GRC Analyst, Third-Party Risk Management

New
S
SamsaraInformation Security
United KingdomFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
2-4 years
Required Skills
SalesforceGoogle WorkspaceSlack

Requirements

  • 2-4 years of experience in the governance, risk, and compliance space.
  • Experience implementing or maintaining vendor-risk programs.
  • Experience performing security and maturity assessments.
  • Experience creating or maintaining risk registers, compliance inventories, and control mappings.
  • Experience coordinating with external auditors, engineering, business stakeholders, and security operations.
  • Experience conducting vendor risk assessments including reviewing certifications, penetration tests, and policies.
  • Strong understanding of vendor integration risks and permission scoping across SaaS platforms like Slack, Google Workspace, and Salesforce.
  • Ability to translate complex technical findings into business risks for non-technical stakeholders.
  • Experience with NIST Cybersecurity Framework, SOC 2, or ISO 27001 is a plus.
  • Experience creating workflows through automation and AI assistance is a plus.
  • Experience with GRC and procurement platforms such as Zip and Vanta is a plus.

Responsibilities

  • Provide programmatic updates and communicate technical and third-party risk to Information Security leadership.
  • Drive automation and efficiency in the TPRM program using tools like Zip and Vanta.
  • Partner with Procurement, Legal, and Privacy teams to identify, document, and mitigate vendor risks.
  • Collaborate across business teams to define vendor use cases and data flows.
  • Embed Samsara's cultural principles as the company scales globally.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now