OneMain Financial Jobs

Job Information

Western Alliance Bank Third-Party Cyber Risk Engineer III in Grove City, Ohio

Job Title: Third-Party Cyber Risk Engineer III Location: OH - Columbus What you'll do: As a Third-Party Cyber Risk Engineer III, you will independently and collaboratively manage cybersecurity risks across the Bank's thirdparty ecosystem. You will lead technical assessments of thirdparty services and clearly communicate findings to business partners and vendors. You will also help advance the team's efficiency and quality by introducing AI and automation into assessment, monitoring, and review processes. You'll partner with technology teams to design and implement modern solutions that strengthen the ThirdParty Cyber Risk program. The ThirdParty Cyber Risk Engineer III is a technically strong cybersecurity professional who improves operational efficiency and performs indepth reviews of vendor environments, AIenabled capabilities, automated assessment outputs, and cloud architectures. The role supports Western Alliance Bank's ThirdParty Cyber Risk program by identifying material risks, validating control effectiveness, and ensuring alignment with regulatory requirements, internal security standards, and enterprise AI governance. Success requires an analytical, skeptical mindset that helps uncover hidden risks among the Bank's third parties. This role requires strong engineering, processimprovement skills, knowledge of security frameworks, experience assessing thirdparty cyber risk, and the ability to communicate complex technical topics across cyber, risk, and business teams. This position is inoffice only. Perform technical cybersecurity assessments of thirdparty vendors, including cloud security, IAM, application and data security, network security, security governance, and incident response capabilities. Evaluate evidence and duediligence materials, including automated assessment outputs, SOC reports, penetration tests, policies, procedures, and AIrelated documentation, ensuring accuracy and completeness. Manage identified cyber risks using a riskbased approach, documenting control gaps and monitoring remediation through the thirdparty lifecycle. Develop and implement automation, dashboards, and AIenabled enhancements to improve assessment efficiency, evidence analysis, and overall program operations. Support incident response involving third parties and help secure SaaS platforms by configuring monitoring tools, advising business teams, and driving remediation of compliance issues. Produce clear technical findings and executivelevel reporting, and communicate risks with internal stakeholders and external vendors. Maintain and improve program documentation, including policies, standards, and procedures. Coordinate with SMEs to develop accurate, timely responses to duediligence inquiries from customers, rating agencies, and prospective clients, reflecting the Bank's security posture. What you'll need: 5+ years of experience in cybersecurity, security engineering, or thirdparty/vendor risk management, ideally within a regulated industry. Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field. Entry level to intermediate knowledge of general Financial Services or Banking is preferred. Solid understanding of authentication protocols SAML, SSO, and LDAP. Solid understanding of concepts regarding SIEM, SOAR, Firewall, Proxies, SSL/TLS, Secure Mail Gateways, Application Firewalls, NAC, Vulnerability Scanners, and EDR. Intermediate to advanced understanding of logging infrastructure concepts: syslog; log parsing; log de-duping; methods for log pulling; RFC 5424; CEF Format; JSON; key value pair format; log enrichment; log maintenance; log troubleshooting. Solid understanding of load balancers, DNS, SMTP, etc. for troubleshooting application functionality. Intermediate to advanced knowledge of NIST, MITRE and Administration of either or all of an IT Automation platform, SOAR, Firewall, IAM platform, SIEM,

DirectEmployers