Security Analyst: Third Party & Trust Center
AI in this role
Key Responsibilities
Third-Party Risk Management
- Assess third parties and vendors globally for compliance with contractual agreements, security requirements, industry best practices, and regulatory obligations.
- Gather all relevant information for each engagement: type of engagement, data in scope, data flows, connectivity to internal networks, and intended data use; and evaluate impact to security objectives.
- Raise information requests where vendor or business responses are incomplete, and maintain accurate, comprehensive assessment records in an online GRC/TPRM platform (e.g., OneTrust).
- Proactively identify gaps or conflicts in existing processes and drive remediation of control deficiencies identified during assessments.
- Monitor assessment timelines, vendor record expiry dates, and reassessment cadences to keep the third-party risk register current.
- Assess potential business changes (new engagements, scope changes, offboarding) for impact to third-party compliance obligations.
Trust Center & Customer Assurance
- Maintain the Elsevier’s Trust Center, curating and publishing customer-facing security documentation: certifications, policies, whitepapers, product details, and FAQs; to accelerate customer due diligence.
- Respond to inbound customer and prospect security questionnaires (e.g., SIG, CAIQ, custom RFP/RFI security sections), partnering with sales, legal, product owner(s), and security to deliver accurate, timely responses.
- Support internal and external audit inquiries related to third-party risk, Trust Center content, and customer due diligence requests.
- Serve as a trusted point of contact for customers and prospects seeking assurance on Elsevier’s security and compliance posture.
Governance & Stakeholder Engagement
- Build strong relationships with business partners (Legal, Procurement, Privacy, and Product teams) and vendors; facilitate continuous improvement aligned with operational processes.
- Contribute to the maturation of processes governing third-party risk, data classification, and data handling requirements.
- Manage day-to-day communication with stakeholders and vendors, escalating concerns, queries, or issues to security leadership as appropriate, including suggested service and process improvements.
- Support metrics, KPIs, and executive-level reporting on third-party risk posture and Trust Center engagement to support risk-based decision making.
Ideal Candidate Profile
Elsevier is looking for a candidate with information security and risk experience in a commercial environment, including:
- Basic technical knowledge across security domains, including infrastructure security and its impact on security operations, vulnerabilities, reporting, analytics, and monitoring.
- Working knowledge of security and privacy standards and audit frameworks such as ISO 27001/27017, ISO 27701/27018, HIPAA, PCI DSS, and NIST 800-53.
- Experience with GRC/TPRM and trust center tooling (e.g., OneTrust, SafeBase, Optro (formerly AuditBoard) or similar platforms).
- Ability to interpret data flow diagrams and evaluate data privacy and data protection implications of third-party engagements.
- Excellent communication skills: able to explain complex or detailed compliance requirements clearly and concisely at all levels of the business and to external customers, and to keep leadership updated on progress and escalate issues promptly.
- A ‘can-do’ attitude and enthusiasm that inspires others; well organized and efficient, with the ability to multi-task and meet tight deadlines.
- Ability to work effectively and supportively within a global, cross-functional team.
- Willingness to receive training, mentoring, and ongoing support.
- Ability to quickly learn and apply enterprise AI tools and technologies to support technical workflows and business objectives.
Qualifications
- Bachelor’s degree in Information Security, Computer Science, or a related field.
- 2 – 3 years of experience in information security compliance, third-party/vendor risk management, or IT audit.
- Experience assessing vendors against security and privacy control frameworks and managing large control sets.
- Experience handling inquiries from customer security questionnaires and maintaining a trust center.
- Fluency in English required.
- Preferred certifications: CISSP, CISA, CISM, Security+, or ISO 27001 Lead Auditor/Implementer.
We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.
We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1-855-833-5120.
Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.
Please read our Candidate Privacy Policy.
We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
USA Job Seekers:
How we rate this
Security Analyst: Third Party & Trust Center at RELX rates 32 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Get new cybersecurity jobs by email
One email a week with the new cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step