Cybersecurity Analyst I, II, or III
New American Funding Santa Ana, California, United States · $90K/yr
Financial Services · 5,001-10,000 employees
About the role
The Cybersecurity Analyst identifies, assesses, and monitors third-party cybersecurity risks to ensure the resilience of the vendor ecosystem. They perform security architecture reviews, evaluate AI-related risks, and provide actionable risk-based guidance to internal stakeholders.
What they look for
Requirements
Candidates must have experience performing third-party cybersecurity or technology risk assessments in an enterprise environment. Proficiency in interpreting security documentation and knowledge of cybersecurity frameworks like NIST or ISO is required.
Benefits
Full description
Overview
Position: Cybersecurity Analyst I, II or III (Depending on experience)
Salary: Starting at $90,000/year+ D.O.E
*Actual compensation may vary from posting based on geographic location, work experience, education, and/or skill level.
Location: On-Site Role - Santa Ana, California
Position Summary:
The Cybersecurity Analyst I/II/III supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ecosystem.
The role includes vendor cybersecurity assessments, continuous cyber monitoring, Security Architecture Reviews (SARs), AI risk assessments, emerging third-party threat analysis, remediation support, and development of meaningful risk reporting and metrics.
This role partners with Third-Party Management (TPM), Legal, Privacy, Enterprise Technology, Procurement, and Business Unit stakeholders to provide practical, risk-based cybersecurity guidance and strengthen third-party cyber resilience.
The position may be filled at the I, II, or III level based on the selected candidate's relevant experience, hands-on technical depth, demonstrated judgment, level of accountability, complexity and scale of prior vendor ecosystems, and experience operating in regulated environments. Candidates with more advanced experience are encouraged to apply; title, level, responsibilities, and compensation may be adjusted accordingly.
*Disclaimer: Identity Verification checks are in place throughout the Candidate journey to prevent candidate fraud
Responsibilities
- Level of responsibility will scale with demonstrated capability, hands-on experience, independence, and complexity of prior responsibilities. General differentiation by level includes:• Analyst I - Executes defined vendor cyber risk assessments and monitoring activities with guidance; independently handles lower-to-moderate complexity vendors and escalates significant findings. Demonstrates foundational hands-on TPRM/security assessment experience and accountability for an assigned portfolio or assessment queue.• Analyst II - Independently owns end-to-end assessments for moderate-to-high risk and critical vendors, leads vendor discussions and remediation, performs SAR and AI risk reviews, and makes risk-based recommendations with limited oversight. Demonstrates experience managing larger or more complex vendor populations and working across multiple business and technology stakeholders.
- Analyst III - Leads the most complex, critical, or strategically significant third-party assessments and incidents; provides independent challenge, mentors less-experienced analysts, influences risk decisions, and drives program/process improvements. Demonstrates substantial hands-on experience in large vendor ecosystems and/or highly regulated industries where regulatory, audit, data protection, resiliency, and due-diligence expectations materially increase assessment depth.• Perform cybersecurity risk assessments for new and existing third-party vendors, review security questionnaires, SOC reports, penetration tests, certifications, policies, and other supporting evidence.• Assessing vendor security controls across cloud security, identity and access management, AI, encryption, API security, vulnerability management, logging, incident response, and secure software development practices.• Support or independently lead Security Architecture Reviews (SARs) based on role level and vendor risk. Analyst I supports defined reviews; Analyst II independently leads higher-risk reviews; Analyst III leads complex/critical reviews, challenges control design, and provides senior-level risk recommendations.• Monitor and investigate emerging third-party cyber threats, including critical vulnerabilities, ransomware, software supply chain attacks, and vendor breaches. Increasing seniority requires greater independence in correlating events to NAF's vendor ecosystem, determining business impact, directing mitigation, and briefing senior stakeholders.
- Assess cybersecurity risks associated with vendor use of Artificial Intelligence (AI), including AI governance, model usage, data handling, AI-enabled services, and emerging AI-related threats.• Evaluate fourth-party and Nth-party dependencies for concentration, cascading, and systemic supply chain risk.• Track security findings through remediation and closure. Analyst I coordinates and documents remediation; Analyst II independently challenges vendor responses and validates corrective actions; Analyst III drives resolution of complex/high-risk findings, exceptions, and escalations involving critical vendors or material residual risk.• Support third-party security incident triage and executive reporting. At higher levels, independently lead vendor cyber incident analysis, determine potential exposure and required actions, develop executive-ready risk briefings, and contribute to KPIs/KRIs and cyber risk quantification.• Leverage TPRM, continuous monitoring, and generative AI capabilities to improve assessment efficiency, risk visibility, reporting, automation, and overall TPCRM program maturity.• Partner effectively with TPM, Legal, Privacy, Procurement, Enterprise Technology, Business Units, and other stakeholders to support consistent third-party cyber risk decisions.
Qualifications
- Experience performing third-party cybersecurity, technology risk, vendor risk, or related security assessments in an enterprise environment.• Ability to interpret security documentation such as SOC reports, penetration test reports, vulnerability assessments, security questionnaires, policies, and cloud security documentation.• Working knowledge of cybersecurity frameworks and standards such as NIST CSF, NIST SP 800-53, CIS Critical Security Controls, ISO 27001, and SOC 2.• Experience assessing SaaS, cloud, and/or AI-enabled vendors, with familiarity across Azure, AWS, or GCP environments.• Experience with TPRM, GRC, or continuous monitoring platforms such as Lema.ai, Black Kite, or comparable enterprise risk solutions is preferred.• Strong analytical, written, and verbal communication skills, with the ability to translate technical cybersecurity risk for both technical and non-technical stakeholders.• Demonstrated judgment, ownership, and ability to operate with increasing independence. Level I candidates should demonstrate sound execution and escalation judgment; Level II candidates should independently lead complex assessments and influence remediation decisions; Level III candidates should demonstrate advanced risk judgment, independent challenge, executive communication, mentoring, and ownership of complex or high-impact risk decisions.• Vendor ecosystem scale: Experience should reflect increasing breadth and complexity rather than a fixed vendor count alone. Relevant indicators include the size of the vendor population or assessment portfolio supported, number of concurrent assessments managed, proportion of critical/high-risk vendors, geographic scope, fourth/Nth-party dependencies, and complexity of technology and data integrations.• Regulatory and industry complexity: Experience in financial services, banking, mortgage, insurance, healthcare, government, or similarly regulated environments is valued because these environments generally require deeper due diligence, evidence validation, audit readiness, regulatory awareness, and defensible risk decisions.
- Technical complexity: Seniority may also be demonstrated through hands-on assessment of cloud/SaaS platforms, APIs, IAM/SSO, sensitive or regulated data flows, AI-enabled services, critical infrastructure dependencies, security architecture, software supply chain risk, and complex remediation scenarios.• Accountability and influence: Progression across levels is demonstrated by increasing ownership of risk decisions, independence in vendor challenge, responsibility for remediation and exceptions, ability to manage escalations/incidents, senior stakeholder engagement, mentoring, and contribution to TPCRM process and program maturity.
Education, Experience, and Certifications:
- Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field, or equivalent relevant professional experience.• Experience: Level will be determined by the combination of relevant years of experience and demonstrated scope, technical depth, accountability, independence, and complexity of prior responsibilities. Leveling will also consider the criticality and complexity of vendors managed, volume of concurrent assessments or portfolio responsibility, regulated-industry experience, stakeholder influence, remediation ownership, incident involvement, and contribution to program maturity. The ranges below are guidelines and are not intended to exclude candidates whose demonstrated capability supports a different level.o Analyst I - Generally 1-3 years of relevant experience; developing practitioner who can execute defined assessments and independently manage lower-to-moderate complexity work with appropriate escalation.o Analyst II - Generally 3-5 years of relevant experience; experienced practitioner who independently owns moderate-to-high complexity assessments, remediation, and risk recommendations with limited oversight.o Analyst III - Generally 5+ years or equivalent demonstrated capability; senior practitioner who leads critical/complex assessments and escalations, provides independent challenge, influences senior stakeholders, mentors others, and contributes to TPCRM program maturity.• Certifications: Relevant industry certifications are preferred but not required. Security+ or comparable foundational credentials may support Analyst I qualifications; CISA, CRISC, CTPRP/CTPRA, CCSP, or comparable risk/cloud credentials are particularly relevant for Analyst II; and advanced certifications such as CISSP, CISM, CRISC, or equivalent credentials are strongly valued for Analyst III. Certifications supplement, but do not replace, demonstrated hands-on experience, technical knowledge, judgment, and accountability.
Reporting Line:
- Primary: Reports directly to AVP, BISO – Cyber Third-Party Risk• Secondary: Partners with TPM and the Office of the CISO to align with organizational priorities.
Work Authorization:
Must be able to verify identity and employment eligibility to work in the U.S. This position does not offer visa sponsorship.
Other Duties:
This job profile is not intended to be an all-inclusive list of job duties and responsibilities, as one may perform additional related duties as assigned in order to meet the needs of the organization.
Physical Demands:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. Must be able to lift up to ten pounds. Primary functions require sufficient physical ability and mobility to work in an office setting; to stand or sit for prolonged periods of time; to occasionally stoop, bend, kneel, crouch, reach, and twist; to lift, carry, push, and/or pull light to moderate amounts of weight; to operate office equipment requiring repetitive hand movement and fine coordination including use of a keyboard; and to verbally communicate to exchange information. VISION: See in the normal visual range with or without correction. HEARING: Hear in the normal audio range with or without correction.
Pay Transparency Disclosure: If based in New American Funding’s offices, this role has the annual base salary range stated below.
Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. The listed range is a guideline, and the range for this role may be modified. For roles that are available to be filled remotely, the pay range is localized according to employee work location by a factor of between 80% and 100% of range. Please discuss your specific work location with your recruiter for more information.
New American Funding offers competitive package of additional benefits, including health, dental & vision, retirement with company contribution, parental leave , mental health & wellness benefits, and generous PTO. New American Funding also offers sales incentive pay for most sales roles and an annual bonus plan for eligible non-sales roles. New American Funding’s compensation and benefits are subject to change and may be modified in the future.
[EOE/M/F/D/V. Drug-free workplace.]
#LI-JS3
Similar roles
-
Cybersecurity Administrator
Coastal Ridge Columbus, Ohio, United States
-
Information System Security Engineer
SAIC Colorado Springs, Colorado, United States
-
System Cybersecurity Engineer
Odyssey Systems Consulting Group, Ltd. Colorado Springs, Colorado, United States · $130K–$165K/yr
-
Senior Security Engineer - Ardán Inc
Westcor Land Title Insurance Company® Orange County, Florida, United States
-
CYBERSECURITY EXPERT
Kave Home Sils, Catalonia, Spain
-
Senior Cybersecurity Specialist - GA, On Site
Vensure Employer Solutions Duluth, Georgia, United States