JobRaahGet matched free

Jobs

Lead Analyst, Security Strategy & Assurance

outsystems · Portugal - Remote · Remote

Posted Sep 8, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

There are NO limits to your career: come shape the future and be part of a truly unique global culture at OutSystems! About This Role If you succeed at the intersection of risk, compliance, and strategic impact, this role offers a unique opportunity to define and lead two of the most critical programs within OutSystems’ Security function. As a Lead Analyst on the Security Strategy and Assurance team, you will manage our Third Party Risk Management (TPRM) program and guide enterprise risk activities that directly shape how OutSystems manages risk across its vendor ecosystem and broader business. This is a lead role, meaning you will operate with significant autonomy, define the scope and approach for complex, cross-functional initiatives, and serve as the go-to expert in your domain. You will design solutions to close gaps between current practices and desired outcomes, build lasting stakeholder relationships, and mentor junior colleagues on the team. If you bring deep expertise in vendor risk and compliance, excel at breaking down ambiguous goals into actionable programs, and want to make a measurable impact on an organization’s security posture, we want to meet you. What You’ll Do Manage and Mature the Third Party Risk Management Program Define and lead OutSystems’ TPRM strategy, including risk tiering methodology, assessment frameworks, and ongoing monitoring cadences for critical and high-risk vendors. Lead end-to-end vendor risk assessments and design scalable processes that can grow with the business. Proactively identify gaps between current TPRM practices and industry standards, and build solutions to close them. Partner with Digital, Procurement, Legal, and Engineering to embed risk requirements into vendor selection and contracting, influencing how partner teams operate. Maintain the vendor risk inventory, track remediation of identified issues, and report status to leadership with clarity and consistency. Monitor the threat and regulatory landscape for developments that affect the third-party risk surface. Lead Enterprise Risk Activities Manage and evolve the enterprise risk register for the Security division, ensuring risks are consistently identified, assessed, and treated across business units. Design and facilitate risk workshops with functional and business leaders to surface emerging risks and validate control effectiveness. Develop key risk indicators (KRIs) and produce executive-level risk reporting, including dashboards and trend analyses, that connect security posture to business outcomes. Integrate risk management into business planning cycles and cross-functional initiatives, ensuring security considerations are embedded early. Guide Compliance Strategy and Audit Readiness Serve as a senior contributor to compliance programs supporting certifications such as SOC 2, ISO 27001, PCI, HIPAA, and regional regulatory frameworks, elevating the work beyond execution to program oversight and continuous…