Third Party Risk Analyst
Fortified Health Security • Exton, PA • Full Time • $65,000–$70,000 / year
Posted on Mon, Oct 5, 2026
Job Summary
Under the general direction of the Manager, Third Party Risk Management, the Third Party Risk Analyst is responsible for ensuring that Third-Party Risk Management (TPRM) assessments are successfully and consistently processed and delivered to clients. This position requires a moderate working knowledge of information security frameworks and the application of these frameworks to identify instances of risk in relation to third parties. The role includes responsibilities in product/service evaluation, risk identification and remediation, report writing, and client consulting on all matters related to the protection and regulatory compliance of patient health information.
Essential Job Functions
The following duties are normal for this position. The omission of specific statements of duties does not exclude them from being expected of this position if the work is similar, related, or a logical assignment for this position. Other duties may be required.
§ Ensure timely delivery of TPRM vendor assessment reports, and other TPRM service deliverables as required
§ Create reports which reflect assessment findings and recommendations in both technical and executive-level formats
§ Communicate with clients and third parties regarding TPRM service support and delivery
§ Directly manage and oversee the delivery of TPRM services for clients the Third Party Risk Analyst is dedicated to supporting
§ Maintain a working knowledge of healthcare information security and privacy laws and regulations alongside industry frameworks including, but not limited to: HIPAA, HITECH, and the NIST CSF 2.0
§ Maintain a working knowledge of TPRM best practices
§ Contribute to the maintenance of client specific and internally managed TPRM policies and standard operating procedures
Knowledge & Skills
Education & Experience
§ Bachelor's degree from a four-year college or university or combination of education and experience
§ 1+ years’ experience in all or most of the following:
o IT support or help desk, preferably in an enterprise environment
o Information security frameworks and/or standards such as the HITRUST CSF, the NIST CSF 2.0, ISO 27001, and SOC 2 Type 2
§ Use and application of the HIPAA Security Rule in day-to-day responsibilities preferred
§ Information security experience within the healthcare industry highly preferred
Special Skills & Knowledge
§ Ability to be flexible and manage tasks as priorities change based on client needs
§ Self-driven individual who requires minimal direct supervision from supervisors when completing known, repeatable tasks
§ Analytical mindset which enables the individual to efficiently and accurately gain an understanding of how a newly presented product or service functions, supporting the creation and delivery of assessment reports and findings
§ Exceptional problem-solving abilities alongside a desire to continually learn new concepts related to the field
§ Detail and results oriented, skilled at both planning and hands-on execution
§ Ability to excel in a team-oriented, collaborative office environment
§ Excellent written, verbal, and presentation skills
§ Intermediate understanding of security concepts and how they should be applied to a system’s architecture and workflow
§ Intermediate understanding of network infrastructure and security concepts
Licenses, Certifications, etc.
§ Preferred certifications: Network+, Security+, HITRUST-related certifications
Competencies
§ Service Delivery – Exeuction of third-party assessments and related services as defined by Fortified’s methodology.
§ Communication – Leverage soft skills to effectively communicate with both external vendors and internal client stakeholders in a way which enables the associate to create comprehensive third party assessment deliverables.
§ Risk Identification – Evaluates third-party products with the objective of identifying risks which impact a client’s security posture, including the documentation of the risk itself and recommended remediation actions.
Requirements
Supervisory Responsibility
§ Third-party risk management services delivered within the Third Party Risk Management business unit
Working Conditions & Travel Requirements
§ Travel as needed
Fortified Health Security is an Equal Opportunity Employer. In compliance with the Americans with Disabilities Act, Fortified Health Security will provide reasonable accommodations to qualified individuals with disabilities. If a reasonable accommodation is needed to perform this position, you need to inform Fortified Health Security People and Culture Team of such request. Signatures below indicate the receipt and review of this job description by the associate assigned to the position and the People and Culture Team.
More live risk_analyst roles
- Senior Enterprise Risk Analyst at First American (Remote)
- Senior Group Risk Analyst at TD Bank — Toronto, ON, Canada
- Enterprise Risk Analyst II at H. Lee Moffitt Cancer Center and Research Institute — Not Specified
- Senior AI Risk Analyst at Summit Tech — Easton, PA, US
- Credit Risk Analyst at Amerisure Mutual Insurance — Farmington Hills, MI, USA
- Risk Analyst at Check (Remote)
- Risk Analyst II at Boulevard (Remote)
- Credit Risk Analyst at Fidelity — Boston, Massachusetts, USA
- Quantitative Cost Risk Analyst (Construction) at Turner & Townsend — Hobbs, New Mexico, United States
- Fraud Risk Analyst at U.S. Bank — Minneapolis, MN, US
- Sr. Risk Analyst (Enterprise Risk Management) at Independence Blue Cross — Philadelphia, Pennsylvania, US
- Mission Risk Analyst at Booz Allen Hamilton — Alexandria, VA, US
- Cyber Risk Analyst at Customers Bank — Malvern, Pennsylvania, United States
- Senior AI Risk Analyst at Victaulic (Remote)
- Treasury Risk Analyst at UW Credit Union — Madison, Wisconsin, United States
- Loan Portfolio Risk Analyst at ESL All Companies — Rochester, NY, US
- Loan Portfolio Risk Analyst at ESL — Rochester, New York, United States
- Risk Analyst Senior at USAA — San Antonio, TX, United States
- Risk Analyst Senior - P&C Risk at USAA — San Antonio, TX, US
- Fraud Risk Analyst at SC State Credit Union — Columbia, South Carolina, United States
- Model Risk Analyst at UMB Bank (Remote)
- Risk Analyst I at ONEOK — Tulsa, Oklahoma, United States
- Risk Analyst at AltaGas — Calgary, Alberta, Canada
- Consumer Credit Risk Analyst at KeyBank — Amherst, New York, United States
- Front Office Credit Risk Analyst, Assistant Vice President at State Street — Boston, Massachusetts, United States
- Credit Risk Analyst, Assistant Vice President at State Street — Boston, Massachusetts, US
What the data says about this job
- Advertised pay for Risk Analyst: a median of $92,759 across 889 priced postings. This posting advertises $65,000 to $70,000, 27% below that median. Explore the market
Measured from employers' own postings and public filings. How we measure