11 дней назад
Senior TPRM Analyst
90 - 105$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior TPRM Analyst (Third-Party Risk Management): Owning complex vendor risk assessments for cloud providers, managed service providers, and critical technology vendors with an accent on SOC 2 and ISO 27001 evidence review, fourth-party risk, and executive reporting. Focus on analyzing supply-chain dependencies, challenging control evidence, leading risk acceptance decisions, and improving TPRM governance.
Location: Remote in the United States
Salary: $90–$105 USD per hour
Company
is an IT consulting firm that delivers technology solutions and practical expertise to improve client performance and support business objectives.
What you will do
- Own end-to-end risk assessments for high-criticality third parties, including cloud providers, managed service providers, and critical technology vendors.
- Review SOC 2 Type II reports, ISO 27001 certificates, control evidence, penetration test summaries, remediation plans, and security questionnaires.
- Set inherent and residual risk ratings, define compensating controls, and track remediation commitments to closure.
- Analyze fourth-party and supply-chain dependencies, vendor concentration risk, subcontractor locations, data residency, and geopolitical exposure.
- Prepare executive-ready risk summaries, escalation memos, and risk acceptance recommendations.
- Present risk trends and exceptions to governance forums, improve TPRM standards and playbooks, and mentor junior analysts.
Requirements
- 7+ years of experience in cybersecurity, risk, audit, or compliance, including at least 5 years in third-party or vendor risk management.
- Experience assessing cloud providers, managed service providers, and critical technology vendors.
- Ability to interpret SOC 2 reports and ISO 27001 certifications, including scope carve-outs, qualified opinions, and control exceptions.
- Experience with fourth-party and supply-chain risk, vendor concentration, criticality tiering, geopolitical exposure, and subcontractor dependencies.
- Strong executive communication, escalation management, and risk acceptance skills.
- Working knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and CIS control frameworks.
Nice to have
- CTRP, CTPRA, CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor certification.
- Experience with ProcessUnity, ServiceNow GRC, or Archer.
- Experience with SecurityScorecard, BitSight, RiskRecon, or Black Kite.
- Exposure to regulated environments and TPRM program design.
Culture & Benefits
- Customer-centric, data-driven approach focused on trust and mutual success.
- Emphasis on innovation, excellence, integrity, and transparency.
- White-glove client service and tailored technology solutions.
- Remote work arrangement for the US role.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
TPRM Analyst (Cybersecurity)
75 - 90$
9 дней назад
Sr. Security Compliance Analyst - PCI DSS & SOC 2 (East Coast)
119 078 - 174 648$
14 дней назад
Senior Security Engineer, IAM (Cybersecurity)
130 000 - 195 000$
14 часов назад
Vulnerability & Cloud Security Program Manager
180 000 - 220 000$
13 дней назад
Advanced Security Engineer (IAM)
104 000 - 156 000$