Associate Cybersecurity Risk Analyst
FinThrive
Description
Overview
We are seeking a detail-oriented and collaborative Associate Cybersecurity Risk Analyst to join
our growing security team. In this role, you will jointly push forward FinThrive's Third Party
Security Risk Management (TPRM) program and manage responses to customer security
inquiries. You will work cross-functionally with IT, Engineering, Product, Sales, Procurement,
and Legal to deliver timely, accurate, and defensible diligence on both sides of the security
review.
Responsibilities
• Third Party Security Risk Management
◦ Execute and mature the day-to-day TPRM program, including risk-based vendor
tiering aligned to data sensitivity, criticality, and regulatory obligations.
◦ Perform vendor security assessments using questionnaires and evidence (SIG,
CAIQ, custom) and review assurance artifacts such as SOC 2 Type II, ISO
27001, HITRUST, PCI, and pen test results.
◦ Document findings, drive remediation to closure, and manage time-bounded risk
acceptances and exceptions.
◦ Support continuous monitoring (security ratings, attestation refresh) and secure
vendor offboarding.
◦ Partner with Legal and Procurement to embed security requirements in contracts
(security addendums, DPAs, breach notification, right to audit).
• Customer Security Inquiries
◦ Manage and respond to customer security questionnaires, RFPs, and due
diligence requests.
◦ Maintain a repository of standardized responses and supporting documentation
to enable cross-functional team independence.
◦ Translate complex security concepts into customer-friendly language and
represent FinThrive's security posture to prospects and customers.
• Cross-Functional Collaboration & Tooling
◦ Work closely with IT, Engineering, Product, and Sales to ensure timely, accurate
completion of both vendor and customer reviews.
◦ Implement and manage tools (e.g., Whistic, Vanta, security ratings platforms) to
streamline and automate inquiry and assessment workflows.
◦ Produce metrics and dashboards covering vendor risk posture, remediation
aging, inquiry volume, and SLA performance.
• Product, Infrastructure & Compliance Knowledge
◦ Maintain a strong understanding of FinThrive's products, SaaS architecture, data
flows, and security controls.
◦ Support FinThrive's Audit and Compliance program by aligning activities to
HITRUST, HIPAA, SOC 2, NIST, and ISO 27001 requirements.
Qualifications
• 1-3 years of relevant experience in information security, third party risk management,
GRC, or due diligence response.
• Experience responding to customer security questionnaires and assessing vendor
security posture against frameworks (SOC 2, HIPAA, ISO 27001).
• Working knowledge of security control domains: IAM, vulnerability management,
encryption, logging/monitoring, incident response, and data handling.
• Familiarity with IT infrastructure (servers, firewalls, load balancers, databases), SaaS
architecture, and web applications.
• Strong written and verbal communication skills, with the ability to explain technical
concepts to non-technical audiences.
• Customer-centric mindset with experience collaborating with Sales teams and
customers.
• Proficiency with Microsoft Office (Word, Excel, PowerPoint, Visio).
• Bachelor's degree (IT, Information Security, or Business Administration preferred).
Preferred Skills
• Security+ or similar certification.
• Familiarity with HITRUST, NIST, PCI DSS, and GDPR/CCPA.
• Experience with Trust Center, questionnaire management, and continuous monitoring
platforms (SafeBase, Whistic, Vanta).
• Familiarity with cloud provider assurance models (AWS/Azure/GCP shared
responsibility) and SaaS risk patterns.
**About FinThrive****FinThrive is advancing the healthcare economy.**For the most recent information on FinThrive's vision for healthcare revenue management visit finthrive.com/why-finthrive
Award-winning Culture of Customer-centricity and ReliabilityAt FinThrive we're proud of our agile and committed culture, which makes FinThrive an exceptional place to work. Explore our latest workplace recognitions at https://finthrive.com/careers#culture
Our Perks and BenefitsFinThrive is committed to continually enhancing the colleague experience by actively seeking new perks and benefits.
· Professional development opportunities
· Term life, Accidental & Medical Insurance
· Meal and Transport arrangements
FinThrive's Core Values and Expectations
· Demonstrate integrity and ethics in day-to-day tasks and decision-making, adhere to FinThrive's core values of being Customer-Centric, Agile, Reliable, and Engaged, operate effectively in the FinThrive environment and the environment of the workgroup, maintain a focus on self-development and seek out continuous feedback and learning opportunities
· Support FinThrive's Compliance Program by adhering to policies and procedures about HIPAA, GLBA, FCRA, and other laws applicable to FinThrive's business practices; this includes becoming familiar with FinThrive's Code of Ethics, attending training as required, notifying management or FinThrive's Helpline when there is a compliance concern or incident, HIPAA-compliant handling of patient information, and demonstrable awareness of confidentiality obligations.
FinThrive is an Equal Opportunity Employer and ensures its employment decisions comply with principles embodied in Title VII, the Age Discrimination in Employment Act, the Rehabilitation Act of 1973, the Vietnam Veterans Readjustment Assistance Act of 1974, Executive Order 11246, Revised Order Number 4, and applicable state regulations.
© 2024 FinThrive. All rights reserved. The FinThrive name, products, associated trademarks, and logos are owned by FinThrive or related entities. RV092724TJO
About FinThrive
-
