Epic Games

Senior Third-Party Risk Management Analyst

Join Epic Games in Cary, NC as a Senior Third-Party Risk Management Analyst. Leverage ServiceNow skills to assess vendor risks, ensuring compliance and security.

ServiceNow Role Type:
ServiceNow Modules:
Department - JobBoardly X Webflow Template
Governance, Risk, and Compliance
Department - JobBoardly X Webflow Template
Third-Party Risk Management
ServiceNow Certifications (nice to have):
Department - JobBoardly X Webflow Template
Certified Implementation Specialist - Third-Party Risk Management

Job description

Date - JobBoardly X Webflow Template
Posted on:
 
May 13, 2025

As a Senior Third-Party Risk Management Analyst, you will lead security-focused due diligence and ongoing oversight of third-party service providers, ensuring they align with Epic's security, privacy, and compliance standards. This role is critical in protecting Epic's ecosystem and will involve leading third-party risk assessments, performing due diligence on vendors, and managing periodic reassessments. You will also collaborate with stakeholders across the company to integrate third-party risk insights into broader enterprise risk initiatives.

Requirements

  • 5+ years of experience in third-party risk management, information security, IT audit, or GRC
  • Deep understanding of security risk assessment frameworks and best practices
  • Proficiency in GRC platforms such as Archer, OneTrust, ServiceNow, or similar tools
  • Excellent verbal and written communication skills
  • Ability to influence and challenge stakeholders at all levels

Benefits

  • 100% coverage of medical, dental, and vision premiums for you and your dependents
  • 401k with competitive match
  • Long Term Disability, Life Insurance
  • Unlimited PTO and sick time
  • Robust mental well-being program through Modern Health
  • Paid sabbatical after 7 years of employment

Requirements Summary

5+ years of experience in third-party risk management, information security, or GRC, with a deep understanding of security risk assessment frameworks and best practices, and proficiency in GRC platforms