In-Office or Remote
Easy Apply
68K-68K Annually
Junior
68K-68K Annually
Junior
Information Technology • Security • Cybersecurity
Administer Windows, Linux, virtualized systems, networks, Microsoft 365, identities, endpoints, backups, and security controls. Provide Tier 2 and Tier 3 support, resolve infrastructure issues, manage patching and vulnerabilities, onboard and offboard employees, maintain documentation, track assets and licenses, and automate routine IT tasks. The hybrid role requires on-site work in Maryland several days per week.
Top Skills: Active DirectoryAWSAzureBackup SolutionsBashDhcpDnsExchange OnlineFirewallsGroup PolicyHyper-VIntuneItilLinuxMicrosoft 365Microsoft Entra IdMicrosoft TeamsNistPowershellPythonSharepointSoc 2Tcp/IpVMwareVpnWindows Server
26 Minutes Ago
Remote or Hybrid
153K-261K Annually
Expert/Leader
153K-261K Annually
Expert/Leader
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Leads business development and strategic growth for the Adaptive Communications and Sensing product line. Develops market opportunities, customer relationships, competitive pursuits, partnerships, investment priorities, and go-to-market strategies across domestic and international defense markets. Engages DoD, Army Aviation, industry, and research stakeholders; guides capture campaigns, customer requirements, business cases, and technology development plans. Requires expertise in tactical communications, defense acquisition, C4ISR, COMSEC, and military sales.
Top Skills: Airborne Tactical RadiosBlosC4IsrComsecDirect Commercial Sales (Dcs)Foreign Military Sales (Fms)MuosU/Vhf
27 Minutes Ago
Remote or Hybrid
79K-135K Annually
Senior level
79K-135K Annually
Senior level
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Administer and configure enterprise business applications supporting Legal Operations, Global Trade, Ethics, and Security. Manage workflows, integrations, access controls, certificates, monitoring, releases, upgrades, incident resolution, and change governance. Translate business requirements into secure configurations, maintain operational reliability and compliance, document runbooks, and train stakeholders. The role supports Appian, Power Automate, ServiceNow, CLM, ERP, and export management integrations in a remote environment.
Top Skills: Active DirectoryAgile ScrumAppianClm SystemsCmmcDnsErp SystemsExport Management SystemsMicrosoft Power AutomateNist 800-171PkiSdlcServicenow

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account