U. S. Bank

Financial Services

InformationSecurityThird-PartyRiskAnalyst

$98–116k Cincinnati, Ohio, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid candidates.

The Brief

“Information Security Third-Party Risk Analyst at U. S. Bank. Skills: Information Security, Third-party risk, Vendor security, Risk assessment. Perform information security risk assessments. Review and analyze vendor security questionnaires”

Industry & Context.

Financial Services
Eligibility Requirements

This position is not eligible for visa sponsorship., Requires working from a U. S. Bank location three (3) or more days per week.

What They're Looking For.

Must Have

5+ years of experience in information security, 5+ years of experience in third-party risk management, vendor risk, or risk analysis, Hands-on experience conducting third-party/vendor information security risk assessments, understanding of information security controls and risk concepts, Experience identifying control gaps and evaluating remediation actions, Experience with contract review or redlining related to security requirements, Ability to clearly communicate risk to both technical and non-technical stakeholders

Nice to Have

Familiarity with security frameworks (e.g., NIST 800-53), Experience reviewing SOC 2 Type II reports, Experience with continuous monitoring tools (e.g., BitSight, Archer), Exposure to third-party security incident response and post-event analysis, Broader technical cybersecurity background, Exposure to emerging risks (e.g., AI, new technologies)

What You'll Do.

Perform information security risk assessments

Review and analyze vendor security questionnaires

Identify security gaps

Document and track risk findings

Evaluate vendor remediation plans

Partner with business stakeholders

Support contract review

Conduct continuous monitoring

Review and assess third-party security incidents

Contribute to reporting

Support audit activities

How You'll Work.

Team & Collaboration

Partner with business stakeholders and external vendors; Collaborate across information security, risk, and compliance teams

Communication Scope

Clearly communicate risk to both technical and non-technical stakeholders

Full Job Description

At U.S. Bank, we’re on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at—all from Day One. ## **_Job Description_** ## __This position is not eligible for visa sponsorship.__ **Location expectations:** This role requires working from a U.S. Bank location three (3) or more days per week. US Bank is seeking an Information Security Third-Party Risk Analyst to join our Information Security organization, supporting third-party risk management and vendor security oversight. This role is responsible for evaluating and managing information security risk across external vendors, ensuring appropriate controls are in place, and driving remediation of identified risks. This person will perform hands-on third-party security risk assessments, analyze vendor controls and security posture, and partner with internal stakeholders and external vendors to reduce risk exposure. They will play a key role in identifying control gaps, tracking remediation, supporting contract security reviews, and contributing to ongoing risk monitoring, reporting, and audit activities. ### **Responsibilities:** * Perform information security risk assessments on third-party vendors (new and existing) * Review and analyze vendor security questionnaires, control responses, and supporting documentation * Identify security gaps, control deficiencies, and non-compliance issues * Document and track risk findings and remediation efforts through resolution * Evaluate vendor remediation plans and compensating controls * Partner with business stakeholders and third parties

Free ATS check

Applying for this Information Security Third-Party Risk Analyst role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Workday

  • Workday has a multi-step form — save your progress after every section.
  • "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
  • Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
  • Job requisition numbers are useful when following up with HR by email.

ANONYMOUS · UNFILTERED

What do employees actually say about U. S. Bank?

Real rants from real employees. Read before you apply.

Read Company Rants →