Senior Cybersecurity Third-Party Risk Analyst

Boeing
Long Beach, US
RemoteCareer-pivot friendly

Why this role

Pace
Steady
The fast-paced nature of this role is evident from the requirement to design and execute end-to-end cybersecurity assessments and maintain automation capabilities, indicating a high demand for timely and accurate risk analysis.
Collaboration
Medium
Collaboration is a key aspect of the role, as evidenced by the need to work closely with various stakeholders including Procurement, Legal, and Security Operations, to ensure that technical findings align with contractual and incident response requirements.
Autonomy
High
As a senior individual contributor, the role demands a high level of autonomy, as seen in the responsibility to independently design and execute assessments and lead lean process improvement initiatives.
Decision Impact
Team
The decision impact is significant, as the role involves producing clear risk findings and remediation guidance, which directly influence vendor risk management and business operations.
Role Level
Individual Contributor
The complexity of the role is high, given the need to design and maintain automated assessment capabilities, develop agentic AI components, and apply lean principles to operational processes.
Career Pivot Friendly
Welcomes transferable skills
Individuals with experience in cybersecurity consulting or similar roles can easily transition into this position, given the emphasis on technical assessment, automation, and process improvement.

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • design & execute end-to-end cybersecurity third-party assessments
  • produce repeatable processes that create clear, prioritized risk findings
Typical background
5+ years of experience in cybersecurity, risk management, or related field

Transferable backgrounds

  • Coming from Cybersecurity Consultant
    Technical Assessment · Process Improvement
    The experience in conducting technical assessments and implementing process improvements in a consultancy role directly aligns with the responsibilities of designing and executing cybersecurity assessments and leading lean process enhancements.
  • Coming from IT Security Analyst
    Risk Management · Automation
    A background in IT security analysis, particularly with a focus on risk management and automation, provides the necessary skills to design and maintain automated assessment capabilities and ensure robust risk management.

Skills & requirements

Required

Third-party Risk AssessmentAutomation And Process ImprovementTechnical Evidence Validation

Preferred

Agentic AI ComponentsLean Process ImprovementTprm/grc Platforms

Stack & domain

Third-party Risk AssessmentTechnical Evidence ValidationCloud Configuration AnalysisIAM AssessmentsLogging/monitoring ValidationVulnerability/penetration Test InterpretationAgentic AILean Process ImprovementTprm/grc PlatformsAravoServicenow GRCRSA ArcherOnetrustAnalyticalProblem-solvingCisspCISMCriscAWS SecurityAzure SecurityGCP SecurityCybersecurityThird-party Risk ManagementAutomationConfigurationIntegrationAI

About the role

This role involves leading the design and execution of cybersecurity assessments for third-party vendors, ensuring robust risk management through automation and process improvements, and is ideal for someone with a strong background in cybersecurity and a knack for lean process optimization.

Original posting from Boeing

Senior Cybersecurity Third-Party Risk Analyst

Company:

The Boeing Company

We are seeking a highly experienced Senior Cybersecurity Third-Party Risk Analyst to perform advanced, technical assessments of third-party cyber risk and to design automation and process improvements using configuration, integration, and agentic AI capabilities. This senior individual contributor will focus on developing hands-on assessment processes to evaluate vendor controls, validate technical evidence, and drive remediation recommendations - while also building robust automation and configuration assets (scripts, connectors, playbooks, and AI agents) to scale assessment throughput, improve data quality, and accelerate risk decisions. A strong emphasis on lean process enhancement will ensure the program delivers higher velocity, lower waste, and measurable improvements in assessment quality and cycle time.

Though the position is primarily remote, there will be times to go into a Boeing facility. Candidates must live near a Boeing Facility or be willing to relocate at their own expense.

This position requires candidates to be a US Person (Green Card holder or US Citizen)

Key Responsibilities

  • Design & Execute end-to-end cybersecurity third-party assessments for strategic and high-risk vendors, including questionnaire reviews, technical evidence validation, architecture reviews, cloud configuration analysis, IAM assessments, encryption and key management reviews, logging/monitoring validation, and vulnerability/penetration test interpretation.
  • Produce repeatable processes that create clear, prioritized risk findings and remediation guidance tailored to vendor risk and business impact
  • Design, build, and maintain automated assessment capabilities: evidence collection scripts, API connectors, ETL pipelines, data validation routines, and integration points with TPRM/GRC platforms (Aravo, ServiceNow GRC, RSA Archer, OneTrust, etc.).
  • Develop and deploy agentic AI components (e.g., automated evidence triage, document ingestion and extraction, risk-scoring assistants, remediation suggestion agents) while ensuring safe, auditable, and privacy-preserving behavior.
  • Lead lean process improvement initiatives across the assessment lifecycle: map value streams, eliminate waste, reduce handoffs, optimize SLAs, and implement continuous improvement cycles to increase throughput and quality.
  • Create and maintain technical assessment artifacts: standardized templates, evidence matrices, technical checklists, assessment playbooks, and scoring rubrics that support repeatability and auditability.
  • Validate and tune automated scoring models and AI outputs; perform periodic calibration and manual reviews to ensure accuracy and reduce false positives/negatives.
  • Collaborate closely with Procurement, Legal, Security Operations/CIRT, Privacy, and other business stakeholders to ensure technical assessment findings map to contractual requirements and incident response expectations.
  • Support remediation verification and re-assessment - use automation to track evidence submission, validate fixes, and update risk status.
  • Maintain strong documentation & processes to support change management of automation logic, AI agent behaviors, data mappings, integration schemas
  • Stay current on emerging attack techniques, supply chain threats, automation best practices, responsible AI controls, and lean methods; propose and implement improvements.

Basic/Required Qualifications

  • 5+ years of cybersecurity experience with at least 3 years focused on third-party/vendor security assessments or equivalent technical assessment roles.
  • Deep hands-on expertise reviewing technical artifacts: cloud console evidence (AWS/Azure/GCP), architecture diagrams, IAM configurations, network security, encryption, logging/monitoring, vulnerability scans, and penetration test reports.
  • Proven ability to translate technical findings into concise executive-level summaries and remediation plans; excellent written and verbal communication skills.
  • Demonstrated experience applying lean principles or continuous improvement methods to operational processes - ability to run value stream mapping, define and measure waste, and implement sustainable improvements.
  • Comfortable working independently as a senior individual contributor and coordinating across technical and non-technical stakeholders; experience in agile environments and using agile tooling (ADO, JIRA).

Preferred Qualifications

  • Bachelor's degree in Computer Science, Information Security, Engineering, or related technical field; advanced degree (MS or equivalent) preferred.
  • Industry recognized security certifications (CISSP, CISM, CRISC) and/or cloud security certifications (AWS/Azure/GCP Security) preferred.
  • Strong configuration skills for security/TPRM tooling (Aravo, ServiceNow GRC, RSA Archer, OneTrust, or similar) including forms, workflows, scoring, and data model configuration.
  • Formal training or certificat

Source: Boeing careers

Similar roles