GRC Analyst, Third-Party Risk Management
New
S
SamsaraInformation Security
United KingdomFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 2-4 years
- Required Skills
- SalesforceGoogle WorkspaceSlack
Requirements
- 2-4 years of experience in the governance, risk, and compliance space.
- Experience implementing or maintaining vendor-risk programs.
- Experience performing security and maturity assessments.
- Experience creating or maintaining risk registers, compliance inventories, and control mappings.
- Experience coordinating with external auditors, engineering, business stakeholders, and security operations.
- Experience conducting vendor risk assessments including reviewing certifications, penetration tests, and policies.
- Strong understanding of vendor integration risks and permission scoping across SaaS platforms like Slack, Google Workspace, and Salesforce.
- Ability to translate complex technical findings into business risks for non-technical stakeholders.
- Experience with NIST Cybersecurity Framework, SOC 2, or ISO 27001 is a plus.
- Experience creating workflows through automation and AI assistance is a plus.
- Experience with GRC and procurement platforms such as Zip and Vanta is a plus.
Responsibilities
- Provide programmatic updates and communicate technical and third-party risk to Information Security leadership.
- Drive automation and efficiency in the TPRM program using tools like Zip and Vanta.
- Partner with Procurement, Legal, and Privacy teams to identify, document, and mitigate vendor risks.
- Collaborate across business teams to define vendor use cases and data flows.
- Embed Samsara's cultural principles as the company scales globally.
View Full Description & ApplyYou'll be redirected to the employer's site