Назад
Company hidden
2 дня назад

Senior Analyst, Third-Party Risk Management (TPRM) (AI)

132 600 - 195 000$
Формат работы
remote (только USA)/onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Analyst, Third-Party Risk Management (TPRM) (AI) (TPRM, AI governance): Building and scaling a proactive third-party risk management program for cloud, SaaS, infrastructure, BPO, and contingent-worker vendors with an accent on security assessments, continuous monitoring, automation, and AI risk governance. Focus on evaluating agentic and generative AI platforms, protecting proprietary data, governing remediation, and translating complex technical risks into actionable business decisions.

Location: United States only; remote work is available, or the role can be performed from Milwaukee, Chicago, New York, San Francisco, Phoenix, or Austin.

Salary: $132,600–$195,000 USD per year, plus potential equity grants.

Company

hirify.global operates an on-demand logistics and delivery marketplace connecting consumers, merchants, and drivers.

What you will do

  • Drive the maturation of the third-party risk management program from a reactive compliance function into a proactive security partnership.
  • Architect security standards and technical controls for BPO, contingent-worker, cloud, SaaS, infrastructure, and other vendor ecosystems.
  • Build process automations, centralized reporting, risk dashboards, and leadership metrics.
  • Lead supplier security AI governance, including assessments of agentic and generative AI risks.
  • Manage the full TPRM lifecycle, including due diligence, vendor onboarding, contract and data protection reviews, reassessments, and continuous monitoring.
  • Partner with security engineering, procurement, privacy, legal, sourcing, and IT teams to assess risks and track remediation to closure.

Requirements

  • 7+ years of experience with security-focused TPRM methodologies and program leadership in a fast-paced, high-growth environment.
  • Bachelor’s or Master’s degree in Information Security, Computer Science, Business Administration, or a related field.
  • Experience building security and compliance programs, conducting audits and risk assessments, evaluating controls, and managing remediation.
  • Deep technical experience assessing cloud, SaaS, AI, infrastructure, API integrations, and cloud-native services across AWS, Azure, and GCP.
  • Ability to review CAIQ, SIG, SOC 2 Type 2, penetration testing reports, ISO 27001, PCI-DSS, NIST, and related assurance documentation.
  • Experience assessing AI/ML risks such as data provenance, model poisoning, data leakage, and secure model training or fine-tuning.

Nice to have

  • CISA, CISSP, CISM, or another relevant industry certification.

Culture & Benefits

  • Security work supporting a 24x7, no-downtime global infrastructure system.
  • Comprehensive medical, dental, vision, disability, and basic life insurance.
  • 401(k) plan with employer matching and 16 weeks of paid parental leave.
  • Flexible paid time off, 80 hours of paid sick time per year, and 11 paid holidays for salaried employees.
  • Wellness, commuter, family-forming assistance, and mental health benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →