OutSystems
Lead Analyst, Security Strategy & Assurance
US - Remote
Sponsorship not specifiedDetected 5 days ago
ReactLLMsAgentic AICybersecurityComplianceProcess ImprovementProcurementCustomer SuccessHIPAALeadershipCommunicationMentoringCISSP
About the role
- If you are someone who brings deep expertise in vendor risk and compliance, excels at breaking down ambiguous goals into actionable programs, and wants to leave a measurable imprint on an organization's security posture, we want to meet you.
Responsibilities
- Own and Mature the Third Party Risk Management Program
- Define and drive OutSystems' TPRM strategy, including risk tiering methodology, assessment frameworks, and ongoing monitoring cadences for critical and high-risk vendors.
- Lead end-to-end vendor risk assessments and architect scalable processes that can grow with the business.
- Proactively identify gaps between current TPRM practices and industry standards, and build solutions to close them.
- Partner with Digital, Procurement, Legal, and Engineering to embed risk requirements into vendor selection and contracting, influencing how partner teams operate.
- Maintain the vendor risk inventory, track remediation of identified issues, and report status to leadership with clarity and consistency.
- Lead Enterprise Risk Activities
- Own and evolve the enterprise risk register for the Security division, ensuring risks are consistently identified, assessed, and treated across business units.
- Design and facilitate risk workshops with functional and business leaders to surface emerging risks and validate control effectiveness.
- Develop key risk indicators (KRIs) and produce executive-level risk reporting, including dashboards and trend analyses, that connect security posture to business outcomes.
Requirements
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
- 7-10 years of experience in information security, risk management, or compliance, with at least 3-4 years focused on third-party or vendor risk.
Nice to have
- Familiarity with GRC platforms.
- Knowledge of emerging third-party risk regulations such as DORA, NIS2, or CMMC.
- Experience with PCI DSS, HIPAA, or regional compliance frameworks.
- Background in a SaaS or cloud technology company environment.
- Experience mentoring or coaching junior team members.
- More about OutSystems
- OutSystems is a leading AI Development Platform built for the enterprise.
- OutSystems bridges the "enterprise gap" by combining the speed of generative AI with a deterministic, enterprise-grade framework.
Company info
- A company at the vanguard of the agentic revolution, where we don't just react to AI innovation-we architect it. Joining OutSystems means stepping onto a high-growth rocket ship that combines the fearless agility of a startup with the sophisticated, global foundation of an enterprise powerhouse.
- Real growth opportunities. We don't just talk about development; we invest in it through structured programs designed to scale your expertise. Whether you are aiming for vertical progression, exploring lateral moves into new domains, or mastering specialized AI skills through our Professional Development Fund and Internal Mobility Program, we provide the resources to get you there.
- A global collective of world-class talent, where you'll collaborate with enterprise software legends and sought-after thought leaders. At OutSystems, our industry experts aren't just visionaries-they are accessible, approachable mentors who are deeply invested in your growth as we architect the agentic future together.
Apply directly at OutSystems →Create a free account for alerts like thisView OutSystems immigration profile
This listing is sourced directly from OutSystems's careers page and normalized into a canonical job model.