LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
Forgot password?
Don't have an account?
or
Join Canary Wharfian
By signing up, you agree to our Terms & Conditions and Privacy Policy.
or

Information Security Risk Specialist

ExperiencedNo visa sponsorship
Millennium logo

at Millennium

Hedge Funds

Posted 4 days ago

No clicks

**Information Security Risk Specialist** at Millennium mitigates third-party risks across global trading. Key responsibilities include conducting security risk assessments of vendors, drafting reports, driving remediation, and enhancing risk programs. Key skills sought are 5+ years of third-party risk management experience, proficiency in analyzing penetration tests, critical thinking, strong communication, and the ability to manage multiple assessments. Relevant certifications and financial services background preferred.

Compensation
Not specified

Currency: Not specified

City
Not specified
Country
Not specified

Full Job Description

Information Security Risk Specialist

About Millennium
Millennium is a global, diversified alternative investment firm, founded in 1989. Defined by evolution, innovation and focus, Millennium's mission is to deliver results for our investors.


Our people are empowered with both independence and support: the autonomy to pursue ideas with conviction and the backing of a global network committed to collaboration, disciplined risk management and continuous learning. With opportunities to deepen expertise and accelerate development, talent at Millennium is equipped to adapt, evolve and build lasting impact over time. Discover how transformative growth accelerates impact.


Meet the Team
Technology is core to the health and growth of our business. The firm's active, multi-manager model demands flexible, scalable technology and advanced proprietary systems, including the development of the next generation of analytical and trading capabilities. Within that environment, Millennium's Information Security team protects the firm's people, data, and technology across a complex, fast-moving global trading landscape, partnering closely with technology, trading, and business stakeholders to embed security into every aspect of our global operations. As the firm accelerates its use of artificial intelligence, the team is equally focused on applying AI in innovative, entrepreneurial ways to strengthen our own defenses. We are a growing organization that combines deep technical expertise with pragmatic risk management to keep pace with the speed and scale of the firm's business. The Third-Party Risk Management team within Information Security assesses and monitors the security posture of the vendors, counterparties, and service providers the firm relies on, keeping third-party risk within the firm's risk appetite, including risk arising from vendors' use of AI and the firm's own AI-enabled third-party integrations.


What You'll Do
Perform security risk assessments of prospective and existing vendors, covering questionnaire review, evidence validation, technical discussions, and identification of fourth-party and subprocessor dependencies
Assess the materiality and business impact of findings, identify compensating controls, and present recommendations and residual risk for remediation or risk acceptance
Draft clear, decision-ready risk assessment reports and maintain the third-party risk inventory and assessment records
Communicate findings and implementation requirements to technical teams, business stakeholders, and senior leaders
Track and drive remediation of security gaps and implementation requirements identified during assessments
Partner with vendor management, procurement, legal, and business teams to embed security requirements into vendor contracts and onboarding
Monitor security incidents and adverse news affecting existing vendors, engaging them directly to assess impact, root cause, and corrective measures
Strengthen the program through improvements to methodology, questionnaires, monitoring, reporting, quality assurance, and automation


What You Bring
Experience conducting vendor and third-party security risk assessments, including familiarity with common security frameworks, standards, and assessment questionnaires (e.g., NIST CSF, SOC 2, ISO 27001, CIS Controls, SIG, CAIQ); 5+ years of hands-on third-party risk management experience preferred
Ability to analyze penetration-test reports and architecture and data-flow diagrams to assess vulnerability severity, connectivity, trust boundaries, and associated security risks
Strong critical thinking and risk judgment, with the ability to weigh materiality, business impact, and compensating controls
Excellent written and verbal communication skills, with the ability to translate technical issues into risk and business impact for deeply technical teams and senior executive stakeholders alike
Ability to manage multiple assessments and deadlines concurrently, work independently, escalate appropriately, and operate effectively in a fast-paced, high-stakes environment
Bachelor's degree or higher in Computer Science, Computer Engineering, Cybersecurity/Information Security, or a related field, or commensurate work experience; relevant certifications such as CTPRP, CTPRA, CISA, or CISSP preferred
Preferred: strong understanding of technology fundamentals across on-premises and cloud infrastructure, with hands-on experience spanning design, deployment, and operations, plus working proficiency across Windows, Linux, and macOS environments
Preferred: experience with the secure use, deployment, and governance of AI models, tools, and supporting infrastructure such as GPUs and inferencing workloads; familiarity with TPRM platforms and reporting/automation tooling (e.g., Python, Excel/VBA); and experience in financial services, particularly hedge funds or other buy-side firms, or another highly regulated industry

Information Security Risk Specialist

Compensation

Not specified

City: Not specified

Country: Not specified

Millennium logo
Hedge Funds

4 days ago

No clicks

at Millennium

ExperiencedNo visa sponsorship

**Information Security Risk Specialist** at Millennium mitigates third-party risks across global trading. Key responsibilities include conducting security risk assessments of vendors, drafting reports, driving remediation, and enhancing risk programs. Key skills sought are 5+ years of third-party risk management experience, proficiency in analyzing penetration tests, critical thinking, strong communication, and the ability to manage multiple assessments. Relevant certifications and financial services background preferred.

Full Job Description

Information Security Risk Specialist

About Millennium
Millennium is a global, diversified alternative investment firm, founded in 1989. Defined by evolution, innovation and focus, Millennium's mission is to deliver results for our investors.


Our people are empowered with both independence and support: the autonomy to pursue ideas with conviction and the backing of a global network committed to collaboration, disciplined risk management and continuous learning. With opportunities to deepen expertise and accelerate development, talent at Millennium is equipped to adapt, evolve and build lasting impact over time. Discover how transformative growth accelerates impact.


Meet the Team
Technology is core to the health and growth of our business. The firm's active, multi-manager model demands flexible, scalable technology and advanced proprietary systems, including the development of the next generation of analytical and trading capabilities. Within that environment, Millennium's Information Security team protects the firm's people, data, and technology across a complex, fast-moving global trading landscape, partnering closely with technology, trading, and business stakeholders to embed security into every aspect of our global operations. As the firm accelerates its use of artificial intelligence, the team is equally focused on applying AI in innovative, entrepreneurial ways to strengthen our own defenses. We are a growing organization that combines deep technical expertise with pragmatic risk management to keep pace with the speed and scale of the firm's business. The Third-Party Risk Management team within Information Security assesses and monitors the security posture of the vendors, counterparties, and service providers the firm relies on, keeping third-party risk within the firm's risk appetite, including risk arising from vendors' use of AI and the firm's own AI-enabled third-party integrations.


What You'll Do
Perform security risk assessments of prospective and existing vendors, covering questionnaire review, evidence validation, technical discussions, and identification of fourth-party and subprocessor dependencies
Assess the materiality and business impact of findings, identify compensating controls, and present recommendations and residual risk for remediation or risk acceptance
Draft clear, decision-ready risk assessment reports and maintain the third-party risk inventory and assessment records
Communicate findings and implementation requirements to technical teams, business stakeholders, and senior leaders
Track and drive remediation of security gaps and implementation requirements identified during assessments
Partner with vendor management, procurement, legal, and business teams to embed security requirements into vendor contracts and onboarding
Monitor security incidents and adverse news affecting existing vendors, engaging them directly to assess impact, root cause, and corrective measures
Strengthen the program through improvements to methodology, questionnaires, monitoring, reporting, quality assurance, and automation


What You Bring
Experience conducting vendor and third-party security risk assessments, including familiarity with common security frameworks, standards, and assessment questionnaires (e.g., NIST CSF, SOC 2, ISO 27001, CIS Controls, SIG, CAIQ); 5+ years of hands-on third-party risk management experience preferred
Ability to analyze penetration-test reports and architecture and data-flow diagrams to assess vulnerability severity, connectivity, trust boundaries, and associated security risks
Strong critical thinking and risk judgment, with the ability to weigh materiality, business impact, and compensating controls
Excellent written and verbal communication skills, with the ability to translate technical issues into risk and business impact for deeply technical teams and senior executive stakeholders alike
Ability to manage multiple assessments and deadlines concurrently, work independently, escalate appropriately, and operate effectively in a fast-paced, high-stakes environment
Bachelor's degree or higher in Computer Science, Computer Engineering, Cybersecurity/Information Security, or a related field, or commensurate work experience; relevant certifications such as CTPRP, CTPRA, CISA, or CISSP preferred
Preferred: strong understanding of technology fundamentals across on-premises and cloud infrastructure, with hands-on experience spanning design, deployment, and operations, plus working proficiency across Windows, Linux, and macOS environments
Preferred: experience with the secure use, deployment, and governance of AI models, tools, and supporting infrastructure such as GPUs and inferencing workloads; familiarity with TPRM platforms and reporting/automation tooling (e.g., Python, Excel/VBA); and experience in financial services, particularly hedge funds or other buy-side firms, or another highly regulated industry