HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    HO

    Hogan Lovells

    Law Firm

    Vendor Security Analyst

    Louisville GBC, United StatesFull-time$120.5k – $146.2k / yearPosted 3w ago
    All Hogan Lovells jobs

    Job description

    Hogan Lovells Cadwalader delivers decisive counsel at the intersection of finance, business, and regulation, helping clients succeed when it matters most. We are a leading global law firm trusted to advise on complex, high stakes matters, combining global scale with local intelligence to help clients move markets, shape industries, define new opportunities, and succeed. With more than 3,100 lawyers worldwide, we bring sharp thinking, deep commercial understanding, and an uncompromising commitment to delivering exceptional outcomes for clients.

    The Vendor Security Analyst performs evaluation of third party and vendor engagements to identify and manage vendor risk which may include completion of risk assessments. They will also conduct the technical security reviews of our suppliers and partners. This role reports to the Head of Information Risk.

    KEY RESPONSIBILITIES

    • Evaluate third party risk and steer vendor relationships
    • Evaluate vendor responses to security questionnaires
    • Make recommendations on ways to mitigate vendor risk
    • Maintain vendor risk repository of artifacts including regular third party vendor certifications and assign risk scores to firm suppliers and partners
    • Conduct onsite audits of high risk vendors reviewing security and controls
    • Actively support and engage in the firm's Responsible Business initiatives, contributing to our commitments to our people, clients, communities, and the environment.
    • Provide support on emerging priorities and undertake additional responsibilities as needed to meet evolving business requirements.

    QUALIFICATIONS

    EDUCATION & EXPERIENCE

    • Strong and demonstration information security risk identification (including Cloud services), assessment, and risk ranking experience
    • Working experience with the following documents used in a risk assessment preferred:
    • SIG (Standardized Information Gathering) questionnaire
    • Penetration test
    • Vulnerability test
    • SOC (Service Organization Control) 1 and 2, Type 2
    • ISO 27001
    • Bachelor's degree preferred.

    SKILLS & ABILITIES

    • Possess a sufficient understanding of technical concepts including systems, networks, and security architecture best practices in order to effectively evaluate risk and assess the effectiveness of controls
    • Confident to make independent decisions
    • Ability to explain technical concepts in layman terms
    • Ability to interact effectively and influence external vendors
    • Keen attention to detail and accuracy in order to analyze documents
    • Broad knowledge of risk management, vulnerability management, and third party risk

    WORK SCHEDULES/HOURS EXPECTATION

    Core hours are generally Monday through Friday, 9:00 a.m. to 5:30 p.m., including an unpaid meal period. This position is based on a standard 37.5-hour workweek. Additional or adjusted hours may be required to meet business needs and must be worked in accordance with applicable overtime requirements and firm policies.

    In Washington, D.C., the expected base salary range for this role is $120,500 to $146,200 per year.

    This range reflects a good-faith estimate of pay at the time of posting; the actual compensation offered may vary depending on factors such as the candidate’s qualifications. This position is eligible for additional forms of compensation, which may include annual discretionary bonuses.  Employees in this role are also eligible for benefits offered by the firm, subject to applicable plan terms and conditions, which currently include medical, dental, and vision insurance; a 401(k)-retirement plan; and paid time off. Please review this link for more information regarding employee benefits in the United States.

    This job description sets forth the responsibilities of this position and may be changed from time to time as shall be determined.

    Hogan Lovells Cadwalader is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, age, national origin, disability, sexual orientation, gender identity or expression, marital status, genetic information, protected Veteran status, or other factors protected by law.

    Hogan Lovells Cadwalader complies with federal and state disability laws and makes reasonable accommodations for applicants and candidates with disabilities. If reasonable accommodation is needed to participate in the job application or interview process, please contact our Benefits Department at [email protected].

    Job details are sourced from the employer's original posting.

    Open job posting
    HO

    About the company

    Hogan Lovells

    Hogan Lovells is a leading international law firm with over 3,000 legal professionals and 48 locations worldwide. As a global full-service firm, they advise companies in all areas of commercial law.

    View all Hogan Lovells jobs
    Industry
    Law Firm
    Open roles
    220

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.