Third-Party Risk Management Analyst
New
S
SamsaraBusiness Technology
Remote - US, except the San Francisco Bay Metro Area, NYC Metro Area, and Washington, D.C. Metro Area.Full-TimeMiddle
Salary$110,670 — $167,400 USD
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years
- Required Skills
- Scripting
Requirements
- 5+ years of experience in third-party/vendor risk management, GRC, or information security compliance.
- Hands-on experience running vendor security assessments and administering a vendor tiering program.
- Experience using automation, scripting, or low-code workflows to scale a vendor risk program.
- Experience partnering with Legal and Procurement on vendor contract security and privacy terms such as Security addendums and DPAs.
- Familiarity with risk assessment frameworks such as NIST CSF, ISO 27001, or SOC 2.
- Experience with a GRC or vendor risk management platform like Vanta, ServiceNow, OneTrust, or Archer.
- Relevant certification such as CTPRP, CISA, CRISC, or CISSP is preferred.
- Must reside in the US, excluding San Francisco Bay Area, New York City, and Washington, D.C. metro areas.
Responsibilities
- Lead end-to-end third-party security risk assessments using qualitative and quantitative methods.
- Oversee vendor reassessment cadence and track remediation of security gaps throughout the vendor lifecycle.
- Partner with Legal and Procurement to review vendor contracts and onboarding requests via Zip.
- Escalate unresolved vendor risk to Security leadership, legal, procurement, and business owners.
- Support internal and external audits of the vendor risk program including ISO, SOC, and FedRAMP.
- Develop metrics, dashboards, and reporting for Security leadership regarding third-party risk posture.
- Implement automation and AI-enabled tools into vendor risk workflows for triage and contract review.
- Mentor junior TPRM resources to support program growth and innovation.
View Full Description & ApplyYou'll be redirected to the employer's site