375,093open jobs
9,735companies
47,872added this week
Browse all
Salary
$121k – $146k per year
Location
In office (Louisville, Washington)
Employment
Full-Time
Overview
Company
Impact
Profile match
A global law firm that works as part of your team. Helping solve your toughest and most complex legal issues. Wherever you are.

Hogan Lovells Cadwalader delivers decisive counsel at the intersection of finance, business, and regulation, helping clients succeed when it matters most. We are a leading global law firm trusted to advise on complex, high stakes matters, combining global scale with local intelligence to help clients move markets, shape industries, define new opportunities, and succeed. With more than 3,100 lawyers worldwide, we bring sharp thinking, deep commercial understanding, and an uncompromising commitment to delivering exceptional outcomes for clients.

The Vendor Security Analyst performs evaluation of third party and vendor engagements to identify and manage vendor risk which may include completion of risk assessments. They will also conduct the technical security reviews of our suppliers and partners. This role reports to the Head of Information Risk.

KEY RESPONSIBILITIES

  • Evaluate third party risk and steer vendor relationships
  • Evaluate vendor responses to security questionnaires
  • Make recommendations on ways to mitigate vendor risk
  • Maintain vendor risk repository of artifacts including regular third party vendor certifications and assign risk scores to firm suppliers and partners
  • Conduct onsite audits of high risk vendors reviewing security and controls
  • Actively support and engage in the firm's Responsible Business initiatives, contributing to our commitments to our people, clients, communities, and the environment.
  • Provide support on emerging priorities and undertake additional responsibilities as needed to meet evolving business requirements.

QUALIFICATIONS

EDUCATION & EXPERIENCE

  • Strong and demonstration information security risk identification (including Cloud services), assessment, and risk ranking experience
  • Working experience with the following documents used in a risk assessment preferred:
  • SIG (Standardized Information Gathering) questionnaire
  • Penetration test
  • Vulnerability test
  • SOC (Service Organization Control) 1 and 2, Type 2
  • ISO 27001
  • Bachelor's degree preferred.

SKILLS & ABILITIES

  • Possess a sufficient understanding of technical concepts including systems, networks, and security architecture best practices in order to effectively evaluate risk and assess the effectiveness of controls
  • Confident to make independent decisions
  • Ability to explain technical concepts in layman terms
  • Ability to interact effectively and influence external vendors
  • Keen attention to detail and accuracy in order to analyze documents
  • Broad knowledge of risk management, vulnerability management, and third party risk

WORK SCHEDULES/HOURS EXPECTATION

Core hours are generally Monday through Friday, 9:00 a.m. to 5:30 p.m., including an unpaid meal period. This position is based on a standard 37.5-hour workweek. Additional or adjusted hours may be required to meet business needs and must be worked in accordance with applicable overtime requirements and firm policies.

In Washington, D.C., the expected base salary range for this role is $120,500 to $146,200per year.

This range reflects a good-faith estimate of pay at the time of posting; the actual compensation offered may vary depending on factors such as the candidate’s qualifications. This position is eligible for additional forms of compensation, which may include annual discretionary bonuses. Employees in this role are also eligible for benefits offered by the firm, subject to applicable plan terms and conditions, which currently include medical, dental, and vision insurance; a 401(k)-retirement plan; and paid time off. Please review this link for more information regarding employee benefits in the United States.

This job description sets forth the responsibilities of this position and may be changed from time to time as shall be determined.

Hogan Lovells Cadwalader is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, age, national origin, disability, sexual orientation, gender identity or expression, marital status, genetic information, protected Veteran status, or other factors protected by law.

Hogan Lovells Cadwalader complies with federal and state disability laws and makes reasonable accommodations for applicants and candidates with disabilities. If reasonable accommodation is needed to participate in the job application or interview process, please contact our Benefits Department at [email protected].

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
375,093 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Louisville
$27k – $61k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree • India
PowerShell
Python
DevOps
Azure
Azure DevOps
GitLab
Grafana
Rest API
Cybersecurity
ISO 27001
OWASP SAMM
Threat Modeling
Analytics
Power BI
Tableau
Management
Jira
ServiceNow
Apply
$73k – $180k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Boadilla del Monte
AI/ML
AI Agents
Anthropic
DevOps
AWS
Cybersecurity
ISO 27001
Apply
$186k – $193k per year • In office • Full-Time • London
Cybersecurity
ISO 27001
NIST CSF
Apply
$126k – $251k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree • United States
Cybersecurity
ISO 27001
NIST CSF
Apply
$22k – $55k per year (Estimated) • In office • Full-Time • Chennai
Cybersecurity
CIS Benchmarks
ISO 27001
Nessus
Wireshark
Apply
$100k – $125k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Washington • Denver • Colorado Springs • Philadelphia • Baltimore
SQL
C#
C#
.NET
Databases
MS SQL
Apply
IT Business Analyst 2 months ago
$56k – $151k per year (Estimated) • Remote/Hybrid • Full-Time • PhD • London
DevOps
Azure
Management
Microsoft Project
Apply
$260k – $365k per year • In office • Full-Time • 3+ years exp • Washington
Cybersecurity
HIPAA
Apply
In office • Full-Time • Paris
Apply
$126k – $174k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Louisville
Databases
Databricks
Snowflake
DevOps
Azure
Apply
$172k – $237k per year • Remote • Full-Time • 10+ years exp • PhD • Charlotte • Louisville • Tampa • Fort Lauderdale • Washington
Databases
Databricks
Snowflake
AI/ML
Claude
Claude Code
Copilot
AI Agents
DevOps
AWS
Azure
GCP
Cybersecurity
HIPAA
Apply
$106k – $200k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Milwaukee • San Francisco • Cincinnati • Kansas City • Chicago
Apply
$118k – $162k per year • Remote • Full-Time • 10+ years exp • Bachelor's Degree • Louisville • Fort Lauderdale • Washington • Chicago • Tampa
DevOps
Azure
GCP
Cybersecurity
HIPAA
Apply
$153k – $203k per year • Equity • Remote/Hybrid • Full-Time • Bachelor's Degree • Louisville
Apply
See all jobs
This is one of many
375,093 more open roles from verified company boards, updated every day.