Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
TPRM Technical Lead (ServiceNow/Cybersecurity): Designing and optimizing the vendor risk ecosystem, workflows, assessment lifecycle, and automation capabilities with an accent on ServiceNow architecture, AI-driven risk scoring, and third-party security controls. Focus on engineering scalable TPRM processes, managing assessment operations, integrating cross-functional security checks, and aligning technical standards with NIST, ISO 27001, SOC 2, and FAIR.
Location: USA - Remote
Base salary: $125,000–$180,000 per year, plus potential bonuses, equity grants, and benefits.
Company
Cybersecurity company developing an AI-native platform that protects organizations, their data, systems, and operations from breaches.
What you will do
- Own the ServiceNow Third Party Risk Management platform as functional owner, technical architect, and principal subject matter expert.
- Design and optimize vendor risk workflows, including onboarding, inherent risk tiering, reassessment, and offboarding.
- Lead automation and AI initiatives for risk scoring, continuous vendor monitoring, assessment operations, and process efficiency.
- Manage the assessment pipeline, queue and capacity planning, SLA tracking, final reviews, and approvals.
- Coordinate story creation, sprint and epic development, and implementation with development teams.
- Partner with Procurement, Legal, IT, Security Engineering, and audit teams to integrate controls, reporting, and security checks into vendor processes.
Requirements
- 10+ years of experience in Third Party Risk Management, GRC, information security risk, or related technical controls disciplines.
- Hands-on administrative or architectural experience with the ServiceNow TPRM module.
- 3+ years as a technical lead, process architect, or principal SME driving automation and operational efficiency in risk or compliance programs.
- Strong practical knowledge of NIST CSF, CSA CCM, ISO 27001, SOC 2, NIST 800-53, SIG, or CAIQ.
- Experience evaluating or integrating AI/ML tools and threat intelligence platforms into GRC workflows.
- Experience leading complex technical implementations, managing stakeholders, and communicating technical risk concepts to business audiences and senior leadership.
Nice to have
- Cloud environment experience and familiarity with CrowdStrike products or services.
- Experience integrating continuous monitoring data with security operations teams.
- Software development, secure coding, integration risk assessment, or third-party software threat modeling experience.
Culture & Benefits
- Remote work with flexibility and autonomy.
- Competitive compensation, equity awards, health insurance, 401(k), and paid time off.
- Physical and mental wellness programs.
- Competitive vacation, holidays, and paid parental and adoption leave.
- Professional development opportunities, employee networks, and volunteer activities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
GRC Analyst (Cloud Security)
10 дней назад
Staff Security Analyst - GRC
160 000 - 190 000$
7 дней назад
GRC Specialist (AI)
200 000 - 220 000$
Asana
6 дней назад
Security Risk Manager (Cybersecurity)
194 000 - 220 000$
8 дней назад
Security Analyst, GRC
100 000 - 120 000$
9 дней назад
Senior GRC Analyst
120 000 - 150 000$