Назад
Company hidden
10 дней назад

TPRM Analyst (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
TPRM Analyst (Cybersecurity): Running vendor intake, risk tiering, due diligence assessments, and ongoing monitoring for suppliers with access to enterprise systems, data, or facilities with an accent on security questionnaires, risk documentation, and cross-functional coordination. Focus on reducing the unassessed vendor backlog, integrating risk workflows with procurement, identifying material findings, and maintaining audit-ready assessment records.

Location: Dallas, TX, United States

Company

hirify.global is an independent distributor of life, health, and wealth insurance products with a strong insurtech focus.

What you will do

  • Run vendor intake, inherent risk tiering, and due diligence assessments on the enterprise third-party risk platform.
  • Reduce the backlog of unassessed suppliers and establish ongoing monitoring and periodic reassessment based on vendor tier.
  • Process security questionnaires to closure within service-level targets and coordinate documentation with vendors and internal stakeholders.
  • Partner with Cybersecurity, Procurement, Contracting, Legal, and business units on technical reviews, risk terms, sanctions screening, and flagged results.
  • Support integration between the third-party risk platform and procurement systems, including vendor populations added through acquisitions.
  • Feed findings into the enterprise risk register and maintain audit-ready assessment documentation.

Requirements

  • Bachelor’s degree in Business, Risk Management, Information Systems, Cybersecurity, or a related field.
  • 1–4 years of experience in third-party risk, vendor management, compliance, or security governance, risk, and compliance; internship experience is considered.
  • Familiarity with vendor assessment frameworks and security questionnaire methodologies.
  • Understanding of how vendor access to systems, data, or facilities creates organizational risk.
  • Strong analytical, organizational, written, and verbal communication skills, including external vendor interaction.
  • Proficiency in Microsoft Office Suite and strong Excel capability.

Nice to have

  • Experience with Whistic, Archer, ServiceNow, or a similar third-party risk platform.
  • CTPRP, CRISC, or a similar professional certification.
  • Experience in insurance, financial services, or another regulated industry.
  • Familiarity with SOC 2 reports, NIST, ISO 27001, or HITRUST.
  • Experience with procurement or contract management systems and sanctions or denied-party screening.

Culture & Benefits

  • Competitive compensation package with benefits for employees and their families.
  • Career development opportunities in a hyper-growth insurtech environment.
  • Family-like workplace culture with a focus on employee support and professional growth.
  • Equal opportunity employer with reasonable accommodations for qualified individuals with disabilities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →