Skip to main content

Cybersecurity Third Party Risk Analyst, Lead

Location: Baltimore, Maryland

Apply

What makes a Cybersecurity Third Party Risk Analyst, Lead successful at OneMain? Check out the top traits we’re looking for and see if you qualify.

  • Adaptable
  • Analytical
  • Curious
  • Entrepreneurial
  • Inventive
  • Problem Solver

Culture

  • We foster an entrepreneurial spirit that's powered by a national brand – our teams are empowered to make a difference
  • We encourage teams to take ownership of initiatives in this fast-paced, innovative culture so they can drive solutions that stay ahead of customer needs
  • We prioritize teamwork and building in-person connections with each other, understanding that fostering a collaborative environment is the best way to support each other.
  • We promote avenues to allow team members to expand their professional capabilities and continuously develop skills, facilitating upward mobility and career progression
Headshot of Andy W.

I like working at OneMain because of the opportunity it provides. You get to work with a lot of talented people, a lot of motivation to better the lives of our customers and a lot of fun technology that you get to interact with on a daily basis. I feel like I have many different options that I can take on yearly.

Andy W., Software Developer

Benefits

  • Blue circular icon with 4 people illustrations

    We promote social and family well-being by offering paid time off for volunteer hours and providing family back-up care.

  • Blue circular icon with open hands holding heart

    We offer extensive, comprehensive coverage to support team members’ needs physically and mentally, such as access to Talkspace and Hinge for on-demand physical therapy via an app.

  • Blue circular icon with piggy bank

    We offer financial wellness that includes 401(k) with match, ESPP, tuition reimbursement and tools like subscription cancelation that help you stay on top of your financial goals.

Cybersecurity Third Party Risk Analyst, Lead

Location: Baltimore, MD
Apply
Job Number R2602-49771 Date posted 02/20/2026

The Cybersecurity Third Party Risk Analyst is responsible for identifying, assessing, and managing cybersecurity risks arising from the organization’s use of third parties. This role performs risk-based cyber due diligence in alignment with a defined assessment schedule and risk tiering methodology to ensure that third-party controls are commensurate with the sensitivity, criticality, and regulatory impact of the services provided.

The Analyst evaluates the design and effectiveness of third-party cybersecurity controls, validates alignment with regulatory requirements and internal standards, and drives remediation of identified control gaps. This role serves as a key liaison between business stakeholders, third parties, and cybersecurity leadership to ensure risks are clearly understood, documented, and mitigated in a manner that balances regulatory obligations with business objectives.

The position requires strong technical acumen, regulatory awareness, and the ability to translate complex cybersecurity risks into clear, actionable insights for both technical and non-technical audiences.

Responsibilities:

  • Perform cybersecurity due diligence of third parties across the vendor lifecycle, including onboarding, periodic reassessments, and trigger-based reviews.
  • Identify control gaps, residual risks, and non-compliance issues; partner directly with third parties and internal stakeholders to develop and track remediation plans.
  • Track and monitor the status of each due diligence review and communicate the status with management and key stakeholders on a regular basis.
  • Clearly articulate risk exposure, business impact, and remediation options, including compensating controls where appropriate.
  • Prepare comprehensive, audit-ready documentation that supports regulatory examinations, internal audit reviews, and management reporting.
  • Monitor remediation progress and provide regular status updates to leadership and key stakeholders.
  • Continuously evaluate and enhance third-party risk management processes, documentation standards, and assessment methodologies to improve efficiency and risk visibility.
  • Support a strong risk culture by promoting transparency, collaboration, and accountability across business and vendor relationships.

Qualifications:

  • 3–7+ years of experience in cybersecurity risk management, information security governance, control testing, audit, or information security.
  • Working knowledge of regulatory frameworks and expectations, including NYDFS 23 NYCRR 500 and industry standards such as NIST CSF and CIS Controls.
  • Demonstrated ability to identify control deficiencies and assess their impact on organizational risk.
  • Experience preparing documentation suitable for regulatory review and audit scrutiny.
  • Strong written and verbal communication skills, with the ability to translate technical risk into concise executive-level summaries.
  • Ability to manage competing priorities in a fast-paced, regulated environment.
  • Proven ability to balance risk mitigation with practical business considerations.

Cybersecurity Risk, a team within OneMain’s Enterprise Risk Management organization, is a fast-growing team focused on providing expert insight into risk, developing team members, and effective oversight of cybersecurity and technology risk. This is a team where you can work with talented team members across Cyber Risk, Cyber Tech, Risk Management, and Technology organizations. You will be challenged to excel with exciting and challenging opportunities daily. There is transparency and great support from management teams to allow team members to be effective, grow their careers, and meet company goals. Hard work and initiative are rewarded and recognized by management and colleagues alike, which promotes a culture of respect and value across the organization. Within the Cybersecurity Risk team, you will be conducting meaningful work and making a difference in the lives of OneMain’s customers and team members by promoting a cybersecurity culture, optimizing cybersecurity capabilities, protecting data, and developing cyber resilient programs.

Apply

You have not saved any jobs.

You have not recently viewed any jobs.

Join our Talent Community

Sign up here for job alert emails and SMS messages from OneMain Financial Recruiting.

Already signed up?

Interested InPlease select a category or location option. Click “Add” to create your job alert.