Digital Third Party Cyber Risk Consultant - Technical Architect
Listed on 2026-03-01
-
IT/Tech
Cybersecurity, Information Security, Data Security, IT Consultant
Innovate here. And see your ideas come to life.
It’s an exciting time to work in tech at Edward Jones. We are making massive investments in emerging technologies to improve how we work with our clients and with each other. Relationships are the focus of our business model. And working in Technology here means using your skills to build, deliver and maintain the technologies that enable us to deepen and support those relationships.
The best part? We develop and create our own industry-leading solutions internally. And you can be a part of it. Working with emerging new technologies. Creating platforms, programs and experiences that change how we work together - and support our client-first focus. Changing the future of our firm, the industry and the advisor-client relationship.
Position Schedule: Full-Time
This job posting is anticipated to remain open for 30 days, from 19-Feb-2026. The posting may close early due to the volume of applicants.
Team OverviewThe TECH Digital 3rd party risk and security awareness organization is part of the Edward Jones overall TECH risk management program, which is designed to ensure that the company's information security systems and information assets are adequately protected. The overall TECH Cyber Risk Management Team works proactively with IS and business leaders to implement practices that meet Edward Jones defined policies and standards for information risk management.
WhatYou’ll Do
The Senior Risk and Controls Security Analyst, with an emphasis on cyber law, serves as a key liaison between the Cybersecurity, Legal, and Business units. This position is critical in identifying, evaluating, and mitigating information security risks while ensuring strict adherence to applicable federal and state laws, regulations, and industry standards. The ideal candidate will possess deep technical knowledge of cybersecurity principles and a strong understanding of the legal landscape surrounding data protection and privacy.
The associate is responsible for evaluating the security posture and compliance of external vendors to mitigate risks to an organization’s data and systems. This role involves assessment, monitoring, and remediation activities throughout the vendor’s lifecycle.
Regulatory Compliance and Legal Alignment: Monitor and interpret cybersecurity laws and regulations, translating them into actionable controls and policies. This role involves collaboration with legal teams on compliance issues and ensuring security documentation reflects current requirements.
Conduct Assessments: Perform in-depth information security risk assessments of third-party vendors, which may involve reviewing documentation, conducting interviews, and performing technical reviews of security controls (e.g., infrastructure security, access management, application security, physical security).
Identify and Escalate Risks: Identify security gaps or risks (e.g., vulnerabilities in software supply chain, non-compliance with standards) and effectively communicate these to internal stakeholders and vendor representatives to develop remediation strategies.
Reporting & Communication: Prepare and present reports on risk and compliance status to various stakeholders and contribute to cybersecurity awareness programs.
Ensure Compliance: Evaluate third parties against internal policies and external regulatory standards and frameworks such as NIST, ISO 27001, SOC 2, HIPAA, GDPR, and PCI-DSS.
Partner with Stakeholders: Collaborate with internal teams, including Legal, Procurement, Compliance, and business units, to ensure contract language reflects cyber requirements and to align risk management activities with business objectives.
Monitor Continuously: Oversee ongoing monitoring of critical and high-risk vendors using various risk intelligence tools and perform periodic reassessments to manage evolving threats
Edward Jones’s compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).