Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Third Party Risk Management Lead (TPRM/SaaS Security): Building and operating Asana’s third-party risk management program, including vendor due diligence, risk tiering, monitoring, remediation, and contract security reviews with an accent on scalable governance and compliance. Focus on assessing high-risk vendors, managing remediation and risk acceptance, reporting program health, and coordinating risk decisions across global teams.
Location: Vancouver office with an office-centric hybrid schedule; standard in-office days are Monday, Tuesday, and Thursday. Work from home is generally available on Wednesdays, while Friday eligibility depends on the role and collaborating teams.
Salary: CAD 123,000–140,000 annual base salary, plus potential equity, incentives, and benefits.
Company
Asana provides a collaboration platform used by millions of teams worldwide and combines human and AI collaboration capabilities.
What you will do
- Own, scale, and continuously improve the third-party risk management program, including risk tiering, assessment workflows, and governance.
- Lead vendor security due diligence by reviewing SOC 2 reports, ISO 27001 certifications, SIG and CAIQ questionnaires, penetration test summaries, and related documentation.
- Track assessment findings, coordinate remediation with vendors and internal stakeholders, and facilitate formal risk acceptance.
- Develop continuous monitoring for critical and high-risk vendors, including reassessments, breach notifications, security posture updates, and vendor risk inventory maintenance.
- Review and negotiate security provisions in vendor contracts, data processing addenda, and subprocessor agreements with Legal and Privacy.
- Create metrics and reporting for senior leadership, and provide evidence for SOC 2, ISO 27001, compliance, and customer audits while coordinating across global time zones.
Requirements
- 5+ years of experience in third-party risk management, vendor risk assessment, or a related information security discipline.
- Strong knowledge of TPRM frameworks and standards, including SIG, CAIQ, NIST SP 800-161, ISO 27001, and SOC 2.
- Experience conducting vendor security assessments and reviewing audit reports, certifications, penetration test summaries, and other security documentation.
- Understanding of security principles, cloud environments, data privacy, and compliance standards relevant to B2B SaaS organizations.
- Ability to build scalable risk management processes, develop effectiveness metrics, and communicate technical risk findings to technical and non-technical audiences.
- Experience collaborating with Procurement, Legal, Privacy, and Engineering teams.
Nice to have
- Curiosity about AI tools and emerging technologies, with willingness to use them to improve productivity, collaboration, or decision-making.
Culture & Benefits
- Office-centric hybrid work model with a global workforce and 13+ offices.
- Mental health, wellness, and fitness benefits.
- Career coaching and professional support.
- Inclusive family-building benefits.
- Long-term savings or retirement plans.
- In-office culinary options and other benefits that may vary by country and local regulations.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
9 дней назад
Senior GRC Analyst
120 000 - 150 000$
10 дней назад
Security & Compliance Manager (GRC/SOX)
130 000 - 150 000CAD
8 дней назад
Principal Technical Information Security Specialist (Cybersecurity)
13 дней назад
Technical Change Risk Manager
139 000 - 164 000CAD
CrowdStrike
9 дней назад
Readiness Services Consultant (Cybersecurity)
90 000 - 135 000CAD
10 дней назад
Solutions Consultant 1 (Cybersecurity)
181 600 - 249 700$