Назад
7 дней назад

Third Party Risk Management Lead

123 000 - 140 000CAD
Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Third Party Risk Management Lead (TPRM/SaaS Security): Building and operating Asana’s third-party risk management program, including vendor due diligence, risk tiering, monitoring, remediation, and contract security reviews with an accent on scalable governance and compliance. Focus on assessing high-risk vendors, managing remediation and risk acceptance, reporting program health, and coordinating risk decisions across global teams.

Location: Vancouver office with an office-centric hybrid schedule; standard in-office days are Monday, Tuesday, and Thursday. Work from home is generally available on Wednesdays, while Friday eligibility depends on the role and collaborating teams.

Salary: CAD 123,000–140,000 annual base salary, plus potential equity, incentives, and benefits.

Company

Asana provides a collaboration platform used by millions of teams worldwide and combines human and AI collaboration capabilities.

What you will do

  • Own, scale, and continuously improve the third-party risk management program, including risk tiering, assessment workflows, and governance.
  • Lead vendor security due diligence by reviewing SOC 2 reports, ISO 27001 certifications, SIG and CAIQ questionnaires, penetration test summaries, and related documentation.
  • Track assessment findings, coordinate remediation with vendors and internal stakeholders, and facilitate formal risk acceptance.
  • Develop continuous monitoring for critical and high-risk vendors, including reassessments, breach notifications, security posture updates, and vendor risk inventory maintenance.
  • Review and negotiate security provisions in vendor contracts, data processing addenda, and subprocessor agreements with Legal and Privacy.
  • Create metrics and reporting for senior leadership, and provide evidence for SOC 2, ISO 27001, compliance, and customer audits while coordinating across global time zones.

Requirements

  • 5+ years of experience in third-party risk management, vendor risk assessment, or a related information security discipline.
  • Strong knowledge of TPRM frameworks and standards, including SIG, CAIQ, NIST SP 800-161, ISO 27001, and SOC 2.
  • Experience conducting vendor security assessments and reviewing audit reports, certifications, penetration test summaries, and other security documentation.
  • Understanding of security principles, cloud environments, data privacy, and compliance standards relevant to B2B SaaS organizations.
  • Ability to build scalable risk management processes, develop effectiveness metrics, and communicate technical risk findings to technical and non-technical audiences.
  • Experience collaborating with Procurement, Legal, Privacy, and Engineering teams.

Nice to have

  • Curiosity about AI tools and emerging technologies, with willingness to use them to improve productivity, collaboration, or decision-making.

Culture & Benefits

  • Office-centric hybrid work model with a global workforce and 13+ offices.
  • Mental health, wellness, and fitness benefits.
  • Career coaching and professional support.
  • Inclusive family-building benefits.
  • Long-term savings or retirement plans.
  • In-office culinary options and other benefits that may vary by country and local regulations.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →