Our client, one of the world's leading investment management companies, is actively looking for a Cybersecurity Contract Review Analyst to join their Global Risk & Security (GR&S) group in Malvern, PA! This role is onsite hybrid 3x a week so local candidates are required.
***This is a 6 month contract with the opportunity to extend and/or convert based on performance***
The company's Global Risk & Security (GR&S) group enables business strategy, protects client and company interests (e.g. assets and data) and stewards a strong risk culture. This person would be a part of an Enterprise Security & Fraud (ES&F) division that is responsible for the global protection of internal employees, property, data, and client assets.
In this role you will:
- Review supplier redlines and comments submitted in response to internal cybersecurity contractual terms and recommend next steps to the Office of General Counsel (OGC) and Third-Party Security Management (TPSM) (e.g., accept the change, propose alternative wording, or reject the change).
- Assess whether supplier-proposed changes weaken the company's security posture, categorizing edits (e.g., control deleted, standard weakened, scope narrowed, clarification needed, or immaterial/favorable) and articulating the associated risk.
- Support the cybersecurity clause refresh by helping group current terms by domain, coordinating with ES&F GRC subject-matter-expert (SME) owners, consolidating their feedback, and drafting updated clause language.
- Design, document, and stand up a formalized annual security term review process. This includes defining the workflow, roles, timelines, and governance, and execute the inaugural cycle end-to-end, establishing it as a repeatable, sustainable program owned within TPSM.
- Partner with OGC and Enterprise Sourcing Management (ESM) to move critical-supplier agreements through the standard negotiation process, sequencing work based on supplier risk prioritization.
- Maintain accurate trackers and status reporting on contract review volume, disposition, and throughput to support program metrics and executive updates.
- Ensure work products are audit-ready, well-documented, and aligned to internal security requirements and industry frameworks (e.g., NIST SP 800-53, ISO 27001).
- Required Skills & Experience
- Undergraduate degree or equivalent combination of training and experience.
- Minimum of 3 years of direct Third-Party Security, IT Security, Cyber Security, and/or contract/security clause review experience.
- Demonstrated experience reviewing security or contractual terms and assessing risk associated with proposed changes; familiarity with contract redline review is strongly preferred.
- Working knowledge of common security control frameworks and standards (e.g., NIST SP 800-53, ISO 27001, PCI DSS, SIG/Shared Assessments).
- Demonstrated experience developing and owning a policy, program, or process from the ground up. This includes designing the workflow, documenting procedures, and driving it through its first execution cycle to support the creation and stand-up of the annual security term review process.
- At least one professional security certification is preferred, such as ISC2 CISSP, GIAC Security Essentials Certification (GSEC), or Certified Information Systems Auditor (CISA).
Mention you found this on Data First Jobs — it helps us bring you more roles like this.
Cybersecurity Contract Review Analyst
Motion Recruitment
Similar Analytics Jobs
View all Analytics jobs→C.A. Fortune
Category Analyst
Selene
Business Analyst
goPro Consultancy Group ltd.
Salesforce Support Analyst - Full Remote
Municipal Property Assessment Corporation
Property Valuation Analyst
Core Specialty Insurance Holdings, Inc.
State Filing & Compliance Analyst
Johnston & Associates
Data Analyst
Like this role? Get carefully selected jobs like it, twice a week, straight to your inbox.
Free, no spam. Unsubscribe anytime.