Sr. Risk Analyst - Vendor Risk Assessment (VRA)
Core
Conducting technically grounded vendor risk assessments to evaluate security controls, identify gaps, and drive remediation for a diverse vendor portfolio within the Information Security GRC team.
Role type
Senior IC Information Security Risk Analyst (Vendor Risk)
Builds
Risk assessments, remediation plans, and risk reports for third-party vendors
Domain
Cybersecurity / Third-Party Risk Management / GRC
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Vendor risk assessment, technical control evaluation, SOC 2/SOC 1/SOC 3 review, penetration test analysis, network architecture review, encryption practices assessment, access control configuration review, ISO 27001 mapping, NIST CSF/SP 800-53 mapping, GDPR compliance, SOX ITGC, cloud security (AWS/Azure/GCP), identity and access management, vulnerability management, secure SDLC, risk prioritization, stakeholder communication, project management, mentoring
Preferred skills
Prior IT or security engineering role experience, CISA, CISM, CISSP, CompTIA Security+, ISO 27001 Lead Auditor/Implementer, CCSK, AWS/Azure Security Specialty
Technologies
AWS, Azure, GCP, SIEM, DLP, VPN, DNS, SSO, MFA
Responsibilities
Conduct end-to-end vendor assessments evaluating technical documentation and control gaps; Map vendor controls to compliance frameworks and drive closure; Own workstreams and track remediation activities; Partner with IT, Engineering, Legal, and Procurement to align on risk tolerance; Communicate risk findings to technical and non-technical stakeholders; Mentor junior analysts on technical evaluation methods; Apply AI tools to automate VRA workflows and generate reporting