3 дня назад
Senior Vendor Security Risk Analyst (Cybersecurity)
131 000 - 164 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Vendor Security Risk Analyst (Cybersecurity): Owning Turo's third-party security risk management program and strengthening security awareness and user access review processes with an accent on vendor due diligence, risk remediation, and cross-functional governance. Focus on evaluating SOC 2, ISO, and penetration-test evidence, building scalable TPRM workflows, and reporting risk, training, and access-review metrics.
Location: San Francisco, United States; hybrid schedule with required in-office work on Mondays, Wednesdays, and Thursdays
Salary: $131,000–$164,000 annually, plus equity and benefits
Company
operates a car-sharing marketplace connecting trusted hosts and guests across the US, UK, Canada, Australia, and France.
What you will do
- Own the vendor security review lifecycle, including intake, risk tiering, due diligence, findings documentation, remediation tracking, and renewals.
- Evaluate SOC 2 reports, ISO certificates, penetration-test results, and security questionnaires, translating findings into business-ready risk recommendations.
- Review DPAs, MSAs, and vendor contracts from a security perspective in partnership with Legal, Procurement, Privacy, and business stakeholders.
- Build scalable intake, tiering, continuous-monitoring, and security-automation workflows for third-party risk management.
- Design and deliver security awareness training, track effectiveness, and run quarterly user access review campaigns with IT and Security.
- Report TPRM, training, and access-review metrics to security leadership, including cycle time, open findings, remediation aging, and completion rates.
Requirements
- 5+ years of experience in third-party risk management, vendor security, or GRC, with direct ownership of vendor security review programs.
- Hands-on experience evaluating SOC 2 reports, ISO certificates, penetration-test results, and security questionnaires.
- Working knowledge of AWS, IAM, and data-protection principles.
- Experience with security-focused contract review and collaboration with Legal and Procurement.
- Bachelor's degree in Computer Science, Information Security, Information Assurance, or equivalent practical experience.
- Relevant certification such as CISA, CISM, CISSP, or equivalent; experience with Vanta, Drata, ZenGRC, security automation, and security awareness programs.
Nice to have
- Experience in fintech, marketplace, SaaS, or another regulated or high-trust industry handling sensitive data.
- Experience creating security awareness content or phishing simulations.
Culture & Benefits
- Full-time employment with equity, benefits, and competitive compensation.
- Employer-paid medical, dental, and vision insurance, with country-specific coverage.
- Retirement employer match, paid time off, paid holidays, volunteer time off, and parental leave.
- Learning and Development stipend, travel credit, host matching program, and cell phone and internet stipend.
- Hybrid employees receive in-office lunch, snacks, and activities.
Hiring process
- Recruiting and interview processes may use AI-enabled tools for support, but live interviews and technical assessments must be completed without AI tools unless an accommodation is approved.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
Sr. Cyber Risk 3rd Party Analyst
145 900 - 234 200$
6 дней назад
Senior Security Governance Analyst (Cybersecurity)
110 500 - 157 300$
6 дней назад
GRC Security Analyst (AI Governance)
114 000 - 139 000$
5 дней назад
Cyber Security Risk Lead (Cybersecurity)
192 546 - 200 875$
3 дня назад
IT Risk and Compliance Analyst
80 000 - 90 000$
8 дней назад
Senior Vulnerability Management Analyst (Cybersecurity)
80 000 - 140 000$