Lead Third Party Risk Analyst (Hybrid)

American Family Insurance
$97,000 - $164,000 a year
Boston, Massachusetts
Full time
1 day ago
Step into the vibrant role of Lead Third Party Risk Analyst at American Family Insurance, where you'll orchestrate the dynamic assessment and management of IT, compliance or operational risks tied to our diverse third-party ecosystem, including vendors, partners, and service providers. You'll create risk management strategies, conduct comprehensive risk assessments, and collaborate cross functionally to ensure we align with internal risk frameworks, and regulatory expectations. Join us in creating a robust and resilient third-party risk program!
You will report to the Senior Manager, Third Party Risk Management.
#LI-Hybrid

Position Compensation Range:

$97,000.00 - $164,000.00

Pay Rate Type:

Salary

Compensation may vary based on the job level and your geographic work location. Relocation support is offered for eligible candidates.

Primary Accountabilities

  • Lead and execute vendor and non-vendor third party risk assessments and due diligence across cybersecurity, privacy, compliance, and operational domains, ensuring alignment with internal risk frameworks, and regulatory expectations.
  • Lead the identification, assessment, management, remediation, and tracking of third-party risks across the TPRM lifecycle, including onboarding, annual reassessments, and offboarding activities.
  • Act as an important partner to cybersecurity, data privacy, compliance, AI Governance, procurement, and teams in evaluating third-party risk profiles—translating findings into applicable business guidance.
  • Drive continuous improvement of the third-party processes, including onboarding, tiering, reassessment, exception handling, issue management, and offboarding.
  • Identify opportunities to deploy automation, analytics, and AI/ML techniques to improve data collection, risk scoring, and reporting processes.
  • Maintain a centralized third-party repository, monitoring performance, controls, and risk remediation across portfolio.
  • Participate in compliance assessments, policy reviews, and internal audits improving third-party-related risks.
  • Monitor latest cybersecurity and data privacy laws, compliance obligations, and industry standards to assess third-party exposure and adjust TPRM criteria accordingly.
  • Remain current on regulatory changes, cybersecurity and data privacy requirements, and third-party risk trends, governance frameworks, and industry best practices.
  • Lead key internal, cross functional, and stakeholder relationships to ensure expectations and opportunities to collaborate are transparently communicated.
  • Work with leaders to evaluate risk relative to company strategy and risk appetite, assign accountability of mitigation strategies, and implement processes to monitor and report success.
  • Accountable for partner engagement/management to understand internal processes and identify potential risks.

Specialized Knowledge & Skills Requirements

  • Experience conducting third-party risk assessments, IT risk and compliance control assessments and evaluating compliance and privacy controls.
  • Stakeholder engagement and communication skills—able to translate risk findings into concise, business-ready guidance.
  • Demonstrated subject‑matter expertise with cybersecurity and information security controls—including privacy impact assessments, data protection requirements, and third-party security practices.
  • In-depth knowledge of regulatory requirements and industry standards related to cybersecurity, data privacy, and compliance.
  • Hands-on experience reviewing privacy, compliance, and cybersecurity artifacts (PIAs, DPAs, SOC reports, ISO certifications, etc.).
  • Broad knowledge and understanding of insurance, industry trends and adjacencies.
  • Demonstrated experience providing customer-driven solutions, support, or service.
  • Advanced knowledge of security analysis processes and standards for conducting and reporting security analysis to stakeholders.
  • Extensive knowledge and understanding of IT Risk Management and/or Information Systems Auditing.
  • Extensive knowledge and understanding of IT risk and control frameworks.
  • Solid knowledge and understanding of risk management methods, standards, processes, governance models, and industry standard risk analysis approaches.

Licenses:

  • Professional certification such as CISA, CIPP, CIPM, CISSP, CRISC, CTPRP or similar are preferred.

Travel Requirements

  • Up to 10%.

Physical Requirements

  • Work that primarily involves sitting/standing.

Working Conditions

  • Not Applicable.

Additional Information

  • Offer to selected candidate will be made contingent on the results of applicable background checks

  • Offer to selected candidate is contingent on signing a non-disclosure agreement for proprietary information, trade secrets, and inventions

  • Sponsorship will not be considered for this position unless specified in the posting

  • In this hybrid role, you will be expected to work a minimum of 10 days per month from one of these offices: Madison, WI 53783; Boston, MA 02110
  • Internal candidates are encouraged to apply regardless of location and will be considered based upon the needs of the role.

We encourage you to apply even if you do not meet all of the requirements listed above. Skills can be used in many different ways, and your life and professional experience may be relevant beyond what a list of requirements will capture. We encourage those who are passionate about what we do to apply!

We provide benefits that support your physical, emotional, and financial wellbeing. You will have access to comprehensive medical, dental, vision and wellbeing benefits that enable you to take care of your health. We also offer a competitive 401(k) contribution, a pension plan, an annual incentive, 9 paid holidays and a paid time off program (23 days accrued annually for full-time employees). In addition, our student loan repayment program and paid-family leave are available to support our employees and their families. Interns and contingent workers are not eligible for American Family Insurance Group benefits.

We are an equal opportunity employer. It is our policy to comply with all applicable federal, state and local laws pertaining to non-discrimination, non-harassment and equal opportunity. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law.

#LI-AB1
Apply
Other Job Recommendations:

Party Planet Assistant Manager/ Sales Associates

Party Planet
Surprise, Arizona
$16 - $18 an hour
Experience with inflating balloons would also be helpful for this position. Email or drop off a resume and let us know why you are...
2 weeks ago

Equity Risk Analyst

Invesco
Houston County, Texas
$130,000 - $135,000 a year
  • 401(K) matching of 100% up to the first 6% with a...
  • The responsibilities of the Investment Risk Analyst include...
1 week ago

Board Certified Behavior Analyst (BCBA)

Spec Results Day School
Ohio
$55 - $85 an hour
  • Self-created schedule
  • Fully Remote
  • Bonus opportunities...
2 weeks ago

Event/Party Host

Big Air Trampoline Park
Sterling Heights, Michigan
  • Greet and welcome party guests
  • Communicate with “commander in chief” to make any...
1 week ago

Party Coordinator

Arch Amenities Group
Washington County, Pennsylvania
  • Continuously monitor entire facility to ensure all guests...
  • Report all incidents and complete necessary paperwork in...
2 weeks ago

Risk Adjustment Analyst II

CareSource
Remote
$61,500 - $98,400 a year
  • Prepare and review integrated analysis and reports to...
  • Identifies trends and patterns within the Risk Adjustment...
2 weeks ago

Game Floor Attendant/ Birthday Party Host

South Windsor Entertainment
Capitol Planning Region, Connecticut
You will be responsible for modeling and acting in accordance with the uncompromising core values and integrity that have...
2 weeks ago

Treasury Risk Analyst

M&T Bank
Buffalo, New York
$70,023 - $116,706 a year
This position supports, and reports, to the Senior Risk Analyst responsible for oversight of interest rate, market or liquidity...
3 weeks ago

SOC Analyst

Piper Companies
Manassas, Virginia
$100,000 - $170,000 a year
  • Analyze logs utilizing Splunk, Panorama and Syslog to...
  • Recommend improvements for threat data collection to...
3 weeks ago

Risk & Business Analyst

Washington Cities Insurance Authority
Tukwila, Washington
$88,008 - $132,012 a year
  • Develop or work with predictive analytic tools and...
  • Collaborate with claims and risk management teams to support...
2 weeks ago