Назад
Company hidden
11 дней назад

Senior TPRM Analyst

90 - 105$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior TPRM Analyst (Third-Party Risk Management): Owning complex vendor risk assessments for cloud providers, managed service providers, and critical technology vendors with an accent on SOC 2 and ISO 27001 evidence review, fourth-party risk, and executive reporting. Focus on analyzing supply-chain dependencies, challenging control evidence, leading risk acceptance decisions, and improving TPRM governance.

Location: Remote in the United States

Salary: $90–$105 USD per hour

Company

hirify.global is an IT consulting firm that delivers technology solutions and practical expertise to improve client performance and support business objectives.

What you will do

  • Own end-to-end risk assessments for high-criticality third parties, including cloud providers, managed service providers, and critical technology vendors.
  • Review SOC 2 Type II reports, ISO 27001 certificates, control evidence, penetration test summaries, remediation plans, and security questionnaires.
  • Set inherent and residual risk ratings, define compensating controls, and track remediation commitments to closure.
  • Analyze fourth-party and supply-chain dependencies, vendor concentration risk, subcontractor locations, data residency, and geopolitical exposure.
  • Prepare executive-ready risk summaries, escalation memos, and risk acceptance recommendations.
  • Present risk trends and exceptions to governance forums, improve TPRM standards and playbooks, and mentor junior analysts.

Requirements

  • 7+ years of experience in cybersecurity, risk, audit, or compliance, including at least 5 years in third-party or vendor risk management.
  • Experience assessing cloud providers, managed service providers, and critical technology vendors.
  • Ability to interpret SOC 2 reports and ISO 27001 certifications, including scope carve-outs, qualified opinions, and control exceptions.
  • Experience with fourth-party and supply-chain risk, vendor concentration, criticality tiering, geopolitical exposure, and subcontractor dependencies.
  • Strong executive communication, escalation management, and risk acceptance skills.
  • Working knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and CIS control frameworks.

Nice to have

  • CTRP, CTPRA, CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor certification.
  • Experience with ProcessUnity, ServiceNow GRC, or Archer.
  • Experience with SecurityScorecard, BitSight, RiskRecon, or Black Kite.
  • Exposure to regulated environments and TPRM program design.

Culture & Benefits

  • Customer-centric, data-driven approach focused on trust and mutual success.
  • Emphasis on innovation, excellence, integrity, and transparency.
  • White-glove client service and tailored technology solutions.
  • Remote work arrangement for the US role.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →