採用
ZS is a place where passion changes lives. As a management consulting and technology firm focused on improving life and how we live it, we transform ideas into impact by bringing together data, science, technology and human ingenuity to deliver better outcomes for all. Here you’ll work side-by-side with a powerful collective of thinkers and experts shaping life-changing solutions for patients, caregivers and consumers, worldwide. ZSers drive impact by bringing a client-first mentality to each and every engagement. We partner collaboratively with our clients to develop custom solutions and technology products that create value and deliver company results across critical areas of their business. Bring your curiosity for learning, bold ideas, courage and passion to drive life-changing impact to ZS.
What you'll do: Governance & Risk Analyst in the Enterprise will…
The GRC Analyst will support the organization’s Governance, Risk & Compliance function with a primary focus on Third‑Party Risk Management (TPRM) and Vendor Risk Assessments (VRA). This role is responsible for conducting end‑to‑end risk assessments of third‑party vendors, identifying security, privacy, and compliance risks, and working with internal stakeholders and vendors to ensure timely risk remediation and closure.
The role requires strong analytical skills, stakeholder engagement, and familiarity with information security, privacy, and regulatory frameworks.
Key Responsibilities
Third‑Party Risk Management (TPRM) & Vendor Risk Assessments (VRA)
- Conduct end‑to‑end Vendor Risk Assessments (VRA) including initiation, analysis, follow‑ups, and final reporting
- Review vendor security questionnaires, supporting evidence, and contractual artifacts to assess information security, privacy, and compliance risks
- Identify inherent and residual risks across domains such as not limited only to below:
- Information Security
- Data Privacy
- Access Controls
- Business Continuity & Disaster Recovery
- Regulatory & Compliance requirements
- Clearly document assessment findings, risk ratings, and remediation recommendations in risk management tools and trackers
- Coordinate with vendors to obtain clarifications, remediation plans, and follow‑up evidence for identified gaps
Stakeholder Collaboration & Governance
- Partner with internal teams including Procurement, Legal, Information Security, Privacy, and Business Owners to support third‑party onboarding and risk decisions
- Escalate high‑risk findings and delays to GRC leadership with clear summaries and recommended actions
- Support second‑level reviews and management reporting for VRAs and TPRM activities
Risk Reporting & Continuous Improvement
- Maintain accurate risk registers, assessment trackers, and dashboards for VRA/TPRM
- Contribute to improving TPRM frameworks, workflows, and reporting to enhance stakeholder value
- Assist in developing and updating SOPs, templates, and guidance documents related to vendor risk management
Audit & Compliance Support
- Support internal and external audits by providing VRA documentation, evidence, and risk summaries
- Assist with broader GRC initiatives such as policy reviews, opportunity security risk assessments, and compliance assessments as needed
What you’ll bring:
- Bachelor’s degree in computer science, Information Systems, or a related field. A relevant master's degree is a plus.
- Proven experience of at least 2 years or more in IT risk management, governance, or a related field.
- Strong understanding of IT risk assessment methodologies, frameworks, and industry best practices.
- Assess vendor security posture against frameworks such as ISO 27001 / 27002, NIST, and SOC 2.
- Familiarity with regulatory requirements (e.g., GDPR, HIPAA, PCI DSS) and their impact on IT risk management.
- Knowledge of vendor risk management principles and practices.
- Experience in performing process, Contract review and project security risk assessments.
- Proficiency in using risk assessment tools and technologies.
- Excellent analytical and problem-solving skills.
- Strong written and verbal communication skills, with the ability to effectively communicate technical concepts to both technical and non-technical audiences.
- Strong organizational and time management skills, with the ability to manage multiple priorities and deadlines.
- Relevant certification such as ISO 27001:2022 LA is preferred.
- Fluency in English
- Client-first mentality
- Intense work ethic
- Collaborative spirit and problem-solving approach
How you’ll grow:
- Cross-functional skills development & custom learning pathways
- Milestone training programs aligned to career progression opportunities
- Internal mobility paths that empower growth via s-curves, individual contribution and role expansions
Perks & Benefits:
ZS offers a comprehensive total rewards package including health and well-being, financial planning, annual leave, personal growth and professional development. Our robust skills development programs, multiple career progression options and internal mobility paths and collaborative culture empowers you to thrive as an individual and global team member.
Hybrid working model:
We are committed to giving our employees a flexible and connected way of working. A flexible and connected ZS allows us to combine work from home and on-site presence at clients/ZS offices for the majority of our week. The magic of ZS culture and innovation thrives in both planned and spontaneous face-to-face connections.
Travel:
Travel is a requirement at ZS for client facing ZSers; business needs of your project and client are the priority. While some projects may be local, all client-facing ZSers should be prepared to travel as needed. Travel provides opportunities to strengthen client relationships, gain diverse experiences, and enhance professional growth by working in different environments and cultures.
Considering applying?
At ZS, we honor the visible and invisible elements of our identities, personal experiences, and belief systems—the ones that comprise us as individuals, shape who we are, and make us unique. We believe your personal interests, identities, and desire to learn are integral to your success here. We are committed to building a team that reflects a broad variety of backgrounds, perspectives, and experiences. Learn more about our inclusion and belonging efforts and the networks ZS supports to assist our ZSers in cultivating community spaces and obtaining the resources they need to thrive.
If you’re eager to grow, contribute, and bring your unique self to our work, we encourage you to apply.
ZS is an equal opportunity employer and is committed to providing equal employment and advancement opportunities without regard to any class protected by applicable law.
To complete your application:
Candidates must possess or be able to obtain work authorization for their intended country of employment. An on-line application, including a full set of transcripts (official or unofficial), is required to be considered.
NO AGENCY CALLS, PLEASE.
Find Out More At:
www.zs.com
What you'll do: Governance & Risk Analyst in the Enterprise will…
The GRC Analyst will support the organization’s Governance, Risk & Compliance function with a primary focus on Third‑Party Risk Management (TPRM) and Vendor Risk Assessments (VRA). This role is responsible for conducting end‑to‑end risk assessments of third‑party vendors, identifying security, privacy, and compliance risks, and working with internal stakeholders and vendors to ensure timely risk remediation and closure.
The role requires strong analytical skills, stakeholder engagement, and familiarity with information security, privacy, and regulatory frameworks.
Key Responsibilities
Third‑Party Risk Management (TPRM) & Vendor Risk Assessments (VRA)
- Conduct end ‑to‑end Vendor Risk Assessments (VRA) including initiation, analysis, follow‑ups, and final reporting
- Review vendor security questionnaires, supporting evidence, and contractual artifacts to assess information security, privacy, and compliance risks
- Identify inherent and residual risks across domains such as not limited only to below:
- Information Security
- Data Privacy
- Access Controls
- Business Continuity & Disaster Recovery
- Regulatory & Compliance requirements
- Clearly document assessment findings, risk ratings, and remediation recommendations in risk management tools and trackers
- Coordinate with vendors to obtain clarifications, remediation plans, and follow‑up evidence for identified gaps
Stakeholder Collaboration & Governance
- Partner with internal teams including Procurement, Legal, Information Security, Privacy, and Business Owners to support third‑party onboarding and risk decisions
- Escalate high‑risk findings and delays to GRC leadership with clear summaries and recommended actions
- Support second‑level reviews and management reporting for VRAs and TPRM activities
Risk Reporting & Continuous Improvement
- Maintain accurate risk registers, assessment trackers, and dashboards for VRA/TPRM
- Contribute to improving TPRM frameworks, workflows, and reporting to enhance stakeholder value
- Assist in developing and updating SOPs, templates, and guidance documents related to vendor risk management
Audit & Compliance Support
- Support internal and external audits by providing VRA documentation, evidence, and risk summaries
- Assist with broader GRC initiatives such as policy reviews, opportunity security risk assessments, and compliance assessments as needed
What you’ll bring:
- Bachelor’s degree in computer science, Information Systems, or a related field. A relevant master's degree is a plus.
- Proven experience of at least 2 years or more in IT risk management, governance, or a related field.
- Strong understanding of IT risk assessment methodologies, frameworks, and industry best practices.
- Assess vendor security posture against frameworks such as ISO 27001 / 27002, NIST, and SOC 2.
- Familiarity with regulatory requirements (e.g., GDPR, HIPAA, PCI DSS) and their impact on IT risk management.
- Knowledge of vendor risk management principles and practices.
- Experience in performing process, Contract review and project security risk assessments.
- Proficiency in using risk assessment tools and technologies.
- Excellent analytical and problem-solving skills.
- Strong written and verbal communication skills, with the ability to effectively communicate technical concepts to both technical and non-technical audiences.
- Strong organizational and time management skills, with the ability to manage multiple priorities and deadlines.
- Relevant certification such as ISO 27001:2022 LA is preferred.
- Fluency in English
- Client-first mentality
- Intense work ethic
- Collaborative spirit and problem-solving approach
How you’ll grow:
- Cross-functional skills development & custom learning pathways
- Milestone training programs aligned to career progression opportunities
- Internal mobility paths that empower growth via s-curves, individual contribution and role expansions
Perks & Benefits:
ZS offers a comprehensive total rewards package including health and well-being, financial planning, annual leave, personal growth and professional development. Our robust skills development programs, multiple career progression options and internal mobility paths and collaborative culture empowers you to thrive as an individual and global team member.
Hybrid working model:
We are committed to giving our employees a flexible and connected way of working. A flexible and connected ZS allows us to combine work from home and on-site presence at clients/ZS offices for the majority of our week. The magic of ZS culture and innovation thrives in both planned and spontaneous face-to-face connections.
Travel:
Travel is a requirement at ZS for client facing ZSers; business needs of your project and client are the priority. While some projects may be local, all client-facing ZSers should be prepared to travel as needed. Travel provides opportunities to strengthen client relationships, gain diverse experiences, and enhance professional growth by working in different environments and cultures.
Considering applying?
At ZS, we honor the visible and invisible elements of our identities, personal experiences, and belief systems—the ones that comprise us as individuals, shape who we are, and make us unique. We believe your personal interests, identities, and desire to learn are integral to your success here. We are committed to building a team that reflects a broad variety of backgrounds, perspectives, and experiences. Learn more about our inclusion and belonging efforts and the networks ZS supports to assist our ZSers in cultivating community spaces and obtaining the resources they need to thrive.
If you’re eager to grow, contribute, and bring your unique self to our work, we encourage you to apply.
ZS is an equal opportunity employer and is committed to providing equal employment and advancement opportunities without regard to any class protected by applicable law.
To complete your application:
Candidates must possess or be able to obtain work authorization for their intended country of employment. An on-line application, including a full set of transcripts (official or unofficial), is required to be considered.
NO AGENCY CALLS, PLEASE.
Find Out More At:
www.zs.com
総閲覧数
0
応募クリック数
0
模擬応募者数
0
スクラップ
0
類似の求人

Risk Management - Credit Risk Analyst
JPMorgan Chase · Chicago, IL, United States, US

Credit Underwriter
Adyen · Chicago

Executive Underwriter, National Accounts Casualty
Hartford · Chicago, IL

Private Client Banker - State and Wacker Branch - Chicago, IL
JPMorgan Chase · Chicago, IL, United States, US

Trading Research/Transaction Cost Analyst
Northern Trust · Chicago, IL
ZS Associatesについて

ZS Associates
BootstrappedZS Associates is a management consulting and professional services firm focusing on consulting, software, and technology. Headquartered in Evanston, Illinois, it provides healthcare, private equity, and technology services.
10,001+
従業員数
Evanston
本社所在地
レビュー
4.4
10件のレビュー
ワークライフバランス
3.2
報酬
4.1
企業文化
4.5
キャリア
4.2
経営陣
4.0
78%
友人に勧める
良い点
Supportive and approachable management
Great work culture and collaborative colleagues
Good training and development opportunities
改善点
Long hours and heavy workload during projects
High performance pressure and expectations
Fast-paced competitive environment
給与レンジ
1,725件のデータ
Junior/L3
Mid/L4
Senior/L5
Junior/L3 · Business Technology Solutions Associate
132件のレポート
$152,505
年収総額
基本給
$137,467
ストック
-
ボーナス
$15,038
$115,393
$204,675
面接体験
2件の面接
難易度
3.5
/ 5
期間
14-28週間
体験
ポジティブ 0%
普通 50%
ネガティブ 50%
面接プロセス
1
Application Review
2
HR Screen
3
Technical/Case Interview
4
Panel Interview
5
Offer
よくある質問
Technical Knowledge
Case Study
Behavioral/STAR
Past Experience
Problem Solving
ニュース&話題
ZS Associates Expands to 28,000 SQFT Across Two Bellevue CBD Locations - The Registry Pacific Northwest Real Estate
The Registry Pacific Northwest Real Estate
News
·
2w ago
Insights at Scale With Agentic AI: How AI Ready Data is Transforming Commercial Life Sciences - Databricks
Databricks
News
·
3w ago
ZS Associates Data Engineer Interiview
Hi guys I have an interview set up for Business Technology Solutions Associate Consultant R&D for Data Engineer role. If anyone appeared for interview recently or currently working there can tell about the interview experience, I would really appreciate it. Thanks
·
3w ago
·
19
·
11
GLIM Chennai (PGPM) – Honest Review for Future Aspirants
Hello aspirants, Many of you must be receiving **offer letters or interview calls for Great Lakes Institute of Management, Chennai (PGPM)**. I thought it would be useful to share an **honest ground-level perspective from someone currently in the program** so you can make a more informed decision. Sorry in advance if this becomes a long post, but I am sure this will helps if you stick till end. # 1. Who should come to GLIM (PGPM) In my opinion, PGPM at GLIM makes the most sense for the follo
·
5w ago
·
14
·
37