11 дней назад
TPRM Analyst (Cybersecurity)
75 - 90$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
TPRM Analyst (Cybersecurity): Executing high-volume third-party security assessments, reviewing control evidence, documenting findings, and tracking remediation with an accent on vendor risk tiering, audit-ready records, and data quality. Focus on validating policies and security reports, maintaining risk registers, resolving inconsistencies, and driving vendors and internal stakeholders through remediation closure.
Location: Remote within the United States
Salary: $75–$90 per hour
Company
EVOCS is an IT consulting firm that delivers technology solutions, advisory expertise, and practical services to help organizations improve performance and achieve business objectives.
What you will do
- Conduct high-volume vendor security assessments and third-party reviews.
- Issue questionnaires, manage evidence requests, and validate submitted materials.
- Review policies, SOC 2 reports, ISO 27001 certificates, penetration test summaries, and other control evidence.
- Identify gaps, assign risk ratings, and document findings clearly.
- Build and track remediation plans through closure with vendors and internal stakeholders.
- Maintain assessment schedules, audit-ready documentation, risk-register accuracy, and status reporting.
Requirements
- 5+ years of experience in cybersecurity, audit, compliance, risk, or vendor management, including at least 3 years conducting vendor security assessments or third-party reviews.
- Hands-on experience with security questionnaires, evidence requests, control reviews, remediation plans, and risk registers.
- Strong written documentation, risk communication, data quality, and attention to consistency.
- Ability to manage concurrent reviews, follow up independently, and drive remediation items to closure.
- Working familiarity with NIST CSF, NIST 800-53, ISO 27001/27002, or CIS frameworks.
- Strong communication skills for working with vendors, procurement, legal, and internal stakeholders.
Nice to have
- Security+, CTPRP, CISA, CRISC, CISM, or ISO 27001 Lead Auditor certification.
- Experience with ProcessUnity, ServiceNow GRC, or Archer.
- Experience with SecurityScorecard, BitSight, RiskRecon, or Black Kite.
- Experience assessing cloud providers, MSPs, or technology vendors.
- Experience managing assessment queues against SLAs in regulated environments.
Culture & Benefits
- Remote work within the United States.
- Customer-centric approach focused on trust and mutual success.
- Emphasis on innovation, quality, integrity, transparency, and data-driven decision making.
- Posting remains active until the position is filled, with extensions in three-day increments.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
Senior TPRM Analyst
90 - 105$
9 дней назад
Sr. Security Compliance Analyst - PCI DSS & SOC 2 (East Coast)
119 078 - 174 648$
14 часов назад
Vulnerability & Cloud Security Program Manager
180 000 - 220 000$
14 дней назад
Senior Security Engineer, IAM (Cybersecurity)
130 000 - 195 000$
13 дней назад
Advanced Security Engineer (IAM)
104 000 - 156 000$