Назад
Company hidden
3 дня назад

Senior Vendor Security Risk Analyst (Cybersecurity)

131 000 - 164 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Vendor Security Risk Analyst (Cybersecurity): Owning Turo's third-party security risk management program and strengthening security awareness and user access review processes with an accent on vendor due diligence, risk remediation, and cross-functional governance. Focus on evaluating SOC 2, ISO, and penetration-test evidence, building scalable TPRM workflows, and reporting risk, training, and access-review metrics.

Location: San Francisco, United States; hybrid schedule with required in-office work on Mondays, Wednesdays, and Thursdays

Salary: $131,000–$164,000 annually, plus equity and benefits

Company

hirify.global operates a car-sharing marketplace connecting trusted hosts and guests across the US, UK, Canada, Australia, and France.

What you will do

  • Own the vendor security review lifecycle, including intake, risk tiering, due diligence, findings documentation, remediation tracking, and renewals.
  • Evaluate SOC 2 reports, ISO certificates, penetration-test results, and security questionnaires, translating findings into business-ready risk recommendations.
  • Review DPAs, MSAs, and vendor contracts from a security perspective in partnership with Legal, Procurement, Privacy, and business stakeholders.
  • Build scalable intake, tiering, continuous-monitoring, and security-automation workflows for third-party risk management.
  • Design and deliver security awareness training, track effectiveness, and run quarterly user access review campaigns with IT and Security.
  • Report TPRM, training, and access-review metrics to security leadership, including cycle time, open findings, remediation aging, and completion rates.

Requirements

  • 5+ years of experience in third-party risk management, vendor security, or GRC, with direct ownership of vendor security review programs.
  • Hands-on experience evaluating SOC 2 reports, ISO certificates, penetration-test results, and security questionnaires.
  • Working knowledge of AWS, IAM, and data-protection principles.
  • Experience with security-focused contract review and collaboration with Legal and Procurement.
  • Bachelor's degree in Computer Science, Information Security, Information Assurance, or equivalent practical experience.
  • Relevant certification such as CISA, CISM, CISSP, or equivalent; experience with Vanta, Drata, ZenGRC, security automation, and security awareness programs.

Nice to have

  • Experience in fintech, marketplace, SaaS, or another regulated or high-trust industry handling sensitive data.
  • Experience creating security awareness content or phishing simulations.

Culture & Benefits

  • Full-time employment with equity, benefits, and competitive compensation.
  • Employer-paid medical, dental, and vision insurance, with country-specific coverage.
  • Retirement employer match, paid time off, paid holidays, volunteer time off, and parental leave.
  • Learning and Development stipend, travel credit, host matching program, and cell phone and internet stipend.
  • Hybrid employees receive in-office lunch, snacks, and activities.

Hiring process

  • Recruiting and interview processes may use AI-enabled tools for support, but live interviews and technical assessments must be completed without AI tools unless an accommodation is approved.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →