Skip to content

Open nowPosted 27 days ago

Third-Party Risk Management 1

Millennium70 open roles

Pay
$175,000 – $250,000 a year
Where
New York, New York, United States of America
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowThird-Party Risk Management 1Millennium · New York, New York, United States of America
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Millennium's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Millennium postings stay open a median of 32 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted 27 days ago

Millennium median: 32 days open

The posting

Third-Party Risk Management 1

About Millennium Millennium is a global, diversified alternative investment firm, founded in 1989. Defined by evolution, innovation and focus, Millennium’s mission is to deliver results for our investors.

Our people are empowered with both independence and support: the autonomy to pursue ideas with conviction and the backing of a global network committed to collaboration, disciplined risk management and continuous learning. With opportunities to deepen expertise and accelerate development, talent at Millennium is equipped to adapt, evolve and build lasting impact over time. Discover how transformative growth accelerates impact.

Meet the Team Information Technology is core to the health and growth of Millennium’s active, multi-manager business model, which demands flexible, scalable technology and advanced proprietary systems. The Information Security team protects the firm’s people, data, and technology across a complex, fast-moving global trading environment, partnering with technology, trading, and business stakeholders to embed security throughout global operations. The team combines deep technical expertise with pragmatic risk management and is advancing innovative applications of artificial intelligence to strengthen the firm’s defenses.

What You'll Do

  • Conduct security risk assessments for prospective and existing vendors, including questionnaire reviews, evidence validation, technical discussions, and identification of fourth-party and subprocessor dependencies.
  • Evaluate the materiality and business impact of findings, identify compensating controls, and recommend remediation or risk acceptance based on residual risk.
  • Prepare clear risk assessment reports and maintain accurate third-party risk inventory and assessment records.
  • Communicate findings, recommendations, and implementation requirements to technical teams, business stakeholders, and senior leaders.
  • Track remediation of identified security gaps and follow up on implementation requirements.
  • Partner with vendor management, procurement, legal, and business teams to embed security requirements into vendor contracts and onboarding processes.
  • Monitor existing vendors for security incidents and adverse news, engaging vendors to assess impact, root cause, and corrective actions.
  • Strengthen the third-party risk management program through improvements to methodology, questionnaires, monitoring, reporting, quality assurance, and automation.

What You Bring

  • Experience conducting vendor or third-party security risk assessments, including familiarity with NIST CSF, SOC 2, ISO 27001, CIS Controls, SIG, and CAIQ.
  • Ability to analyze penetration-test reports and architecture or data-flow diagrams to assess vulnerability severity, connectivity, trust boundaries, and associated security risks.
  • Strong critical thinking and risk judgment, with the ability to assess materiality, business impact, and compensating controls.
  • Excellent written and verbal communication skills, with the ability to translate technical issues into clear risk and business implications for stakeholders.
  • Ability to manage multiple assessments and deadlines effectively in a fast-paced, high-stakes environment.
  • Bachelor’s degree or higher in Computer Science, Computer Engineering, Cybersecurity, Information Security, or a related field, or commensurate work experience.
  • Five or more years of hands-on third-party risk management experience: relevant security certifications, such as CTPRP, CTPRA, CISA, or CISSP, are preferred.
  • Experience with the secure use, deployment, and governance of AI models, tools, and supporting infrastructure, including GPUs and inferencing workloads; familiarity with on-premises and cloud infrastructure, TPRM platforms, reporting and automation tools, and Windows, Linux, and macOS environments is preferred.

Salary Range Millennium offers a total compensation package which includes a base salary, discretionary performance bonus, and comprehensive benefits. The estimated base salary range for this position is $175,000 to $250,000, which is specific to New York and may change in the future. When finalizing an offer, we take into consideration an individual’s experience level and the qualifications they bring to the role to formulate a competitive total compensation package

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Millennium's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Millennium's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Millennium's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.