About this role
Our vision is to transform how the world uses information to enrich life for all .
Micron Technology is a world leader in innovating memory and storage solutions that accelerate the transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever.
The Third‑Party Cybersecurity Risk Management (TPCRM) Staff Analyst is a senior individual contributor responsible for shaping, governing, and continuously improving information risk management related to external suppliers. The analyst leads complex and ambiguous third‑party cybersecurity risk issues, advises senior business and security stakeholders, drives program maturity, and supports enterprise‑level decision‑making across Information Security, Privacy, Regulatory Compliance, Procurement, Legal, and Governance.
Responsibilities
- Serve as a staff-level subject matter expert for third‑party cybersecurity risk management, including enterprise supplier risk governance, regulatory alignment, and assessment quality.
- Lead highly complex third‑party risk assessments involving critical suppliers, high‑risk services, sensitive data, manufacturing dependencies, or material business impact.
- Shape assessment methodology, risk criteria, evidence expectations, and control evaluation practices to improve consistency, scalability, and defensibility of TPCRM outcomes.
- Perform advanced gap analysis against frameworks and standards such as ISO 27001, NIST, SOX, TISAX, and GDPR, and advise stakeholders on enterprise‑level remediation priorities.
- Lead risk treatment strategy for material supplier findings, including mitigation planning, risk acceptance recommendations, supplier escalations, evidence validation, and closure decisions.
- Develop, revise, and mature third‑party risk management policies, standards, processes, guidelines, and runbooks through formal governance and change management.
- Lead third‑party governance activities, including onsite supplier audits, executive risk reporting, cross‑functional working groups, and escalation of material supplier risks.
- Translate cybersecurity, regulatory, supplier, and threat intelligence insights into actionable risk themes, program enhancements, and supplier risk mitigation strategies.
- Interpret risk tolerance, contractual obligations, control tradeoffs, supplier criticality, and business impact to support informed risk acceptance, mitigation, avoidance, or transfer decisions.
- Partner with procurement, legal, information security, business, privacy, resilience, and vendor management teams to embed TPCRM expectations throughout the supplier lifecycle.
- Advise business‑led initiatives on third‑party cyber risk, due diligence requirements, standards compliance, supplier engagement, and governance escalation paths.
- Mentor senior and junior analysts, lead process improvement initiatives, advance automation and reporting maturity, and help establish consistent TPCRM execution across teams and regions.
Education
- Bachelor’s Degree in Computer Science/Management Information Systems/Business Administration. Master’s degree is preferred.
- Related field of study or equivalent combination of education and experience.
Experience :
Analyzing and applying Information Security, Cyber Risk Management, Third‑Party Risk Management, and Privacy practices for a minimum of seven years of experience, with demonstrated ability to lead complex supplier risk issues, influence cross‑functional stakeholders, and improve risk management practices in the following areas:
- Advanced third‑party / vendor risk management, supplier assessments, external assurance programs, cybersecurity governance, or enterprise risk functions.
- Strong IT business process knowledge, supplier lifecycle understanding, business acumen, and ability to connect supplier risk to operational and enterprise impact.
- Experience influencing procurement, legal, vendor management, privacy, information security, business, and executive stakeholders on risk decisions and remediation priorities.
- Experience working with and improving third-party risk management tools such as ServiceNow, Optro, Archer, AuditBoard, SecurityScorecard, BitSight, or equivalent platforms.
- Experience developing risk analytics, dashboards, scorecards, executive reporting, metrics, and narratives that communicate third-party risk posture and program maturity.
- Advanced understanding of threat, vulnerability, business continuity, supplier security, incident response, and third-party risk assessment methodologies.
- Knowledge of national and international regulatory and security frameworks including NIST Cybersecurity Framework, ISO standards, SOX, GDPR, HIPAA, PCI DSS, TISAX, and related supplier security expectations.
- Experience leading risk treatment decisions, remediation governance, supplier escalations, executive briefings, onsite supplier assessments, or high-risk supplier reviews.
- CRISC, CISA, CISSP, ISO 27001 Lead Auditor, CISM, or equivalent certifications are preferred.
- Preferred skills in SharePoint, Teams, reporting tools, workflow platforms, AI-enabled automation, and other collaboration or knowledge management platforms.
- Demonstrated ability to mature cybersecurity risk practices, establish reusable processes, and improve outcomes across third-party ecosystems and high-risk supplier relationships.
Soft skills requirements
- Ability to define, communicate, and influence enterprise third‑party cybersecurity risk decisions in business‑relevant language.
- Excellent verbal and written communication skills, including the ability to craft and deliver concise executive-level communications, risk narratives, and decision briefs.
- Ability to lead confidently through ambiguity, competing priorities, sensitive supplier issues, and rapidly changing risk conditions.
- Ability to communicate cybersecurity and third‑party risk concepts clearly to technical, non‑technical, supplier, and executive audiences.
- Strong problem‑solving, analytical, facilitation, negotiation, and risk‑based decision‑making skills.
- Ability to mentor analysts, build stakeholder trust, influence without direct authority, and drive consistent execution across cross‑functional and regional teams.
About Micron Technology, Inc.
We are an industry leader in innovative memory and storage solutions transforming how the world uses information to enrich life for all . With a relentless focus on our customers, technology leadership, and manufacturing and operational excellence, Micron delivers a rich portfolio of high-performance DRAM, NAND, and NOR memory and storage products through our Micron® and Crucial® brands. Every day, the innovations that our people create fuel the data economy, enabling advances in artificial intelligence and 5G applications that unleash opportunities — from the data center to the intelligent edge and across the client and mobile user experience.
To learn more, please visit micron.com/careers
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
To request assistance with the application process and/or for reasonable accommodations, please contact [email protected]
Micron Prohibits the use of child labor and complies with all applicable laws, rules, regulations, and other international and industry labor standards.
Micron does not charge candidates any recruitment fees or unlawfully collect any other payment from candidates as consideration for their employment with Micron.
AI alert : Candidates are encouraged to use AI tools to enhance their resume and/or application materials. However, all information provided must be accurate and reflect the candidate's true skills and experiences. Misuse of AI to fabricate or misrepresent qualifications will result in immediate disqualification.
Fraud alert: Micron advises job seekers to be cautious of unsolicited job offers and to verify the authenticity of any communication claiming to be from Micron by checking the official Micron careers website in the About Micron Technology, Inc.