Third-Party Risk Management 1 at Millennium | NY, US | Rezi

Third-Party Risk Management 1 at Millennium

Third-Party Risk Management 1

Millennium · NY, US

4 days ago

Third-Party Risk Management 1

Millennium · NY, US

4 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Third-Party Risk Management 1 role.

Rezi rewrites your resume against Millennium's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Third-Party Risk Management 1 posting at Millennium — free, in seconds.

About the Role

The Information Security team protects the firm’s people, data, and technology across a complex, fast-moving global trading environment. This role partners with technology, trading, and business stakeholders to embed security throughout global operations, combining deep technical expertise with pragmatic risk management and advancing innovative applications of artificial intelligence to strengthen the firm’s defenses.

Responsibilities

  • Conduct security risk assessments for prospective and existing vendors, including questionnaire reviews, evidence validation, technical discussions, and identification of fourth-party and subprocessor dependencies.
  • Evaluate the materiality and business impact of findings, identify compensating controls, and recommend remediation or risk acceptance based on residual risk.
  • Prepare clear risk assessment reports and maintain accurate third-party risk inventory and assessment records.
  • Communicate findings, recommendations, and implementation requirements to technical teams, business stakeholders, and senior leaders.
  • Track remediation of identified security gaps and follow up on implementation requirements.
  • Partner with vendor management, procurement, legal, and business teams to embed security requirements into vendor contracts and onboarding processes.
  • Monitor existing vendors for security incidents and adverse news, engaging vendors to assess impact, root cause, and corrective actions.
  • Strengthen the third-party risk management program through improvements to methodology, questionnaires, monitoring, reporting, quality assurance, and automation.

Requirements

  • Experience conducting vendor or third-party security risk assessments, including familiarity with NIST CSF, SOC 2, ISO 27001, CIS Controls, SIG, and CAIQ.
  • Ability to analyze penetration-test reports and architecture or data-flow diagrams to assess vulnerability severity, connectivity, trust boundaries, and associated security risks.
  • Strong critical thinking and risk judgment, with the ability to assess materiality, business impact, and compensating controls.
  • Excellent written and verbal communication skills, with the ability to translate technical issues into clear risk and business implications for stakeholders.
  • Ability to manage multiple assessments and deadlines effectively in a fast-paced, high-stakes environment.
  • Experience with the secure use, deployment, and governance of AI models, tools, and supporting infrastructure, including GPUs and inferencing workloads; familiarity with on-premises and cloud infrastructure, TPRM platforms, reporting and automation tools, and Windows, Linux, and macOS environments is preferred.

Skills

  • NIST CSF
  • SOC 2
  • ISO 27001
  • CIS Controls
  • SIG
  • CAIQ
  • AI models
  • GPUs
  • inferencing workloads
  • on-premises infrastructure
  • cloud infrastructure
  • TPRM platforms
  • reporting tools
  • automation tools
  • Windows
  • Linux
  • macOS

Location

  • New York

Work Type

  • Full-time

Experience Level

  • Five or more years of hands-on third-party risk management experience

Education Level

  • Bachelor’s degree or higher in Computer Science, Computer Engineering, Cybersecurity, Information Security, or a related field, or commensurate work experience.

Salary/Compensations

  • $175,000 to $250,000

Benefits

  • Base salary
  • Discretionary performance bonus
  • Comprehensive benefits

About the Company

  • Millennium is a global, diversified alternative investment firm, founded in 1989. Defined by evolution, innovation and focus, Millennium’s mission is to deliver results for our investors.
  • Our people are empowered with both independence and support: the autonomy to pursue ideas with conviction and the backing of a global network committed to collaboration, disciplined risk management and continuous learning. With opportunities to deepen expertise and accelerate development, talent at Millennium is equipped to adapt, evolve and build lasting impact over time. Discover how transformative growth accelerates impact.